smithery.ai

security-quick-audit

変更差分に対する簡易セキュリティ監査を行い、リスクを洗い出す。

First seen Mar 30, 2026

Installation

$ npx skills add https://smithery.ai

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,293 B
  • docs SUMMARY.md 121 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Trigger examples: "脆弱性チェック", "セキュリティ診断", "security audit", "security check", "セキュリティチェック", "リスク評価"

手順

  1. git diff 等を使用して変更ファイルと影響範囲を列挙する。
  2. 入力値の取り扱い(検証/サニタイズ)を確認する。

- XSS対策(HTMLエスケープ等) - SQL/Command インジェクション対策

  1. 認証/認可の境界に影響がないか確認する(CSRF対策含む)。
  2. 依存関係の追加・変更があれば脆弱性リスクを確認する(OWASP Top 10等を意識)。
  3. 機密情報(キー/トークン/PII)がハードコードされていないか確認する。

出力フォーマット

# セキュリティ簡易監査

## 対象
<変更ファイル/機能の一覧>

## 監査結果
- **入力検証 (XSS/Injection)**: ✅/⚠️/❌ <短い理由>
- **認証/認可 (CSRF/Auth)**: ✅/⚠️/❌ <短い理由>
- **依存関係**: ✅/⚠️/❌ <短い理由>
- **機密情報**: ✅/⚠️/❌ <短い理由>

## フォローアップ
- <必要があれば箇条書き>