Experience Lwc Security Validate

Use this skill as THE specialized Lightning Web Security (LWS) validator for a Lightning Web Component bundle (`.js`, `.ts`, `.html`, `.css`, `.js-meta.xml`) — the canonical LWS/Product-Security review for LWCs, NOT a generic code-security pass. It produces either a severity-ranked finding list with code-level remed...

概要

Experience Lwc Security Validate is a SKILL.md workflow from forcedotcom/sf-skills. It is categorized under security and links back to its reviewed source so users can inspect the complete instructions and bundled resources before installation.

ユースケース

Apply Experience Lwc Security Validate as a repeatable security workflow.
Evaluate the source instructions and bundled resources before installation.
Use the skill with a compatible Agent Skills runtime.

導入方法

# Review source first
open https://github.com/forcedotcom/sf-skills/blob/main/skills/experience-lwc-security-validate/SKILL.md

Copy the reviewed skill folder into the skills directory used by your compatible agent.

セキュリティ

AIToolly validated the published source structure and license automatically. Review forcedotcom/sf-skills and any bundled scripts again before granting workspace, command, or network access.

関連Skills

Cargo Fuzz

trailofbits/skills

セキュリティ

cargo-fuzzは、Cargoを使用するRustプロジェクトにおける事実上の標準的なファジングツールです。libFuzzerバックエンドを使用したRustコードのファジングに使用します。

Claude CodeClaude
securityresearch
6,618 Starsソースあり

Yara Rule Authoring

trailofbits/skills

セキュリティ

マルウェア識別用の高品質な YARA-X 検知ルールの作成をガイドします。YARA ルールの記述、レビュー、または最適化時に使用します。命名規則、文字列の選択、パフォーマンスの最適化、レガシーな YARA からの移行、および誤検知の削減をカバーしています。トリガー:YARA、YARA-X、malware detection、threat hunting、IOC、signature、crx module、dex module。

Claude CodeClaude
designsecurity
6,618 Starsソースあり

Agentforce D360 Analyze

forcedotcom/sf-skills

セキュリティ

単一の Agentforce セッションの Data Cloud 360° ビュー。ユーザーがセッション ID(Agent Session UUID `019d…` または MessagingSession ID `0Mw…`)によって特定の Agentforce セッションの追跡、検査、要約、または説明を求めたときに TRIGGER。また、ユーザーがまだセッション ID を持っていない場合に、時間、エージェント、チャネル、結果、または会話テキストによるセッションの検出(検索、一覧表示、探索)でもトリガーされます。設計時のアーキテクチャに関する質問(代わりに agentforce-architecture-analyze を使用)や、ランタイムのパフォーマンス/l については NOT TRIGGER。

pythondata
828 StarsApache-2.0

Security Audit

TerminalSkills/skills

セキュリティ

OWASP Top 10の脆弱性スキャン、既知のCVEに関する依存関係のチェック、流出したシークレットやAPIキーの検出を行い、優先順位付けされた修正案を生成することで、コードベースの包括的なセキュリティ監査を実行します。このスキルは、静的解析パターンと依存関係監査ツールを組み合わせています。

CodexClaude Code
securityaudit
72 StarsApache-2.0