スキル ghe-design
📦

ghe-design

コンテンツリビジョン r1 高リスク ⚙️ 外部コマンド🌐 ネットワークアクセス📁 ファイルシステムへのアクセス

ドメイン固有の要件を作成する

要件が曖昧だったり、1つのテンプレートに無理に押し込められたりすると、チームは時間を失います。このスキルは、Claude、Codex、Claude Codeが各ドメインに適した明確でテスト可能な要件を作成できるように導きます。

対応: Claude Codex Code(CC)
⚠️ 38 不十分

自分のエージェントでインストール

このリクエストをエージェントにコピーしてください。正規の Skill ページとマニフェストが含まれています。

エージェントリクエスト
Review the Skillstore skill "ghe-design" from https://skillstore.io/skills/emasoft-ghe-design.md and its manifest at https://skillstore.io/api/skills/emasoft-ghe-design/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

エージェントは引き続き計画を提示し、セキュリティポリシーで必要な確認を求める必要があります。

エージェントが読めるリソース

AI エージェント、クローラー、スクリプトがページ全体ではなく整理されたコンテキストを必要とする場合は、これらのリンクを使ってください。

テストする

「ghe-design」を使用しています。 ダークモード切り替えの要件をリクエストする。

期待される結果:

切り替え機能、ユーザー価値、永続化の動作、システム設定の扱い、切り替え時の期待事項、受け入れチェックを説明する短い要件。

「ghe-design」を使用しています。 支払いフローの要件をリクエストする。

期待される結果:

コンプライアンス、取引フロー、保持ルール、監査ログ、障害処理、検証手順を扱う構造化された要件。

「ghe-design」を使用しています。 認証システムの要件をリクエストする。

期待される結果:

脅威モデル、信頼境界、認証フロー、必須ヘッダー、測定可能な制御を含むセキュリティ重視の要件。

セキュリティ監査

高リスク

Most static command and network findings are false positives from Markdown code fences, inline paths, and reference links. The audit confirms the ~/.claude write allowance and flags absolute prompt-control wording plus mandatory full-report posting.

1
スキャンされたファイル
341
解析済み行数
2
レビュー項目
0
誤検知を無視

確認済みのセキュリティ上の懸念 (2)

高
Prompt Injection Attempt Detected
The skill declares 'THIS LAW IS ABSOLUTE AND ADMITS NO EXCEPTIONS' and orders agents to follow every user specification. This can conflict with higher-priority safety and system instructions.
The wording asserts absolute authority and no exceptions, which is a strong prompt-control pattern. It does not explicitly say to ignore system instructions, so confidence is high but not maximal.
中
Mandatory External Report Posting
The skill requires full reports to be posted to a GitHub issue thread and to GHE_REPORTS. This may disclose project details outside local storage.
The text explicitly requires full report posting to a GitHub issue thread. The exact repository visibility is unknown, so the risk depends on deployment context.
機能レビュー項目 (2)

これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。

高
Hidden file in home directory
- ~/.claude (for plugin/settings fixes)
Line 26 explicitly permits writing to ~/.claude for plugin and settings fixes. That hidden home configuration directory can alter agent behavior or expose user configuration.
高
Hidden file access
- ~/.claude (for plugin/settings fixes)
The skill grants access to a hidden home directory used for Claude configuration. This is a real filesystem risk even though it appears in a boundary list.
監査者: codex 監査履歴を表示 →
このレポートを共有・引用

バージョン付き評価レポート、中立的なバッジ、埋め込みカード、引用を共有できます。Skillstore は証拠を報告しますが、この Skill が安全かどうかは判断しません。

バージョン別レポートを開く
セキュリティ評価

レポートリンクをコピー

https://skillstore.io/skills/emasoft-ghe-design/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdownバッジ

[![Skillstore security assessment](https://skillstore.io/badges/skills/emasoft-ghe-design/security.svg)](https://skillstore.io/skills/emasoft-ghe-design?utm_source=security_passport_badge)

HTMLバッジ

<a href="https://skillstore.io/skills/emasoft-ghe-design?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/emasoft-ghe-design/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

埋め込みカード

<iframe src="https://skillstore.io/embed/skills/emasoft-ghe-design.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
学術引用 (APA · BibTeX · CFF)

APA形式の引用

Emasoft. (2026). ghe-design security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/emasoft-ghe-design/audits/8

BibTeX形式の引用

@techreport{emasoft-emasoft-ghe-design-2026, author = {Emasoft}, title = {ghe-design security audit report (audit version 8)}, institution = {Skillstore}, year = {2026}, number = {8}, url = {https://skillstore.io/skills/emasoft-ghe-design/audits/8}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "ghe-design security audit report (audit version 8)" version: "unspecified" type: report authors: - name: "Emasoft" date-released: "2026-07-05" url: "https://skillstore.io/skills/emasoft-ghe-design/audits/8" identifiers: - type: other value: "skillstore:emasoft-ghe-design:audit:8" description: "Skillstore immutable audit report identifier"

Skillstore スコア

このスコアの理由 証拠の信頼度: 中
55
アーキテクチャ
85
保守性
87
コンテンツ
71
コミュニティ
83
仕様準拠

作成できるもの

機能要件を計画する

実装を開始する前に、目的、受け入れ基準、アセット、参照を含む簡潔な要件を作成します。

技術システムを仕様化する

複雑なエンジニアリング作業のために、アーキテクチャ、障害モード、データ契約、検証手順を文書化します。

セキュリティ要件を準備する

エンジニアが検証できる形式で、脅威モデル、信頼境界、緩和策、セキュリティヘッダーを記録します。

これらのプロンプトを試す

基本要件を作成する
Use ghe-design to draft requirements for this feature: [feature]. Include what, why, acceptance criteria, and references.
ドメインに適応させる
Use ghe-design to write requirements for [domain]. Choose sections that fit the domain and explain how completion will be verified.
既存の要件を拡張する
Use ghe-design to review this requirement draft: [draft]. Add missing constraints, edge cases, references, and testable acceptance criteria.
分野横断型の仕様を作成する
Use ghe-design to create a full requirement for [system]. Cover architecture, risks, compliance, failure modes, assets, and verification evidence.

ベストプラクティス

  • ユーザーの目標から始め、明確さを高めるセクションだけを追加します。
  • すべての受け入れ基準を観察可能かつテスト可能にします。
  • 大きなソースドキュメントをコピーせずに外部参照を列挙します。

回避

  • すべての要件を同じテンプレートに無理に当てはめないでください。
  • ユーザー要件を黙って改善内容に置き換えないでください。
  • 検証証拠のない曖昧な成功条件を使わないでください。

よくある質問

このスキルは何の作成に役立ちますか?
何を構築するのか、なぜ重要なのか、完了をどのように検証するのかを説明する要件ドキュメントの作成に役立ちます。
これは固定された要件テンプレートですか?
いいえ。構成をドメインに合わせられるようにしながら、パターンと必須の基本事項を提示します。
どのドメインを対象としていますか?
アルゴリズム、ゲーム、金融、分散システム、セキュリティ、シンプルなプロダクト機能の例を含みます。
受け入れ基準の作成に役立ちますか?
はい。実装者が要件の完了を証明できるように、測定可能な受け入れ基準を重視します。
コマンドを実行したりコードを生成したりしますか?
いいえ。これは要件作成のためのガイダンステキストであり、実行可能なスクリプトは含まれていません。
インストール前にユーザーは何を確認すべきですか?
ユーザーは、広範なエージェント指示、~/.claudeへの書き込み許可、GitHubレポート投稿ルールを確認する必要があります。

開発者情報

作成者

Emasoft

ライセンス

MIT

Skillstore リビジョン

r1

バージョンに関する注意

作者はバージョンを宣言していません。

参照

30c73eac2afe762f6aa9c4553158769369d47351

メンテナンスの新しさ

2026/7/18

利用状況

5 ダウンロード · 265 閲覧

ファイル構成

📄 SKILL.md

Emasoft のその他のスキル

すべて表示
すべて表示