security-review
Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Use when reviewing or improving this repository's release-integrity story, including artifact verification, SBOMs, attestations, vulnerability scanning, signing guidance, and release-workflow safety. Do not use for general CI validation, GitHub-settings-only work, or unrelated app customization.
Use when validating that kcNotes still works as intended after changes to Docker-first Makefile workflows, scripts, CI, release packaging, smoke tests, or documentation alignment. Do not use for app redesign, GitHub-policy-only changes, or instruction-only skill edits with no workflow impact.
Use when updating or reviewing GitHub-side hardening guidance for this repository, including required settings, rulesets, scanning, review protections, and workflow permissions. Do not use for ordinary app implementation unless the task is primarily about documented GitHub controls.
Draft a concise pull request handoff after substantive repository changes are finished or ready for review. Trigger when wrapping up code, test, script, workflow, release, security, documentation-with-behavior-impact, or app changes and the user needs a PR title/body grounded in the real diff, commits, and validations run. Do not use for tiny chat-only answers, speculative plans, or changes that are not ready for PR handoff.
| name | security-review |
| description | Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching. |
If "$security-review" is NOT present in the user request:
Use for:
Rules:
Use ONLY if explicitly requested (e.g. “full security review”, “threat model”)
Rules:
Focus on real, high-impact issues:
Ignore:
For each issue:
If no issues: say so clearly.
Only if necessary, choose ONE:
If no strong match → use none