ソース情報
- リポジトリ
- dyoshikawa/skills
- ソースの最終更新活動
- 2026年8月23日 07:49
- 検出された SKILL.md の言語
- 英語
- スター
- 0
- フォーク
- 0
インストール方法
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
ソースファイルを確認
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
メニュー
デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。
インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
直接コマンドでは確認用 Prompt が省略されます。実行前にソースを確認してください。
npx skills add https://github.com/dyoshikawa/skills --skill security-scan-diffコマンドは1行のまま表示されます。コピー前に横へスクロールして全体を確認してください。
ローカルで確認しますか?SkillsMP が現在取得できるファイルをダウンロードできます。
Scan an entire repository for security issues and malicious code — leaked secrets, injection and code-execution flaws, supply chain and CI/CD risks, insecure configuration, and malicious instructions hidden in AI rule files. Use when the user wants a whole-repository security scan or audit, rather than the diff-scoped `security-scan-diff`.
Babysit a Dependabot dependency-bump PR all the way to merge: verify the author is the genuine Dependabot bot, diagnose and resolve any CI failure (excluding or fixing a breaking bump when needed), get every check green, and merge. Use when the user wants to shepherd a Dependabot bump PR to merge.
Resolve every open issue one at a time: fact-check each with web research, close the ones that need no action, and run the `goal-pr` skill to fix, review, and merge the ones that do — repeating until no actionable issues remain.
SKILL.md を表示中
| name | security-scan-diff |
| description | Scan for malicious code in git diff between a tag/commit and HEAD |
target_ref = $ARGUMENTS
If target_ref is not provided, ask the user which tag or commit to compare against HEAD.
Thoroughly check for malicious code in the diff between ${target_ref} and the latest commit (HEAD).
Verify the target ref exists and get the diff scope.
git log ${target_ref}..HEAD --oneline to list commits.git diff ${target_ref}..HEAD --stat to get file change statistics.Execute the following security reviews in parallel using subagents:
Call security-reviewer subagent to review CI/CD and workflow files (.github/, scripts/) for:
${{ github.event.* }} direct expansion in run:)curl | bash, eval, base64 decode execution)pull_request_target usageCall security-reviewer subagent to review source code files (src/) for:
eval, Function constructor, suspicious child_process usage)../.. directory escape)fetch, http.request, axios to external URLs)package.json changes)Call security-reviewer subagent to review config and documentation files for:
package.jsonIntegrate the results from all subagents and produce a unified report in the following format:
## Security Review Report: ${target_ref} -> HEAD
### Conclusion
- Whether malicious code was detected or not
### Check Results Summary Table
| Check Item | Result |
|------------|--------|
| ... | ... |
### Findings (if any)
| Severity | Description | File | Risk |
|----------|-------------|------|------|
| ... | ... | ... | ... |
### Recommendations (if any)
- Actionable recommendations for each finding
### Positive Observations
- Good security practices found in the diff