.agents/skills/kirospec-basic/SKILL.md
Create and maintain .kiro specifications from local scripts without external folder dependency.
npx skillsauth add kissrosecicd-hub/agents-evolution kirospec-basicInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Назначение:
.kiro/specs/<spec-name>/ без внешней зависимости;design/requirements/tasks.Когда включать:
SPEC, спецификацию, либо правки design.md, requirements.md, tasks.md;Что делает skill:
SPEC_NAME из окружения.spec-init.sh.design.mdrequirements.mdtasks.mdБыстрый запуск:
SPEC_NAME="payments-webhook" \
SPEC_ROOT="." \
bash scripts/spec-init.sh "${SPEC_NAME}"
Локальные скрипты:
bash scripts/spec-init.sh <spec-name>pwsh -File scripts/spec-init.ps1 <spec-name>bash scripts/spec-init-undo.sh <spec-name>Reference:
references/SPEC_GUIDELINES.mdreferences/ExampleDesign.mdreferences/ExampleRequirements.mdreferences/ExampleTasks.mdПравила:
--force;--root;tools
KISS reference skill for v2rayA on Arch/Ubuntu/Fedora with TUN, RoutingA, DoH DNS and Outline key import.
testing
Identifies dependencies at heightened risk of exploitation or takeover. Use when assessing supply chain attack surface, evaluating dependency health, or scoping security engagements.
development
Run Semgrep static analysis scan on a codebase using parallel subagents. Supports two scan modes — "run all" (full ruleset coverage) and "important only" (high-confidence security vulnerabilities). Automatically detects and uses Semgrep Pro for cross-file taint analysis when available. Use when asked to scan code for vulnerabilities, run a security audit with Semgrep, find bugs, or perform static analysis. Spawns parallel workers for multi-language codebases.
development
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration schemas, cryptographic library ergonomics, or evaluating whether code follows 'secure by default' and 'pit of success' principles. Triggers: footgun, misuse-resistant, secure defaults, API usability, dangerous configuration.