security-regression-tests
Apply this skill when security-sensitive code or behavior changes need abuse-case regression tests.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
القائمة
Apply this skill when security-sensitive code or behavior changes need abuse-case regression tests.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
استنادا إلى تصنيف SOC المهني
Apply this skill when self-hosted Coolify or Coolify Cloud servers, applications, services, databases, build servers, destinations, Docker Compose stacks, domains, TLS certificates, Traefik or Caddy proxies, health checks, rolling updates, preview deployments, environment variables, build secrets, API tokens, teams, backups, restores, updates, monitoring, cleanup, resource limits, networking, firewalls, or deployment and rollback behavior are created, changed, reviewed, diagnosed, migrated, secured, or operated.
Apply this skill when PostgreSQL-specific schema, query, transaction, migration, indexing, extension, role, row-level security, connection pooling, replication, backup, restore, managed Postgres, or runtime behavior is created, changed, reviewed, or reported, including PostgreSQL 18 asynchronous I/O, B-tree skip scan, UUIDv7, virtual generated columns, RETURNING OLD/NEW, OAuth, logical-replication conflicts, observability, or 17-to-18 upgrades.
Apply this skill when Ubuntu Server or Ubuntu cloud images, especially Ubuntu 24.04 LTS or 26.04 LTS, are installed, upgraded, tuned, secured, diagnosed, backed up, restored, rebooted, or operated, including APT, dpkg, Snap, PPA, deb822 sources, unattended-upgrades, phased updates, needrestart, Livepatch, kernels, systemd services and timers, journald, cgroup v2, PSI, sysctl, CPU, memory, storage, network, SSH socket activation, AppArmor, UFW, Docker or Podman host integration, release upgrades, and remote recovery.
Apply this skill when deciding whether an AI agent, workflow automation, internal tool, or operational integration is economically worth building, expanding, replacing, or retiring by comparing human touch and wait time, exception density, stable machine-readable boundaries, expected cost per accepted outcome, human alternatives, supervision, failure recovery, maintenance, break-even volume, throughput value, effective lifetime, NPV, and independent safety gates.
Apply this skill when production automation, scheduled jobs, cron, polling, webhooks, events, queues, workers, durable workflows, approval steps, connectors, or operational pipelines are designed, changed, reviewed, or reported and the task must choose trigger responsibilities, prevent missed or duplicate work, detect silent wrong results, place human approval at the irreversible boundary, minimize credentials and personal data, control useful-effect cost, and keep an owned versioned automation registry.
Apply this skill when cloud, infrastructure, Kubernetes, serverless, database, storage, logging, telemetry, CDN, NAT, egress, autoscaling, quota, budget, tagging, snapshot, container registry, Marketplace, LLM API, or third-party SaaS usage is created, changed, reviewed, or reported and the risk is whether normal, growth, or incident usage can silently explode spend without scenario bills, account or project isolation, quotas, tags, lifecycle, retention, caps, commitment discipline, or automated shutoff guardrails.
| mustflow_doc | skill.security-regression-tests |
| locale | en |
| canonical | true |
| revision | 13 |
| lifecycle | mustflow-owned |
| authority | procedure |
| name | security-regression-tests |
| description | Apply this skill when security-sensitive code or behavior changes need abuse-case regression tests. |
| metadata | {"mustflow_schema":"1","mustflow_kind":"procedure","pack_id":"mustflow.core","skill_id":"mustflow.core.security-regression-tests","command_intents":["test","test_related","test_audit","lint","build"]} |
Convert security-sensitive behavior changes into safe negative tests that preserve defensive expectations without turning the task into vulnerability scanning, exploit development, or penetration testing.
.mustflow/config/commands.toml entries for test, audit, lint, and build-related intents..mustflow/config/commands.toml have been checked for the current scope..mustflow/skills/INDEX.md.findMany, updateMany, deleteMany, unsafe migration default, or missing database policy enforcementfalse, 0, {}, [], empty strings, or type-mismatched placeholders satisfy required policy fieldscannot_read_other_users_invoice or rejects_private_network_callback_url.Use configured oneshot command intents when available:
test_relatedtesttest_auditlintbuildPrefer the narrowest configured test intent that covers the changed boundary. Do not infer missing test, lint, scanner, or build commands. If a relevant intent is unknown or manual-only, report that status and the remaining verification risk.