Skip to main content

security-plan-gap

Use when defining plans, specs, or task breakdowns for web application work that may be missing security requirements

소스 정보

저장소
alicankiraz1/Codex-Sentinel
최근 소스 활동
2026년 3월 22일 09:55
감지된 SKILL.md 언어
영어
스타
80
포크
5

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
3 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
security-plan-gap
description
Use when defining plans, specs, or task breakdowns for web application work that may be missing security requirements
# Security Plan Gap ## Overview Find missing security requirements before code exists. This skill turns design omissions into actionable plan additions. ## When to Use - writing a feature plan or architecture - reviewing a spec before implementation starts - breaking work into tasks that may cross trust boundaries or handle sensitive data ## Workflow 1. Read the current plan, spec, or task breakdown. 2. Load `references/plan-gap-checklist.md`. 3. Load `../shared/common-web-threats.md`, `../shared/finding-schema.md`, and the relevant stack profile if known. 4. Produce a gap report with missing controls, risk scenarios, and suggested plan additions. 5. End with a closing coverage note using the shared headings: Reviewed / Not reviewed / Assumptions / Tools run. ## Guardrails - Treat missing requirements as gaps, not confirmed vulnerabilities. - Prefer concise, actionable additions over generic best-practice lists. - Lower confidence when the stack or architecture is only partly defined. - Treat this skill as the default planning-stage review pass when `codex-sentinel` invokes it automatically.
GitHub에서 보기