claude-skills/engineering
xingzihai 2f92a1dfcb feat(skill-tester): add Security dimension to quality scoring system
- Add SecurityScorer module (605 lines) with comprehensive security assessment
- Add 4 security scoring components:
  - Sensitive data exposure prevention (hardcoded credentials detection)
  - Safe file operations (path traversal prevention)
  - Command injection prevention (shell=True, eval, exec detection)
  - Input validation quality (argparse, error handling, type checking)
- Add 53 unit tests with 850 lines of test code
- Update quality_scorer.py to integrate Security dimension (20% weight)
- Rebalance all dimensions from 25% to 20% (5 dimensions total)
- Update tier requirements:
  - POWERFUL: Security ≥70
  - STANDARD: Security ≥50
  - BASIC: Security ≥40
- Update documentation (quality-scoring-rubric.md, tier-requirements-matrix.md)
- Version bump to 2.0.0

This addresses the feedback from PR #420 by providing a focused, well-tested
implementation of the Security dimension without bundling other changes.
2026-03-26 13:25:27 +00:00
..
.claude-plugin chore: sync cross-platform indexes, regenerate docs, fix plugin.json counts 2026-03-25 15:42:39 +01:00
.codex release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
agent-designer fix: correct broken install paths, improve skill descriptions, standardize counts 2026-03-23 11:57:40 +01:00
agent-workflow-designer fix(engineering): improve agent-workflow-designer - add scripts + extract references 2026-03-11 20:23:01 +01:00
agenthub fix(plugins): change author from string to object in plugin.json 2026-03-19 09:02:28 +01:00
api-design-reviewer release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
api-test-suite-builder fix: correct broken install paths, improve skill descriptions, standardize counts 2026-03-23 11:57:40 +01:00
autoresearch-agent feat(autoresearch-agent): fix critical bugs, package as plugin with 5 slash commands 2026-03-13 14:38:59 +01:00
browser-automation fix: trim 3 SKILL.md files to comply with Anthropic 500-line limit 2026-03-25 15:20:47 +01:00
changelog-generator release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
ci-cd-pipeline-builder release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
codebase-onboarding fix(engineering): improve codebase-onboarding - add scripts + extract references 2026-03-11 20:21:34 +01:00
database-designer improve(engineering): enhance tdd-guide, env-secrets-manager, senior-secops, database-designer, senior-devops 2026-03-25 13:49:25 +01:00
database-schema-designer fix: correct broken install paths, improve skill descriptions, standardize counts 2026-03-23 11:57:40 +01:00
dependency-auditor release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
docker-development feat(marketplace): add 6 missing standalone plugins — total 22→28 2026-03-18 09:01:31 +01:00
env-secrets-manager improve(engineering): enhance tdd-guide, env-secrets-manager, senior-secops, database-designer, senior-devops 2026-03-25 13:49:25 +01:00
focused-fix feat(engineering): integrate focused-fix skill — docs, command, agent, marketplace 2026-03-23 13:59:30 +01:00
git-worktree-manager release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
helm-chart-builder feat(marketplace): add 6 missing standalone plugins — total 22→28 2026-03-18 09:01:31 +01:00
interview-system-designer fix(engineering): address Claude Code review findings 2026-03-11 20:46:48 +01:00
mcp-server-builder release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
migration-architect release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
monorepo-navigator fix(engineering): improve monorepo-navigator - add scripts + extract references 2026-03-11 20:22:16 +01:00
observability-designer release: v2.1.1 — skill optimization, agents, commands, reference splits (#297) 2026-03-09 15:54:25 +01:00
performance-profiler fix(engineering): address Claude Code review findings 2026-03-11 20:46:48 +01:00
pr-review-expert fix: correct broken install paths, improve skill descriptions, standardize counts 2026-03-23 11:57:40 +01:00
rag-architect fix: correct broken install paths, improve skill descriptions, standardize counts 2026-03-23 11:57:40 +01:00
release-manager fix: correct broken install paths, improve skill descriptions, standardize counts 2026-03-23 11:57:40 +01:00
runbook-generator fix(engineering): improve runbook-generator - add scripts + extract references 2026-03-11 20:24:23 +01:00
secrets-vault-manager feat(engineering,ra-qm): add secrets-vault-manager, sql-database-assistant, gcp-cloud-architect, soc2-compliance 2026-03-25 14:05:11 +01:00
skill-security-auditor fix(security-auditor): reduce false positives — whitelist plugin dirs, remove 'token' from exfil pattern 2026-03-17 15:43:37 +01:00
skill-tester feat(skill-tester): add Security dimension to quality scoring system 2026-03-26 13:25:27 +00:00
spec-driven-workflow fix: trim 3 SKILL.md files to comply with Anthropic 500-line limit 2026-03-25 15:20:47 +01:00
sql-database-assistant feat(engineering,ra-qm): add secrets-vault-manager, sql-database-assistant, gcp-cloud-architect, soc2-compliance 2026-03-25 14:05:11 +01:00
tech-debt-tracker fix(security): add disclaimers to sample code and scaffolding templates 2026-03-11 20:18:27 +01:00
terraform-patterns feat(engineering-team): add azure-cloud-architect, security-pen-testing; extend terraform-patterns 2026-03-25 13:32:22 +01:00
SKILL.md seo: optimize all 9 pack descriptions — add Gemini CLI, Cursor, OpenClaw keywords + 'agent skill/plugin' framing 2026-03-15 23:22:14 +01:00