security-review
Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Use when reviewing or improving this repository's release-integrity story, including artifact verification, SBOMs, attestations, vulnerability scanning, signing guidance, and release-workflow safety. Do not use for general CI validation, GitHub-settings-only work, or unrelated app customization.
Use when validating that kcNotes still works as intended after changes to Docker-first Makefile workflows, scripts, CI, release packaging, smoke tests, or documentation alignment. Do not use for app redesign, GitHub-policy-only changes, or instruction-only skill edits with no workflow impact.
Use when updating or reviewing GitHub-side hardening guidance for this repository, including required settings, rulesets, scanning, review protections, and workflow permissions. Do not use for ordinary app implementation unless the task is primarily about documented GitHub controls.
Draft a concise pull request handoff after substantive repository changes are finished or ready for review. Trigger when wrapping up code, test, script, workflow, release, security, documentation-with-behavior-impact, or app changes and the user needs a PR title/body grounded in the real diff, commits, and validations run. Do not use for tiny chat-only answers, speculative plans, or changes that are not ready for PR handoff.
| name | security-review |
| description | Manual-only skill. Use ONLY when the user explicitly invokes: $security-review Never select this skill via semantic matching. |
If "$security-review" is NOT present in the user request:
Use for:
Rules:
Use ONLY if explicitly requested (e.g. “full security review”, “threat model”)
Rules:
Focus on real, high-impact issues:
Ignore:
For each issue:
If no issues: say so clearly.
Only if necessary, choose ONE:
If no strong match → use none