← スキル一覧に戻る

openwebf-security-remote-content
by archview-ai
⭐ 0🍴 0📅 2025年12月20日
SKILL.md
name: openwebf-security-remote-content description: Review security risks and mitigations for remote WebF content (untrusted bundles, URL allowlists, HTTPS, trust boundaries, clickjacking). Use when the user mentions untrusted remote bundles, bundle URL validation/allowlists, or remote updates risk. allowed-tools: Read, Grep, Glob, mcp__openwebf__docs_search, mcp__openwebf__docs_get_section, mcp__openwebf__docs_related
OpenWebF Security: Remote Content & Trust Boundaries
Instructions
- Identify trust boundaries:
- remote bundle URLs
- user-generated content
- bridge/native plugins
- Review how URLs are constructed and validated (allowlists, HTTPS, pinning/versioning).
- Use MCP docs (“Security”, “Store Guidelines”) as the baseline for recommendations.
- Provide remediation steps ordered by severity; do not modify files by default.
If the user is primarily asking about store policy/compliance for remote updates, prefer openwebf-security-store-guidelines.
More:
スコア
総合スコア
50/100
リポジトリの品質指標に基づく評価
✓SKILL.md
SKILL.mdファイルが含まれている
+20
○LICENSE
ライセンスが設定されている
0/10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
レビュー
💬
レビュー機能は近日公開予定です