ソース情報
- リポジトリ
- CodySwannGT/lisa
- ソースの最終更新活動
- 2026年7月20日 18:54
- 検出された SKILL.md の言語
- 英語
- スター
- 3
- フォーク
- 3
インストール方法
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
ソースファイルを確認
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
メニュー
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
直接コマンドでは確認用 Prompt が省略されます。実行前にソースを確認してください。
npx skills add https://github.com/CodySwannGT/lisa --skill lisa-security-zap-scanコマンドは1行のまま表示されます。コピー前に横へスクロールして全体を確認してください。
ローカルで確認しますか?SkillsMP が現在取得できるファイルをダウンロードできます。
This skill should be used for any non-trivial request — features, bugs, stories, epics, spikes, or multi-step tasks. It accepts a ticket URL (Jira, Linear, GitHub), a file path containing a spec, or a plain-text prompt. It assembles an agent team, breaks the work into structured tasks, and manages the full lifecycle from research through implementation, code review, deploy, and empirical verification.
any non-trivial request —…
This skill should be used for any non-trivial request — features, bugs, stories, epics, spikes, or multi-step tasks. It accepts a ticket URL (Jira, Linear, GitHub), a file path containing a spec, or a plain-text prompt. It assembles an agent team, breaks the work into structured tasks, and manages the full lifecycle from research through implementation, code review, deploy, and empirical verification.
SOC 職業分類に基づく
SKILL.md を表示中
| name | lisa-security-zap-scan |
| description | Run an OWASP ZAP baseline… |
| allowed-tools | ["Bash","Read"] |
Run a ZAP baseline security scan against the local application.
Check prerequisites:
docker infoscripts/zap-baseline.sh exists in the projectExecute scan:
bash scripts/zap-baseline.shAnalyze results:
zap-report.html (or zap-report.md for text)reason, even when compressed to one line each.Apply the impact-or-exploitability bar -- the same bar the lisa-security-review skill
defines; follow that skill, do not restate it. A ZAP alert is not a reproducer by itself: the
alert names a pattern, not an exercised impact path.
claim-evidence-mapping contract (BCE-1, #1835): a ZAP request/response transcript is an
http-transcript and reaches the http-api boundary only. An alert whose claim is about
rendered UI (browser) or persisted state (data) needs evidence at that boundary -- a
transcript never proves it.reason (typically
"alert only, no reproducer / no bounded impact", or "transcript does not reach the claim's
boundary"). Unproven alerts are not dropped and not demoted out of the security summary --
they render in the unproven bucket so a reader still sees them.security.review.unprovenBucket is set to something other
than security-unproven; no other classification changes.Handle failures:
Run the scan now.