Back to skills
SKILL.md
Sentinel Review
ASecurityDockerfile、Compose、Terraform、GitHub Actionsをread-only検査し、共通Finding schemaとredaction基準で返す。
- 8 stars
- 0 votes
- 0 copies
- 0 views
- Added September 23, 2026
Works with
Security analysis
100/100npx -y skills add coil398/dotfiles --skill sentinel-review --agent claude-codeAre you the author of Sentinel Review?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/coil398-sentinel-review-dotfiles)---
name: sentinel-review
description: Dockerfile、Compose、Terraform、GitHub Actionsをread-only検査し、共通Finding schemaとredaction基準で返す。
---
<!-- Cursor native overlay: runtime entry; shared review rules live in .agents -->
# Sentinel review — Cursor native entry
Cursorの親は、次の共有原本をこのSkillの実体から相対して解決する。
~~~text
SHARED_SKILL_PATH=../../../.agents/skills/sentinel-review/SKILL.md
SCHEMA_PATH=../../../.agents/skills/sentinel-review/references/findings-schema.md
REDACTION_PATH=../../../.agents/skills/sentinel-review/references/redaction.md
RESULT_PATH=../../../.agents/skills/code-review-guidance/references/result-contract.md
~~~
親はSHARED_SKILL_PATHとRESULT_PATHをReadし、共有手順が指定する入出力・集約用の資料も読む。SCHEMA_PATHとREDACTION_PATHは実在を確認して評価Taskへ絶対pathで渡し、検出の専門本文は実際の評価者が読む。親が直接評価する場合は親自身が評価資料を読む。対象repoのcwdや固定Agent定義から契約資料を推測しない。
CursorのTask起動、model、effort、role、容量は公開schemaと既存runtime方針に従い、対象IaCの相対path一覧とschema/redaction pathを欠落なくIaC検査の標準Taskへ渡す。この親入口は必要なIaC検査Taskを起動できる。標準Taskにはreadonlyを設定できないため、promptで書込み禁止を明示し、返却後に親が対象repoのstatusを確認する。起動された検査Taskは別の司令塔や親Skillを再委任しない。この入口と検査者は書き込みを実行せず、apply、deploy、外部ネットワーク、workflow実行、修正、commit、push、report保存を行わない。壊れた応答は共有手順の未確認として扱う。
Attribution
Comments
Loading comments…