一键导入
security-review
Load when reviewing Mandate402 for security risks across API, auth, database, payment, x402, worker, Morph, contract, or release boundaries.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Load when reviewing Mandate402 for security risks across API, auth, database, payment, x402, worker, Morph, contract, or release boundaries.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Load when backend API work touches authentication, authorization, rate limiting, CORS, input validation, public endpoints, or security remediation in Mandate402.
Load when architecture choices, ADRs, trade-off evaluation, technical debt, or pattern selection need explicit decision records for Mandate402.
Load when designing or reviewing backend systems, APIs, auth, databases, security, performance, scalability, CI/CD, monitoring, or production runtime patterns.
Load when reviewing Mandate402 code for secrets, auth, authorization, input validation, payment safety, blockchain integration, or release security risks.
Load when testing Cloudflare Workers, Vitest worker pools, binding mocks, integration tests, coverage, or worker test failures.
Load when planning or building React/Next.js UI with CO-STAR structure, design tokens, dashboards, hero sections, or custom UI prompts.
| name | security-review |
| description | Load when reviewing Mandate402 for security risks across API, auth, database, payment, x402, worker, Morph, contract, or release boundaries. |
| metadata | {"compatibility":"OpenAI/Codex, Claude, Cursor, Gemini, and agents that can read repo-local Markdown skills","source":"repo-local bridge","upstream_note":"The requested sickn33 security-review slug is not exposed by the current upstream skill index; use cc-skill-security-review plus Mandate402 security skills."} |
This is the repo-local security review router for Mandate402. It keeps the public trigger stable while routing agents to the narrower project and OSS skills that match the actual risk boundary.
mandate402-runtime-security for API/auth/payment runtime work and mandate402-blockchain for Morph or contract-facing work.api-security-hardening for public API hardening, cc-skill-security-review for general secure-code checklist coverage, and software-crypto-web3 for onchain/offchain risk.execution_unknown remains unresolved until correlation proves final truth.