원클릭으로
security-check
Quick security checklist for a PR or set of files (secrets, input, logging). Use proactively for security reviews.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Quick security checklist for a PR or set of files (secrets, input, logging). Use proactively for security reviews.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | security-check |
| description | Quick security checklist for a PR or set of files (secrets, input, logging). Use proactively for security reviews. |
| disable-model-invocation | false |
| allowed-tools | Read, Glob, Grep, Bash |
| model | haiku |
| tier | 1 |
| intent | review |
Run a quick, checklist-based security pass on changed files or a PR: no hardcoded secrets, proper input handling, no sensitive data in logs, no obvious OWASP issues. Lightweight; for deeper review escalate to security-auditor agent. Follow docs/SECURITY.md.
Tier: 1 - Light/Cheap
Reasoning: Checklist-based; read-only; pattern matching (secrets, sanitization). Escalate to security-auditor when issues found.
$TARGET: PR diff, or list of files to check (e.g., paths or "current PR")$FOCUS: Focus area (default: all) — e.g., "secrets", "input", "logging"Secrets & config:
.env)Input & sanitization:
Logging:
Static site considerations:
Obvious risks:
## ✅ Security Check Complete
### Scope
{Files or PR checked}
### Checklist
- Secrets: ✅
- Input/sanitization: ✅ / ⚠️ / ❌
- Logging: ✅ / ⚠️ / ❌
- Static site risks: ✅
### Findings
**Blocking:** {count} — {brief list}
**Suggestions:** {count} — {brief list}
### Recommendation
{Pass / Request changes / Escalate to security-auditor}
When sensitive data handling is involved and issues found:
## 🔄 Escalate to security-auditor
### Reason
{Why deeper review is needed}
### Findings so far
- {Finding 1}
- {Finding 2}
### Next step
Run security-auditor agent for full review (docs/SECURITY.md).
Escalate to security-auditor if:
For Astro static sites:
docs/ doesn't contain sensitive datasrc/pages/api/ endpoints for data exposurePUBLIC_* vars available on clientCreate blog posts — from a topic (writes content) or with provided content (scaffolding). Use proactively when creating new blog posts or articles.
Pre-publication audit for blog posts — comprehensive final review of SEO, AEO, accessibility, images, content quality, i18n parity, and project conventions before publishing. Use proactively before publishing any blog post.
Pre-publication audit for blog series — validates series definition, post ordering, cross-post consistency, navigation, and runs individual post audits for all posts in the series. Use proactively before publishing any blog series.
Audit the blog tag taxonomy — frequency analysis, orphan detection, hierarchy validation, and proposals for new subtopic tags. Read-only — proposes, never modifies tags or posts. Use proactively before each release cycle or after a content drop of 5+ posts.
Optional DeepWorkPlan addon that connects an AI-first repo to the developer's Dailybot team — installing (with consent) the Dailybot agent skill (DailybotHQ/agent-skill) and/or the Dailybot CLI (DailybotHQ/cli), wiring the plan lifecycle into best-effort agent updates - kickoff when a plan starts, significant task completions, a blocked report when an unattended run halts, and a milestone on plan completion - with payloads derived from the plan's state layer, and optionally committing the Dailybot skill's deterministic hook enforcement (dailybot hook lifecycle hooks, CLI >= 1.12.0) so the agent harness itself reminds agents about unreported work. Opt-in, never required, never blocks the work, reconciles existing setups instead of clobbering them, and defers all auth to the Dailybot skill's own consent flow. Use when the developer or team already uses Dailybot and wants DWP progress visible to humans.
Optional DeepWorkPlan addon that safely upgrades a repo's dependencies — reasoning about the repo's ACTUAL package manager (npm/pnpm/yarn + ncu, pip/poetry/uv, cargo, go mod, bundler, composer, and more) rather than assuming npm — with a batched, validated, revertible workflow that detects the manager and manifests/lockfiles, classifies upgrades (patch/minor/major), upgrades in safe batches, runs the repo's real validation gate after each batch, reverts a failing batch, and summarizes. Opt-in, never required, reconciles with the repo's existing tooling. Use when the developer wants to bring dependencies up to date without breaking the build.