supabase
Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...
check-security
Terraform のセキュリティをチェックする。「セキュリティチェック」「シークレット検出」「セキュリティ監査」「tf セキュリティ」「state のシークレット」「機密情報確認」「セキュリティスキャン」「脆弱性チェック」「ハードコード検出」などで起動。
Full skill instructions
Terraform 設定とstateのセキュリティチェックを行います。
| 操作 | トリガー例 |
|---|---|
| 全体スキャン | 「セキュリティチェック」「監査」 |
| コード検査 | 「ハードコード検出」「コード内シークレット」 |
| State 検査 | 「state のシークレット」「state 監査」 |
| IAM 検査 | 「IAM チェック」「権限確認」 |
| ネットワーク検査 | 「SG チェック」「ネットワーク監査」 |
# AWS キーのパターン検出(AKIA, ASIA, AIDA, AROA 等に対応)
grep -rnE "A(KIA|SIA|IDA|ROA|IPA|GPA|3T)[0-9A-Z]{16}" *.tf **/*.tf 2>/dev/null
# シークレットキーのパターン検出
grep -rn "aws_secret_access_key\s*=" *.tf **/*.tf 2>/dev/null
# パスワードのハードコード検出
grep -rn "password\s*=\s*\"" *.tf **/*.tf 2>/dev/null
# API キーのハードコード検出
grep -rn "api_key\s*=\s*\"" *.tf **/*.tf 2>/dev/null
# State ファイルの確認
terraform state pull | grep -i "password\|secret\|key\|token" 2>/dev/null
# AdministratorAccess の使用
grep -rn "AdministratorAccess\|arn:aws:iam::aws:policy/AdministratorAccess" *.tf **/*.tf 2>/dev/null
# ワイルドカード権限
grep -rn '"Action"\s*:\s*"\*"\|"Resource"\s*:\s*"\*"' *.tf **/*.tf 2>/dev/null
# 全リソースアクセス
grep -rn '"*"' *.tf **/*.tf 2>/dev/null | grep -i "action\|resource"
# 0.0.0.0/0 からの SSH 許可
grep -B5 -A5 "0.0.0.0/0" *.tf **/*.tf 2>/dev/null | grep -i "22\|ssh"
# 0.0.0.0/0 からの全ポート許可
grep -B5 -A5 'from_port\s*=\s*0' *.tf **/*.tf 2>/dev/null
# パブリック S3 バケット
grep -rn "acl\s*=\s*\"public" *.tf **/*.tf 2>/dev/null
# 暗号化なしの EBS
grep -B10 "aws_ebs_volume\|aws_instance" *.tf **/*.tf 2>/dev/null | grep -v "encrypted\s*=\s*true"
# 暗号化なしの RDS
grep -B10 "aws_db_instance" *.tf **/*.tf 2>/dev/null | grep -v "storage_encrypted\s*=\s*true"
# 暗号化なしの S3
grep -B10 "aws_s3_bucket" *.tf **/*.tf 2>/dev/null | grep -v "server_side_encryption"
## セキュリティチェック結果
### 概要
| カテゴリ | 検出数 | 重要度 |
|----------|--------|--------|
| シークレット | {N} | 🔴 高 |
| IAM 過剰権限 | {N} | 🔴 高 |
| ネットワーク | {N} | 🟡 中 |
| 暗号化 | {N} | 🟡 中 |
### 🔴 高リスク
#### シークレットのハードコード
| ファイル | 行 | 問題 |
|----------|-----|------|
| main.tf | 15 | AWS アクセスキーがハードコード |
| ... | ... | ... |
**修正方法**: 環境変数または AWS Secrets Manager を使用
#### IAM 過剰権限
| ファイル | 行 | 問題 |
|----------|-----|------|
| iam.tf | 20 | AdministratorAccess の使用 |
| ... | ... | ... |
**修正方法**: 最小権限の原則に従って権限を制限
### 🟡 中リスク
#### ネットワークセキュリティ
| ファイル | 行 | 問題 |
|----------|-----|------|
| sg.tf | 10 | 0.0.0.0/0 から SSH 許可 |
| ... | ... | ... |
**修正方法**: 特定の IP 範囲に制限
#### 暗号化未設定
| ファイル | 行 | 問題 |
|----------|-----|------|
| storage.tf | 5 | EBS 暗号化が無効 |
| ... | ... | ... |
**修正方法**: `encrypted = true` を設定
### 推奨事項
1. シークレットは AWS Secrets Manager または環境変数で管理
2. IAM ポリシーは最小権限の原則に従う
3. セキュリティグループは必要最小限のポートのみ許可
4. すべてのストレージで暗号化を有効化
# ❌ 悪い例
resource "aws_db_instance" "main" {
password = "hardcoded-password" # ハードコード
}
# ✅ 良い例
resource "aws_db_instance" "main" {
password = var.db_password # 変数から取得
}
# または
data "aws_secretsmanager_secret_version" "db" {
secret_id = "db-password"
}
# ❌ 悪い例
resource "aws_iam_role_policy" "admin" {
policy = jsonencode({
Statement = [{
Action = "*"
Resource = "*"
}]
})
}
# ✅ 良い例
resource "aws_iam_role_policy" "limited" {
policy = jsonencode({
Statement = [{
Action = ["s3:GetObject", "s3:PutObject"]
Resource = "arn:aws:s3:::my-bucket/*"
}]
})
}
Handles the full Supabase workflow from schema changes to deployment, with built-in security guardrails that catch common traps like RLS...
Comprehensive guides and best practices for Neon Serverless Postgres, covering setup, connection methods, authentication, and platform APIs.
Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data access using auth rules.
A skill to evaluate how secure Firestore security rules are. Use this when Firestore security rules are updated to ensure that the generated rules are extremely secure and robust.
Official skill for integrating Firebase AI Logic (Gemini API) into web applications. Covers setup, multimodal inference, structured output, and security.
Complete Better Auth server and client setup with database adapters, session management, plugins, and security configuration.
Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".
Complete Cloudflare platform integration with decision trees for compute, storage, AI, networking, security, and infrastructure-as-code.
Run Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.
Send, read, and manage Gmail messages, drafts, labels, and account settings.
Comprehensive website auditing across 230+ rules in 21 categories including SEO, performance, security, and accessibility.
Shared authentication, CLI syntax, and output formatting patterns for gws Google Workspace commands.
Discover your celebrity doppelgänger with StarByFace!
GeoSpy: Pricing, Features, FAQs, and Alternatives for AI Teams
Detect AI-generated voices to protect against audio fraud.
Ensure Your Content's Originality with AI Plagiarism Checker
Upscale images by 400% without quality loss
Protect your social media from copyright disputes
Accurately Detect AI-Generated Content with TheChecker.AI
Chrome extension that detects and flags AI-generated content