code-review-and-quality
78مراجعة الشيفرة عبر خمسة محاور للجودة
قد تُخفي تغييرات الشيفرة مشكلات تتعلق بالصحة والأمان والبنية وسهولة القراءة والأداء. تطبق هذه المهارة عملية مراجعة منظمة وتنتج ملاحظات عملية مرتبة حسب الأولوية.
Harden Applications Against Security Risks
Security reviews can miss trust boundaries and unsafe data flows. This skill supplies threat-modeling prompts, OWASP patterns, and practical review checklists.
انسخ هذا الطلب إلى Agent لديك. يتضمن صفحة Skill المعتمدة وملف manifest.
Review the Skillstore skill "security-and-hardening" from https://skillstore.io/skills/addyosmani-security-and-hardening.md and its manifest at https://skillstore.io/api/skills/addyosmani-security-and-hardening/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.يجب أن يواصل Agent عرض خطته وطلب أي تأكيد تفرضه سياسة الأمان.
استخدم هذه الروابط عندما يحتاج AI Agent أو crawler أو script إلى سياق نظيف بدلًا من قراءة الصفحة كاملة.
جارٍ استخدام "security-and-hardening". Review an endpoint that accepts a webhook URL and fetches it on behalf of a user.
النتيجة المتوقعة:
جارٍ استخدام "security-and-hardening". Assess an LLM feature that renders model replies in a web page.
النتيجة المتوقعة:
جارٍ استخدام "security-and-hardening". Triage a high-severity package advisory from a native package-manager audit.
النتيجة المتوقعة:
All 96 findings are false positives from examples and Markdown in SKILL.md. No executable behavior or prompt injection was found.
شارك تقرير التقييم المرتبط بالإصدار والشارة المحايدة وبطاقة التضمين والاستشهادات. تعرض Skillstore الأدلة من دون أن تقرر ما إذا كانت هذه المهارة آمنة.
https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/addyosmani-security-and-hardening?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/addyosmani-security-and-hardening?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/addyosmani-security-and-hardening/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/addyosmani-security-and-hardening.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>addyosmani. (2026). security-and-hardening security audit report (audit version 2) [Author version unspecified]. Skillstore. https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2@techreport{addyosmani-addyosmani-security-and-hardening-2026,
author = {addyosmani},
title = {security-and-hardening security audit report (audit version 2)},
institution = {Skillstore},
year = {2026},
number = {2},
url = {https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "security-and-hardening security audit report (audit version 2)"
version: "unspecified"
type: report
authors:
- name: "addyosmani"
date-released: "2026-09-19"
url: "https://skillstore.io/skills/addyosmani-security-and-hardening/audits/2"
identifiers:
- type: other
value: "skillstore:addyosmani-security-and-hardening:audit:2"
description: "Skillstore immutable audit report identifier"
Map trust boundaries, validate request data, check authorization, and identify abuse cases before shipping an endpoint.
Triage audit results by reachability, review install scripts and provenance, and define a documented remediation decision.
Evaluate prompt injection, unsafe model output, excessive tool permissions, data exposure, and unbounded consumption risks.
Review this feature for trust boundaries, untrusted inputs, authentication, authorization, and sensitive data exposure. List the three most important fixes.
Audit this API endpoint against relevant OWASP risks. Check validation, queries, output encoding, access control, rate limits, errors, and logging. Cite issues and propose fixes.
Triage these package audit results. Check reachability, available fixes, install scripts, provenance, and lockfile impact. Recommend an action and review date.
Threat-model this LLM feature. Analyze prompt injection, unsafe output, data exposure, tool permissions, retrieval isolation, SSRF, limits, and irreversible actions. Prioritize controls and tests.
المؤلف
addyosmaniالترخيص
MIT
مراجعة Skillstore
r2
تنبيه الإصدار
لم يعلن المؤلف عن إصدار.
مرجع
5d5054f8a23586f9b500fece1cb613a9dffc787b
حداثة الصيانة
١٩/٩/٢٠٢٦
الاستخدام
1 تنزيلات · 0 مشاهدات
بنية الملفات
📄 SKILL.md
مراجعة الشيفرة عبر خمسة محاور للجودة
قد تُخفي تغييرات الشيفرة مشكلات تتعلق بالصحة والأمان والبنية وسهولة القراءة والأداء. تطبق هذه المهارة عملية مراجعة منظمة وتنتج ملاحظات عملية مرتبة حسب الأولوية.
Clarify User Intent Before You Build
Underspecified requests cause teams to build the wrong outcome and discover misalignment late. This skill runs a focused, one-question interview that turns ambiguity into confirmed intent.
Plan Work Into Verifiable Tasks
Large or vague software work can hide dependencies, missing acceptance criteria, and verification gaps. This skill converts a specification into ordered task slices with checkpoints, scope guidance, and clear completion conditions.
Document Decisions and Architecture Clearly
Teams lose context when important technical decisions remain in chat, code comments, or individual memory. This skill turns architectural reasoning, API guidance, project instructions, and release changes into structured documentation.
Build Accessible, Production-Ready Frontends
Frontend work can become inconsistent, inaccessible, or difficult to maintain. This skill guides component architecture, responsive layouts, state handling, and polished user experiences.
Debug Errors with a Root-Cause Workflow
Debugging failures by guesswork wastes time and can hide the real cause. This skill provides a repeatable process for reproducing, isolating, fixing, and verifying problems.
تعزيز مراجعات أمان التطبيقات
بواسطة alirezarezvani
غالبًا ما تفتقر مراجعات الأمان إلى قوائم تحقق متسقة وسير عمل قابل لإعادة الاستخدام. توفر هذه المهارة قوالب تمهيدية لمراجعات الأمان، وإرشادات مرجعية، وسكربتات تقارير بسيطة لـ Claude وCodex وClaude Code.
تدقيق الكود بحثًا عن مخاطر أمنية
بواسطة Barnhardt-Enterprises-Inc
من السهل شحن الكود الحساس أمنيًا مع عيوب خفية في المصادقة ومعالجة المدخلات والأسرار. تمنح هذه المهارة Claude وCodex وClaude Code مراجع أمنية منظمة وإرشادات للماسحات لإجراء مراجعات أكثر أمانًا.
بناء واجهات API خلفية آمنة
بواسطة sickn33
تحتاج فرق الواجهة الخلفية إلى تطبيقات آمنة تمنع الثغرات الشائعة. ترشد هذه المهارة إلى التحقق، والمصادقة، وتقوية واجهات API، وحماية قواعد البيانات، ومراجعات الأمان.
مراجعة الكود لأساسيات الأمان
بواسطة DanielPodolsky
غالبًا ما تظهر أخطاء الأمان في مجالات شائعة مثل المصادقة، والتخويل، ومعالجة المُدخلات، وتعرّض البيانات. تمنح هذه المهارة Claude وCodex وClaude Code قائمة تحقق مركّزة للعثور على هذه المخاطر أثناء المراجعة.
Audit Python Web Apps Before Release
بواسطة glenskii
Python teams need repeatable checks for common application security controls. This skill provides configurable pytest coverage with clear evidence, boundaries, and release decisions.
تعزيز قرارات هندسة الأمن
بواسطة 89jobrien
غالبا ما يمتد العمل الأمني عبر البنية المعمارية، والهوية، والامتثال، والاختبار، وتخطيط الاستجابة. تمنح هذه المهارة Claude وCodex وClaude Code إرشادات منظمة في هندسة الأمن.