security-review
Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Draft a concise pull request handoff after substantive repository changes are finished or ready for review. Trigger when wrapping up code, test, script, workflow, release, security, documentation-with-behavior-impact, or template customization changes and the user needs a PR title/body grounded in the real diff, commits, and validations run. Do not use for tiny chat-only answers, speculative plans, or changes that are not ready for PR handoff.
Use when updating or reviewing GitHub-side hardening guidance for derived repositories, including required settings, rulesets, scanning, review protections, and workflow permissions. Use terraform-hardening instead for Terraform-backed changes under config/infra. Do not use for ordinary in-repo implementation changes unless the task is primarily about documented GitHub controls.
Use when adding or revising optional language-specific guidance for Go, Node.js, SQL, or small polyglot derived repositories without bloating the generic template. Keep language behavior optional. Do not use for generic template policy, routine validation, GitHub-settings-only work, or release-integrity-only work.
Use when reviewing or improving this template's release-integrity story, including artifact verification, SBOMs, attestations, vulnerability scanning, signing guidance, and release-workflow safety. Do not use for general CI validation, GitHub-settings-only work, or unrelated template customization.
Use when adapting or customizing this repository to meet the needs of the source code under `src/`, including language and framework needs, dependencies, runtime behavior, Docker, Makefile targets, and customization surfaces. Do not use for routine bug fixes, small refactors, pure workflow validation, GitHub-settings-only work, or release-integrity-only work.
Use when changing or reviewing the Terraform-backed GitHub repository hardening workspace under config/infra, including provider pins, rulesets, default branch protection, required checks, secret scanning, Dependabot security updates, token handling, plan/apply behavior, and infra documentation. Do not use for ordinary app code, generic release integrity, generic template adaptation, or non-infra GitHub Actions changes unless they directly affect hardening expectations.
| name | security-review |
| description | Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching. |
If "$security-review" is NOT present in the user request:
Use for:
Rules:
Use ONLY if explicitly requested (e.g. “full security review”, “threat model”)
Rules:
Focus on real, high-impact issues:
Ignore:
For each issue:
If no issues: say so clearly.
Only if necessary, choose ONE:
If no strong match → use none