Skip to main content
Manusで任意のスキルを実行
ワンクリックで

web-security-baseline

スター6
フォーク1
更新日2026年6月8日 19:57

OWASP Top 10 (web, not agentic) baseline review for any web application code change — auth, sessions, headers, CSRF, XSS, SQL injection, CORS, rate limits, secret handling, file upload, SSRF. Use this skill on any PR or diff that touches HTTP handlers, auth flows, session/cookie logic, file uploads, redirect/URL parsing, database queries with user input, or proxying/fetching external URLs. Catches the bug classes that ship to production and become public CVEs. Distinct from the security-auditor agent (which is invoked explicitly); this skill auto-triggers when relevant code is in scope.

インストール

Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。

SKILL.md
readonly