security-evidence
SolidUse when 要判一則 Codex Security finding 是真漏洞還是假警報(finding mode),或上線前要分清 repo / staging / production 各層還缺哪些安全證據(map mode)。NOT for 修 code、跑掃描、寫 SECURITY.md。
Install
Quality Score: 85/100
Skill Content
Details
- Author
- YuDefine
- Repository
- YuDefine/nuxt-supabase-starter
- Created
- 7 months ago
- Last Updated
- today
- Language
- JavaScript
- License
- MIT
Integrates with
Similar Skills
Semantically similar based on skill content — not just same category
acceptance-readback
由 `engineering-delivery` 調用:監看部署或合併後 CI 到終態,取得驗收證據,並在 失敗時判定根因是否可由改碼解除。
acquire-codebase-knowledge
Use when the user asks to map, document, or onboard into an existing codebase and needs evidence-backed architecture, structure, conventions, integrations, testing, and concerns documentation.
omv-audit
Deep-audits a candidate finding from an Evidence.v1 file. Use when the user has an omv-find result they want to investigate further, wants to prove or disprove a vulnerability, needs to fill Evidence.v1 fields for omv-report, or invokes `/omv-audit`. Reads .omv/findings/<id>.yaml and produces a confirmed or blocked finding with all required evidence fields populated.