skills/architecture-audit/SKILL.md
架構文件稽核。比對 CLAUDE.md 記錄與實際程式碼結構,找出差異並建議更新。大型 refactor 完成後或 OpenSpec 歸檔時手動執行。
npx skillsauth add seikaikyo/dash-skills architecture-auditInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
在以下情況使用此 Skill:
/architecture-auditcat CLAUDE.md
確認文件存在。若不存在,建議先建立。
# 前端
ls -R src/ | head -100
# 後端
ls -R *.py **/*.py | head -100
# 路由數量
grep -c "path:" src/router/index.ts 2>/dev/null || true
檢查以下項目:
| 項目 | 方法 | |------|------| | 新增的目錄/檔案 | 實際有但 CLAUDE.md 未記錄 | | 刪除的目錄/檔案 | CLAUDE.md 記錄但實際已不存在 | | 路由數量 | CLAUDE.md 記錄數 vs 實際數 | | 依賴版本 | package.json/requirements.txt vs CLAUDE.md | | 元件數量 | 實際元件數 vs CLAUDE.md 記錄 |
架構稽核報告
===========
專案: {project_name}
日期: {date}
差異:
+ src/views/NewPage.vue (未記錄)
- src/views/OldPage.vue (已刪除)
~ 路由數量: 文件記 22, 實際 25
建議更新:
1. CLAUDE.md 目錄結構段落加入 NewPage
2. 移除已刪除的 OldPage 記錄
3. 更新路由數量為 25
# 快速檢查
dash architecture check .
# 詳細差異
dash architecture diff .
# 全專案掃描
dash architecture check --all
tools
Conduct comprehensive GDPR compliance assessments by evaluating data processing activities against EU Regulation 2016/679, including Article 30 records of processing, lawful basis validation, data subject rights implementation, Data Protection Impact Assessments (DPIAs) under Article 35, breach notification procedures, international transfer safeguards (SCCs, adequacy decisions), and technical/organizational measures under Article 32. Use when processing personal data of EU residents, preparing for supervisory authority audits, implementing privacy-by-design for new systems, scoping compliance gaps for M&A due diligence, assessing third-party processors, or responding to data subject access requests at scale. Incorporates 2026 guidance from ICO, EDPB, and post-Data (Use and Access) Act 2025 UK-GDPR considerations. Do not use for implementing specific Article 32 controls — use implementing-gdpr-data-protection-controls; or for DSAR automation — use implementing-gdpr-data-subject-access-request.
tools
Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis. Use during DFIR/incident-response investigations, after triage collection (e.g. with KAPE), to establish program execution, file/folder access, and persistence evidence from acquired forensic images.
development
Build automated multi-turn adversarial attacks against conversational LLM targets using Microsoft PyRIT's RedTeamingOrchestrator, CrescendoOrchestrator (gradual escalation), and TreeOfAttacksWithPruningOrchestrator (adaptive branching), with scorer feedback loops and persisted conversation memory. Use when single-shot LLM scanning is insufficient and you need multi-turn, scorer-driven AI red-team campaigns against a chatbot or agent.
testing
Stand up MISP, enable and cache curated threat feeds (CIRCL, abuse.ch, Feodo Tracker), apply warninglists to suppress false positives, query indicators with PyMISP, and export attributes as auto-generated Suricata/Sigma/Wazuh detection rules. Use when maturing a MISP instance to actively drive detection, curating threat feeds with quality controls, or automating IOC-to-detection pipelines for the SIEM/IDS.