用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/tomevault-io/skills-registry --skill security-checklist命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| Use when this capability is needed.
> Use when this capability is needed.
Review architecture and API design for the vfs-s3 project. Use when the user mentions @architect, asks to review an issue's design, discuss module boundaries, API shape, or architectural decisions for vfs-s3. Also trigger when the user wants to create an ADR (Architecture Decision Record) or evaluate a technical approach for the project. Intended for dispatch from Codex automation or Claude routines; GitHub trigger phrase: @vfs-s3-bot please prepare design doc Use when this capability is needed.
基于 SOC 职业分类
| name | security-checklist |
| description | Security checklist to run before marking any task done Use when this capability is needed. |
| metadata | {"author":"albinotonnina"} |
Before reporting status="done", verify each item:
Input validation
Authentication & authorisation
Data handling
Transport & headers
Content-Security-Policy header still passes for any new inline scripts/stylesRate limiting
/login, /register, /reset-password) have strict rate limits (≤5 req/min)If any item is not applicable, note why in the PR description.
Source: albinotonnina/echos — distributed by TomeVault.