auth-system-design — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited auth-system-design (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
認証基盤を場当たりに組んで「乗っ取り」「ログインできない」を生むリスクを防ぐ。 auth-boundary-check(既存境界の点検)の上流として、認証・本人確認・セッション戦略を一貫設計する。
以下を準備すること。不足している場合は推測せず、不足を明示する。
以下の順で出力すること。順序を変えない。
secret-management-review と連携して確認する| 観点 | 状態 | 備考 |
|---|---|---|
| 自動化フロー | — | 自動処理用の資格情報が過剰権限になっていないか |
| データ / 認証 / ログ | — | セッション・認証失敗・回復操作のログを設計したか |
| 実装 / 運用フロー | — | 鍵・トークン失効の運用手順が存在するか |
| 非エンジニア理解可能性 | — | 認証フローを関係者に説明できるか |
| 会員共有 / 再利用耐性 | — | 認証設計が他機能・他プロダクトに転用できるか |
| 他LLM移植耐性 | — | 判断が特定認証製品に依存していないか |
状態は OK / 注意 / NG / 対象外 で記入すること。
施工AI(Claude Code / Cursor 等)へ渡す前に以下を確定させること。
auth-boundary-check skill — 設計した認証の権限境界を点検するaccess-control-matrix skill — 認証の上に載る認可マトリクスを設計するsecret-management-review skill — 認証で使う鍵・トークンの管理を点検するaudit-log-design skill — 認証・回復イベントの監査ログ~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.