Skip to main content
alpha-omega-security
GitHub クリエイタープロフィール

alpha-omega-security

3 件の GitHub リポジトリにある 56 件の収集済み skills をリポジトリ単位で表示します。

収集済み skills
56
リポジトリ
3
更新
2026年8月28日
リポジトリエクスプローラー

リポジトリと代表的な skills

verify
未分類

Re-run a finding's reproduction against current HEAD, test its attack tree, grade five fixed evidence criteria, and account for every matched design control.

2026年8月28日
critic
未分類

Judge whether a validated finding can affect a real release build, and record the attacker position, preconditions, impact, counterevidence, and facts that could change that conclusion. Finding-scoped and read-only.

2026年8月28日
disclose
未分類

Draft the disclosure content for a finding in GitHub Security Advisory shape. Produces a title, markdown description, affected package block, CVSS vector, CWE list, references, and a suggested-recipients list from CODEOWNERS or git history, then writes them…

2026年8月28日
public-issue
未分類

File a low-severity finding as an ordinary public GitHub issue after explicit analyst confirmation. Use for hardening gaps, defence-in-depth misses, and other bugs that do not warrant coordinated private disclosure.

2026年8月28日
report-upstream
未分類

File a finding on the upstream repository through GitHub's private vulnerability reporting, request the temporary private fork, and push the proposed patch to it when available. Use after disclose has produced a draft and (optionally) patch has produced a…

2026年8月28日
security-deep-dive
未分類

Audit first-party source for security vulnerabilities using an inventory-first, six-step per-sink methodology. Use when you want a thorough scan that distinguishes real findings from pattern matches and records both in a machine-readable report. The target is…

2026年8月28日
audit-memory
未分類

Focused static audit for reachable memory corruption in first-party C, C++, unsafe Rust, native extensions, and FFI boundaries.

2026年8月27日
embedded-native
未分類

Map native languages, extension bridges, build tools, manifests, and dependencies after shallow Git submodules have been initialized. Runs when triage finds native-extension, submodule, or mixed native-language signals.

2026年8月27日
収集済み skill 44 件中 8 件を表示しています。
threat-model-authoring
情報セキュリティアナリスト

Draft phase 3.5 of a threat model from the orientation brief, surface analysis, and maintainer answers. USE WHEN writing threat-model.md to the canonical §1.1–§1.19 structure. Combines concise prose with the §1.7 trust table and contract matrix, §1.8 output…

2026年8月11日
threat-model-backtest
情報セキュリティアナリスト

Backtest phase 3.6 of threat-model production against historical findings before sign-off. USE WHEN a draft model must prove it can uniquely route real reports. Builds a stratified producer-side corpus across components and contract dimensions, clusters large…

2026年8月11日
threat-model-sidecar
情報セキュリティアナリスト

Emit and validate the §1.19 machine-readable companions: threat-model.yaml using schema threat-model-sidecar/v2, and the flat threat-model.json export conforming to schema.json. USE WHEN an orchestrated threat model is ready for publication, automated or…

2026年8月11日
threat-model
情報セキュリティアナリスト

Produce a threat model for a targeted open-source repository or package: its implicit security contract (assumptions, guarantees, disclaimed properties, and known misuses), not an audit, pentest, CVE list, or build-hygiene review. USE WHEN asked to produce,…

2026年8月11日
threat-model-triage
情報セキュリティアナリスト

Triage one inbound vulnerability report, scanner hit, fuzzer artifact, or AI finding against a finished threat model. USE WHEN asked whether a finding is valid or in scope. Applies the §1.1 routing algorithm and §1.17 precedence to assign exactly one closed…

2026年8月10日
threat-model-interview
情報セキュリティアナリスト

Run phase 3.4 maintainer question waves for threat-model production. USE WHEN inferred claims need ratification or interview-first versus draft-first mode must be chosen. Asks 3–7 prioritized proposed-answer questions per wave; wave 1 always covers scope,…

2026年8月10日
threat-model-recon
情報セキュリティアナリスト

Orient and mine an open-source repository for threat-model production phases 3.1–3.2. USE WHEN starting a threat model or surveying security posture before modeling. Reads README, top-level docs, SECURITY/THREAT docs, maintainer issue rulings, and changelog…

2026年8月10日
threat-model-surface
情報セキュリティアナリスト

Perform phase 3.3 deep analysis of an in-scope attack surface for a threat model. USE WHEN the orientation brief is ready and code must be read to derive the §1.7 per-input trust table and contract-dimension matrix, §1.5 no-surprise side-effects inventory,…

2026年8月10日
3 件中 3 件のリポジトリを表示
すべてのリポジトリを表示しました