← 카탈로그
스킬curated

security-pipeline

 

보안 파이프라인 - CWE Top 25 + STRIDE 자동 검증

#automation

다음 행동

/security-pipeline
기술 README 원문 보기

설치 옵션, 예시 코드, 세부 사용법을 영어 README 원문 그대로 확인합니다.

Overview

보안 파이프라인 스킬은 코드 변경 시 자동으로 CWE Top 25 기반 보안 검증을 수행한다. /handoff-verify --security, /commit-push-pr 실행 시 통합 동작한다. 보안 체크리스트 참조: ~/.claude/skills/_reference/security-checklist.md

effort:max가 항상 강제 적용된다. 보안 검증은 축약하지 않는다.


Trigger Conditions

파일 패턴 기반 자동 트리거

다음 패턴을 포함하는 파일이 변경되면 보안 파이프라인이 자동으로 실행된다:

패턴트리거 수준설명
**/auth/**Full Scan인증 관련 모듈
**/payment/**Full Scan결제 처리 모듈
**/api/**CWE ScanAPI 엔드포인트
**/middleware/**CWE Scan미들웨어
**/session*CWE Scan세션 관리
**/token*CWE Scan토큰 처리
**/crypto*CWE Scan암호화 로직
**/admin/**Full + STRIDE관리자 기능
**/upload*CWE Scan파일 업로드
**/.env*Credential Scan환경변수 파일
**/config/secret*Credential Scan시크릿 설정

커밋 기반 자동 트리거

/commit-push-pr 실행 시 staged 파일 목록에서 위 패턴이 감지되면, 커밋 전 보안 파이프라인이 자동으로 실행된다.


CWE Scanning Rules

Critical (커밋 차단)

CWE IDRuleGrep Pattern
CWE-89SQL Injectionquery\(.*\$\{, query\(.*\+
CWE-79XSSinnerHTML, dangerouslySetInnerHTML, v-html
CWE-78OS Command Injectionexec\(.*\$\{, spawn\(.*req\.
CWE-77Command InjectionTemplate string in shell command
CWE-798Hardcoded CredentialsapiKey\s*=\s*['"], secret\s*=\s*['"]

High (경고, 커밋 허용)

CWE IDRuleGrep Pattern
CWE-22Path Traversal\.\.\/ with user input
CWE-352CSRFPOST handler without csrf check
CWE-287Improper AuthRoute without auth middleware
CWE-862Missing AuthzHandler without role/permission check
CWE-502Unsafe Deserializationeval\(, new Function\(
CWE-918SSRFfetch\(.*req\., axios.*req\.
CWE-434Unrestricted UploadUpload without validation
CWE-269Privilege EscalationRole change without verification

Medium (정보 제공)

CWE IDRuleGrep Pattern
CWE-200Info Disclosure`console\.log.*password\token\secret`
CWE-20Input ValidationEndpoint without schema validation
CWE-327Broken Cryptomd5\(, sha1\(, Math\.random\(\)
CWE-276Incorrect Permsorigin:\s*['"]?\*, 0o?777

Auto-Fix Rules

자동 수정은 사용자 승인 후 적용한다. 신뢰도가 High인 항목만 자동 수정 대상이다.

Parameterized Queries (CWE-89)

Before: db.query(`SELECT * FROM users WHERE id = '${id}'`)
After:  db.query('SELECT * FROM users WHERE id = $1', [id])

Environment Variables (CWE-798)

Before: const apiKey = 'sk-proj-abc123'
After:  const apiKey = process.env.API_KEY
+ .env.example에 API_KEY= 추가

Safe DOM Manipulation (CWE-79)

Before: element.innerHTML = userInput
After:  element.textContent = userInput

Remove Sensitive Logs (CWE-200)

Before: console.log('Token:', token)
After:  // (line removed)

Secure Hash (CWE-327)

Before: const hash = md5(data)
After:  const hash = crypto.createHash('sha256').update(data).digest('hex')

Integration Points

/handoff-verify (v6)

/handoff-verify 커맨드의 검증 단계에서 보안 검사가 포함된다. verify-agent가 민감 파일 변경을 감지하면 이 스킬을 자동 호출한다.

/commit-push-pr

커밋 전 자동 보안 게이트로 동작한다:

  • Critical 발견 시: 커밋 차단 (BLOCKED)
  • High 발견 시: 경고 표시 후 사용자 확인 (WARN)
  • Medium 이하만 존재: 통과 (PASS)

/security-review (통합됨)

이전 security-review 스킬의 OWASP 체크리스트는 _reference/security-checklist.md로 전환. 전체 보안 리뷰 시 이 스킬의 CWE Top 25 매핑 + STRIDE + 의존성 검사가 수행되며, 체크리스트 참조 파일을 함께 로드한다.


effort:max Enforcement

이 스킬은 항상 effort:max로 실행된다. 보안 검증에서 분석 깊이를 줄이는 것은 허용하지 않는다.

적용 범위:

  • CWE 패턴 매칭 시 false positive 최소화를 위한 컨텍스트 분석
  • STRIDE 분류 시 전체 데이터 흐름 추적
  • 자동 수정 제안 시 사이드 이펙트 검증
  • 의존성 검사 시 transitive dependency 포함

이것도 같이 보면 좋다

같은 업무 태그와 카테고리가 겹치는 항목부터 보여줍니다.

스킬운영자 실사용

agents-sdk

Build AI agents on Cloudflare Workers using the Agents SDK. Load when creating stateful agents, durable workflows, real-time WebSocket apps, scheduled tasks, MCP servers, chat applications, voice agents, or browser automation. Covers Agent class, state management, callable RPC, Workflows, durable execution, queues, retries, observability, and React hooks. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.

 무료
#audio#automation#code
스킬운영자 실사용

embedded-captions

Add captions to a talking-head video. ONE catalog (CATALOG.md) of 32 visual identities behind two engines: column-flow (captions composited INTO the scene — matte occlusion + mix-blend; cream/ink/editorial/keynote/documentary/loud/neon/glitch/chrome/velocity) and themed constitutions (anchor/ordnance/terminal/neonsign/stardust/stomp/scoreboard/transit/vhs/arcade/dossier/laser/thunder/hologram/biolume/aurora/spectrum/papercut/popup/chalkboard/graffiti/brush/inkwater/ransom/lastpage/nightcity — e.g. a glyph-decode climax, a neon sign WRITTEN stroke by stroke, or the quiet `anchor` rail default). Route by identity, never by mode. Trigger on "captions/subtitles", "embed/cinematic captions", "VFX captions", "炸/特效/酷炫字幕", a named identity, or top-tier motion-graphics asks. Embedding every word is wrong for most talking-head content — `anchor` is the verbatim default. Pipeline: transcription → hyperframes remove-background matting → HTML render → ffmpeg overlay. Requires hyperframes and a single-subject clip.

 무료
#video#web#automation
스킬운영자 실사용

pr-to-video

pr-to-video workflow - a GitHub pull request (URL like github.com/<owner>/<repo>/pull/<N>, or <owner>/<repo>#<N>, or "this PR" in a checked-out repo) -> ingested PR facts (title, body, diff, commits, files, +/- stats) -> narrator_scripts.json + audio (voice + BGM) + section_plan.md -> code-diff / before-after / impact explainer video. Input is a CODE CHANGE. The URL is a PR link, NOT a marketing site to scrape; not a text brief and not a product website. For a non-PR input (product site, general website, topic text), see /hyperframes-read-first.

 무료
#video#audio#web