Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Security Radar

ASecurity

資安套件情報雷達。每日掃描並精選「有效、熱門、自身安全」的資安套件/工具,聚焦 Nuxt 3 / Vue 3 / TypeScript(npm)、Go、Python (FastAPI) 技術棧。查詢已收錄套件的評估結論、安全狀態與選型建議時使用。

2 stars
0 votes
0 copies
0 views
Added 9/22/2026
developmenttypescriptpythongosqlvuefastapigitapidatabasesecurity

Works with

api

Security Analysis

A100/100

Scanned 9/22/2026

Install to Claude Code

$npx -y skills add seikaikyo/dash-skills --skill security-radar --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Radar?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Security Radar
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/seikaikyo-security-radar/badge)](https://www.skillsdirectory.com/skills/seikaikyo-security-radar)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: security-radar
description: 資安套件情報雷達。每日掃描並精選「有效、熱門、自身安全」的資安套件/工具,聚焦 Nuxt 3 / Vue 3 / TypeScript(npm)、Go、Python (FastAPI) 技術棧。查詢已收錄套件的評估結論、安全狀態與選型建議時使用。
updated: 2026-09-09
---

# Security Radar(資安套件情報雷達)

## 用途

每日自動掃描資安生態,把通過查證的套件/工具沉澱到 `packages.md`,
作為技術棧(Nuxt 3 / Vue 3 / TypeScript、Go、Python FastAPI、Neon PostgreSQL、
Vercel / Render、Logto JWT/JWKS)的資安選型依據。

## 評估標準(三維度,逐項查證)

收錄前必須通過全部三項,**不可憑印象**:

1. **有效**:解決明確的安全問題;與現有技術棧整合成本合理
   (npm / Go module / pip 可直接安裝,或 CI 一鍵接入)。
2. **熱門**:GitHub stars、近 90 天 commit/release 活躍度、下載量。
   已停止維護(>12 個月無活動)的不收錄;已收錄者標「淘汰」。
3. **安全**:查 osv.dev / GitHub Advisory Database 確認無未修補 CVE;
   參考 OpenSSF Scorecard 與 release provenance(SLSA / sigstore)。
   **自身有未修補高危漏洞者一律淘汰。**

## 維護規則

- 資料表在 `packages.md`,一列一套件。
- 已收錄的套件不重複新增;只在狀態變化時更新該列:
  - 爆出未修 CVE → 安全狀態標 ⚠️ 並附公告連結
  - 停止維護 → 標「淘汰」
  - 已修補 → 更新為 ✅ 並註記修補版本
- 每日主題輪替:npm/JS(依賴稽核、XSS/CSP、JWT、rate limiting)、
  Go(安全 middleware、secrets 掃描、fuzzing)、
  通用(SAST、supply chain、secrets 偵測、容器/CI 安全)。
- **OWASP 對應**:每筆收錄必填「OWASP 2025」欄,以 [OWASP Top 10:2025](https://owasp.org/Top10/2025/)
  代碼標示(可多個)。A01 Broken Access Control(含 SSRF)|A02 Security Misconfiguration|
  A03 Software Supply Chain Failures|A04 Cryptographic Failures|A05 Injection|
  A06 Insecure Design|A07 Authentication Failures|A08 Software or Data Integrity Failures|
  A09 Security Logging and Alerting Failures|A10 Mishandling of Exceptional Conditions。
  新增後同步更新 `packages.md` 文末的涵蓋矩陣,並以矩陣「缺口」欄優先決定次日主題。
  OWASP 若發布新版,先更新此對照與矩陣標題,再依新版重標。
- 有新收錄或狀態更新才 commit / 開 PR;當天無變化則不動 repo。
- **自動 merge**(使用者已於 2026-08-31 授權):PR 開**正式**(非 draft);
  確認無 merge conflict 且 CI(若有)全綠後,直接以 squash 合併並附合併說明,
  不等人工審核。若 CI 紅燈或有衝突,先修到綠再合併;修不了才留著 PR 並說明原因。

## 安全狀態圖例

| 標記 | 意義 |
|------|------|
| ✅ | 查證時無未修補 CVE |
| ⚠️ | 有未修補 CVE 或重大疑慮(附連結) |
| 淘汰 | 停止維護或有未修高危漏洞,不建議使用 |

Attribution

seikaikyoseikaikyo
View sourceMore from seikaikyo →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

284072 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2192 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

9881 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →