一键导入
security-remediation
Generate security remediation steps, fix strategies, and implementation guidance for vulnerabilities and issues
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Generate security remediation steps, fix strategies, and implementation guidance for vulnerabilities and issues
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Generate Sprint Stories from Master Story + sprint scope — ADO-ready PRD lift, UI/Figma, non-redundant sections
Generate Master Stories (feature-level) from PRD — for Sprint Stories use sprint-story-generator; for tech tasks use tech-task-generator
Understands natural English language queries and converts them to SDLC commands. Supports hybrid pattern matching + AI understanding. Asks for ADO work item if missing, shows non-closed items for quick selection. Works with any stage, any role.
One-command setup for AI-SDLC IDE Plugin. Installs dependencies, creates env, bootstraps .sdlc/, wires Claude Code commands, Cursor MCP, and validates everything.
Security validation for Java/TEJ/Spring backend code
Backend developer skill for Java 17, TEJ, RestExpress, Kafka, Gradle, PostgreSQL
| name | security-remediation |
| description | Generate security remediation steps, fix strategies, and implementation guidance for vulnerabilities and issues |
| model | sonnet-4-6 |
| token_budget | {"input":8000,"output":4000} |
Provides remediation strategies and implementation guidance for security issues detected in security scans.
npm audit # Check vulnerabilities
npm audit fix # Auto-fix available patches
npm audit --json > audit.json # Detailed analysis
npm install <package>@latest # Manual update
npm test # Verify no breaking changes
brew install git-secrets # Install tool
git secrets --install # Initialize
git secrets --register-aws # Add pattern
git secrets --scan -r # Scan history
const validateHttps = (url) => {
if (!url.startsWith('https://')) {
throw new Error(`Only HTTPS allowed: ${url}`);
}
};
// iOS Keychain
import * as Keychain from 'react-native-keychain';
await Keychain.setGenericPassword(key, value, {
accessible: Keychain.ACCESSIBLE.WHEN_UNLOCKED,
});
// Android Keystore
import { EncryptedSharedPreferences } from '@react-native-encrypted-preferences';
await EncryptedSharedPreferences.setItem(key, value);
const validateUserId = (id: unknown): number => {
const parsed = parseInt(String(id), 10);
if (isNaN(parsed) || parsed <= 0) {
throw new Error('Invalid user ID');
}
return parsed;
};
const safeOperation = async () => {
try {
return await riskyOperation();
} catch (error) {
logger.error('Operation failed', { error });
showUserFriendlyError('Something went wrong');
throw error;
}
};
Documents:
Testing Checklist:
Deployment Considerations:
Use when: