← スキル一覧に戻る

security-audit
by cityfish91159
⭐ 0🍴 0📅 2026年1月24日
SKILL.md
name: security_audit description: Checklist for security-sensitive coding, ensuring MaiHouses guards and policies are respected. allowed-tools: Read, Grep, Glob
Security Audit Protocol
1. Critical "Guard" Files
WARNING: The following files are OFF-LIMITS for modification without explicit user approval.
scripts/ai-diff-gate.ts.github/workflows/**- Any file with
midlaworpolicyin the name.
2. Database Security (Supabase)
- RLS (Row Level Security):
- EVERY table must have RLS enabled.
- Policies must explicitly define
USINGandWITH CHECKclauses. - NEVER use
service_rolekey in frontend client code.
- SQL Injection:
- Use parameterized queries or ORM methods (Supabase JS client) only.
- Avoid raw SQL string concatenation.
3. API Security
- Authentication:
- Verify
userexists inreq(usually populated by middleware/auth helper). - Check permissions before performing actions (e.g.
checkPermission(user.id, 'post.create')).
- Verify
- Input Validation:
- Validate ALL inputs using
zodschemas. - Sanitize HTML inputs if rendering user content (use
DOMPurify).
- Validate ALL inputs using
4. Audit Checklist
- Are guards/policies untouched?
- Is RLS enabled and tested?
- Is input validation (
zod) in place? - Are no secrets committed to code?
- Did I run
/security-review(if available) or manual check?
スコア
総合スコア
50/100
リポジトリの品質指標に基づく評価
✓SKILL.md
SKILL.mdファイルが含まれている
+20
○LICENSE
ライセンスが設定されている
0/10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
レビュー
💬
レビュー機能は近日公開予定です