Skip to main content
Manusで任意のスキルを実行
ワンクリックで
RedHatProductSecurity
GitHub クリエイタープロフィール

RedHatProductSecurity

2 件の GitHub リポジトリにある 154 件の収集済み skills をリポジトリ単位で表示します。

収集済み skills
154
リポジトリ
2
更新
2026-07-15
リポジトリエクスプローラー

リポジトリと代表的な skills

ai-code-review
ソフトウェア品質保証アナリスト・テスター

Security-focused review of AI-generated or AI-assisted code. Use when reviewing code produced by AI coding assistants, auditing AI-generated patches, verifying AI-assisted contributions before merge, or when a review needs to account for failure modes specific to AI code generation.

2026-07-15
network-security
情報セキュリティアナリスト

Configure Kubernetes network security including host access restrictions, network policies, port management, and connectivity requirements. Use when writing, reviewing, or auditing pod specs, Services, NetworkPolicies, or NetworkAttachmentDefinitions.

2026-07-15
ai-systems-security
情報セキュリティアナリスト

Secure AI-powered products and infrastructure. Use when integrating LLM APIs, deploying model-serving infrastructure, building agent workflows, connecting MCP servers, or reviewing AI system architecture for security gaps.

2026-07-15
authentication
情報セキュリティアナリスト

Enforce standard authentication for external data source connections. Use when integrating, configuring, or reviewing connections from AI systems to external databases, APIs, or data services.

2026-07-15
container-hardening
ネットワーク・コンピュータシステム管理者

Harden container images and runtime configuration. Use when building, reviewing, or auditing Containerfiles, Dockerfiles, container compose files, or Kubernetes pod security settings.

2026-07-15
dependency-vulnerability-audit
ソフトウェア品質保証アナリスト・テスター

Supply chain security audit using CLI vulnerability scanners, license compliance checks, and supply chain risk assessment. Use when auditing project dependencies for known CVEs, license concerns, and supply chain health.

2026-07-15
input-validation-injection
ソフトウェア開発者

Apply when reviewing or writing code that processes untrusted input, constructs queries or commands, or handles user-supplied data. Covers SQL, LDAP, OS command injection, prototype pollution, and general validation strategy.

2026-07-15
logging
情報セキュリティアナリスト

Enforce logging of access to sensitive external data sources in AI systems. Use when designing, building, or reviewing audit and logging capabilities for AI systems accessing external databases or data services.

2026-07-15
このリポジトリの収集済み skills 145 件中、上位 8 件を表示しています。
secdevai-tool
情報セキュリティアナリスト

Run external security analysis tools (Bandit, Gosec, Scorecard, Semgrep) inside read-only containers via podman/docker. Use when the user wants to execute specific security tools, combine their output with AI analysis, or run all available tools at once.

2026-04-23
secdevai-review
情報セキュリティアナリスト

Perform AI-powered security code review using OWASP Top 10, CWE/SANS Top 25, and WSTG patterns. Use when reviewing source code, specific files, git commits, or entire codebases for security vulnerabilities. Supports web and non-web code (C/C++, Go, Rust, etc.), multi-language analysis, severity classification, and automated finding validation via subagent.

2026-04-22
secdevai
情報セキュリティアナリスト

AI-powered secure development assistant. Dispatches to review, fix, tool, and export subcommands. Use when the user invokes /secdevai with no subcommand or needs an overview of available security commands.

2026-04-22
secdevai-validate
情報セキュリティアナリスト

Validate security findings for exploitability, severity accuracy, and CVSS scoring. Use when secdevai-review dispatches findings for validation, or when the user invokes /secdevai validate to re-validate prior results. Rejects false positives, calibrates severity to Red Hat classification, and produces per-finding CVSS v3.1 analysis.

2026-04-22
secdevai-dast
情報セキュリティアナリスト

Dynamic Application Security Testing (DAST) using RapiDAST and ZAP. Use when the user wants to scan a running web app or API for security vulnerabilities, run a DAST scan, test a service endpoint, use RapiDAST or ZAP, or says "/secdevai dast" or "/secdevai-dast". Auto-detects Dockerfile/Compose for containerized targets, finds OpenAPI specs, guides the full scan workflow from target setup through SARIF result export, and — uniquely — traces each DAST finding back to the exact source file and line that is the root cause.

2026-04-22
secdevai-export
情報セキュリティアナリスト

Export security review results to Markdown and SARIF report formats. Use when the user wants to save, export, or generate reports from security review findings produced by /secdevai review, /secdevai fix, or /secdevai tool.

2026-04-22
secdevai-help
情報セキュリティアナリスト

Display all available SecDevAI commands, usage examples, aliases, and configuration options. Use when the user asks for help, needs a command reference, or wants to see the typical security review workflow.

2026-04-20
secdevai-oci-image-security
情報セキュリティアナリスト

Analyze OCI container images for security vulnerabilities, misconfigurations, supply chain risks, and hardening gaps. Use when reviewing container images from Red Hat, Quay.io, Docker Hub, or any OCI-compliant registry. Covers CVE analysis, config security, EOL component detection, credential exposure, and TLS/crypto misconfigurations.

2026-03-10
このリポジトリの収集済み skills 9 件中、上位 8 件を表示しています。
2 件中 2 件のリポジトリを表示
すべてのリポジトリを表示しました