Agent skill

Ipa Security Guide

by classmethod in classmethod/tsumiki

ipa-security-check をはじめとするセキュリティ診断ツールが出力したレポートを読み込み、各検出項目を優先順位付きの dev-debug 依頼リストに変換する。対象プロジェクトの言語・FWを問わず汎用的に使える。コードベースを直接読んでアーキテクチャ判断を行う。

MITAuto-check passed

Install Ipa Security Guide

skills CLI
$ npx skills add classmethod/tsumiki --skill ipa-security-guide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install classmethod/tsumiki ipa-security-guide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/classmethod/tsumiki.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ipa-security-guide .claude/skills/ipa-security-guide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ipa-security-guide
GitHub stars
974
Token cost
~783 tokens
SKILL.md length
143 words
Files
4
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

ipa-security-check をはじめとするセキュリティ診断ツールが出力したレポートを読み込み、各検出項目を優先順位付きの dev-debug 依頼リストに変換する。対象プロジェクトの言語・FWを問わず汎用的に使える。コードベースを直接読んでアーキテクチャ判断を行う。

  • Works in 3 steps: 対応不要候補リスト —… → 優先順位付き依頼リスト — tsumiki:dev-debug… → まとめテーブル — 全件を一覧で整理
  • SKILL.md covers このスキルが行うこと, 起動方法, 前提条件 and ファイル構成, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Ipa Security Guide is an agent skill from classmethod/tsumiki. ipa-security-check をはじめとするセキュリティ診断ツールが出力したレポートを読み込み、各検出項目を優先順位付きの dev-debug 依頼リストに変換する。対象プロジェクトの言語・FWを問わず汎用的に使える。コードベースを直接読んでアーキテクチャ判断を行う。

Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `knowledge/priority.md`, `knowledge/triage.md` and `lib/output_formatter.md`).

The licence is MIT.

Example prompts

  • “/ipa-security-guide”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 対応不要候補リスト — アーキテクチャや設計上の理由で対応不要と考えられる件と根拠。最終判断はユーザーが行う
  2. 優先順位付き依頼リスト — tsumiki:dev-debug にそのままコピペできるフォーマット
  3. まとめテーブル — 全件を一覧で整理

What it can do on your machine

Read from SKILL.md and the folder at commit fa5aaff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ipa Security Guide loads about 783 tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 143 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~783

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from classmethod/tsumiki at commit fa5aaff, republished under its MIT licence (© classmethod). 143 words, ~783 tokens.

Download SKILL.mdSave it as .claude/skills/ipa-security-guide/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
ipa-security-guide
description
ipa-security-check をはじめとするセキュリティ診断ツールが出力したレポートを読み込み、各検出項目を優先順位付きの dev-debug 依頼リストに変換する。対象プロジェクトの言語・FWを問わず汎用的に使える。コードベースを直接読んでアーキテクチャ判断を行う。
argument-hint
[レポートファイルパス (省略時: ipa-security-report-*.md を自動検出)] [-o 出力ファイルパス]

IPA Security Guide Skill

このスキルが行うこと

ipa-security-check をはじめとするセキュリティ診断ツールが出力したレポートを読み込み、以下を出力する。

  1. 対応不要候補リスト — アーキテクチャや設計上の理由で対応不要と考えられる件と根拠。最終判断はユーザーが行う
  2. 優先順位付き依頼リスト — tsumiki:dev-debug にそのままコピペできるフォーマット
  3. まとめテーブル — 全件を一覧で整理

外部ツールへの依存なし。コードベースを直接読んでアーキテクチャを判断する。

起動方法

/ipa-security-guide
/ipa-security-guide <レポートファイルパス>
/ipa-security-guide -o <出力ファイルパス>
/ipa-security-guide <レポートファイルパス> -o <出力ファイルパス>
  • レポートファイルパスを省略した場合は、security-reports/ipa-security-report-*.md を優先して自動検出する。見つからない場合はカレントディレクトリの ipa-security-report-*.md も検索する
    • 1件のみ: 自動で使用する
    • 複数件: ファイル名一覧を提示し、AskUserQuestion でユーザーに選んでもらう
    • 0件: ipa-security-report.md へのフォールバックを試みる。それも存在しない場合はエラーを報告して終了する
  • -o を指定した場合は結果をそのパスに Write する。省略した場合は画面出力のみ

前提条件

  • 入力はセキュリティ診断ツール(ipa-security-check 等)が生成した Markdown レポートであること
  • 対象プロジェクトの言語・フレームワークは問わない

ファイル構成

ipa-security-guide/
├── SKILL.md                  ← 本ファイル(Claude が最初に読む)
├── knowledge/
│   ├── triage.md             ← 対応不要の判断基準・除外対象の定義
│   └── priority.md           ← 優先順位・グループ化の基準
└── lib/
    └── output_formatter.md   ← 依頼リスト・結果出力のフォーマット定義

実行手順

ステップ1: 事前準備(一括読み込み)

以下をすべて Read する。件ごとに読み直さない。

  1. レポートファイル(「起動方法」のファイル検出ルールに従って特定する)
    • 存在しない場合はエラーを報告して終了
    • レポートのヘッダーからプロジェクトのルートディレクトリを推定する
  2. knowledge/triage.md
  3. knowledge/priority.md
  4. lib/output_formatter.md
ステップ2: 検出ファイルを一括で Read する

レポートから全検出項目のファイルパスを一覧化し、まとめて Read する。 1件ずつ処理しながら読むのではなく、先にすべて読んでコンテキストに入れる。

  • ファイルが見つからない場合はユーザーに正しいパスを確認してから進む
  • 無闇に Grep で全ファイルを探さない
  • 判断に必要な関連ファイルは「この件を分析した結果、判断できなかった場合のみ」追加で Read する
ステップ3: 全件を一括で分析する

ステップ1〜2で読んだ内容をもとに、全検出項目を一括で分析する。件ごとにループして都度判断するのではなく、全体像を把握した上でまとめて行う。

分析対象から除外する finding(triage.md の除外対象セクションも参照):

  • <!-- ipa-triage:begin ... ipa-triage:end --> ブロックで status: 問題なし または status: 保留 が設定されているもの(ユーザーがトリアージ済み)
  • ## 偽陽性候補 セクションに分類されているもの(false-positive-review が偽陽性の疑いありと判定)
  • 分析対象は status: 未対応 と status: 対応する の finding のみ

各件について以下を判断する:

3a. ファイルの目的と検出箇所の文脈を把握する
  • このファイルが何をしているか
  • 検出箇所がどのような文脈にあるか
  • 修正が可能か、どう修正すべきか
3b. 対応不要候補の特定

triage.md(ステップ1で読済み)の基準で対応不要候補を特定する。

候補が見つかった場合は必ずユーザーに提示して最終判断を求める。スキル単独で確定しない。 ユーザーが対応不要と確定した項目については ipa-skip コメント追加の依頼を生成する。

3c. グループ化と優先順位付け

priority.md(ステップ1で読済み)の基準でグループ化と優先順位を決める。

ステップ4: 依頼リストを生成・出力する

output_formatter.md(ステップ1で読済み)のフォーマットに従って結果を出力する。

-o オプションが指定されている場合は、出力内容を指定パスに Write する。 省略されている場合は画面に出力するのみ。

重要な原則

  • コードを読む前に対応不要と断定しない — 判断は必ずコードを確認してから下す
  • 対応不要の最終判断はユーザーが行う — スキルは候補と根拠を提示するだけ。確定はユーザーの承認後
  • 不明点はユーザーに確認する — コードから辿れない場合は推測せず一時停止して聞く。ファイルパスやアーキテクチャの詳細など、ユーザーが把握していることは多い
  • 推測で判断しない — 確認できなかった情報は「確認できず」と明記し、依頼文内に調査を含める
  • アーキテクチャ依存の判断は根拠付きで明示する — 「なぜ対応しなくてよいか」を省略しない
  • 依頼文は tsumiki が迷わず実行できる粒度にする — 情報が足りない依頼は作らない
  • 不要な Read を避ける — 検出ファイルから判断できる場合は追加の Grep・Read をしない

© classmethod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in skills/ipa-security-guide of classmethod/tsumiki.

  • SKILL.md
  • knowledge/priority.md
  • knowledge/triage.md
  • lib/output_formatter.md

Open the folder on GitHubat commit fa5aaff

Compare with similar skills

Ipa Security Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ipa Security Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ipa Security Guide this skillclassmethod/tsumiki974—~783Automated safety check: PassMIT
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Pp Openipamvanhorn/printing-press-library2.1k—~5.1kAutomated safety check: NotesApache-2.0
Lang Tables Figuresbrycewang-stanford/Awesome-Journal-Skills1.2k—~1.6kAutomated safety check: PassMIT
Grad Phenomenologyasgard-ai-platform/skills241—~1.5kAutomated safety check: PassMIT
Analyzing iOS Binariestrilwu/secskills156—~2kAutomated safety check: PassMIT

Similar skills

  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Pp Openipa

    mvanhorn/printing-press-library

    Il primo CLI per l'Indice delle Pubbliche Amministrazioni — lookup istantaneo di enti, PEC, codici IPA,...

    2.1k GitHub stars~5.1k tokensUpdated yesterday
    Auto-check: notes
  • Lang Tables Figures

    brycewang-stanford/Awesome-Journal-Skills

    A skill your agent uses when preparing the exhibits of a Language (LSA) manuscript — numbered examples, Leipzig-convention interlinear glosses, IPA transcription, tableaux/trees, and quantitative…

    1.2k GitHub stars~1.6k tokensUpdated 10 days ago
    Media & CreativeAuto-check passed
  • Grad Phenomenology

    asgard-ai-platform/skills

    Apply phenomenological methods including bracketing (epoche), lived experience inquiry, and Interpretive Phenomenological Analysis (IPA) to uncover the essence of human experience.

    241 GitHub stars~1.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    156 GitHub stars~2k tokensUpdated 1 mo ago
    MobileAuto-check passed
  • Ipa Security Check

    classmethod/tsumiki

    IPA「安全なウェブサイトの作り方 改訂第7版」「安全なSQLの呼び出し方」「ウェブ健康診断仕様」「セキュリティ実装チェックリスト」「安全なウェブサイトの運用管理に向けての20ヶ条」に基づき、ソースコードを静的に検査して脆弱性候補を検出する。発見した問題には IPA 原典の出典 (文書名・章・ページ・URL) を必ず付与する。

    974 GitHub stars~1.8k tokensUpdated 2 mo ago
    DatabasesAuto-check passed

More from classmethod/tsumiki

All 14 skills in this repo
  • Dev Context

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-context", "プロジェクトコンテキストを生成", "プロジェクトを分析", "generate project context", "analyze project", "コンテキストを更新".

    974 GitHub stars~755 tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Impl

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-impl", "タスクを実装", "テストファースト実装", "implement task", "実装を開始", "クイック修正", "quick fix", "dev-impl auth 001".

    974 GitHub stars~1.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Plan

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-plan", "実装計画を作成", "要件からタスク分解", "create implementation plan", "plan tasks", "タスクを分割", "設計してタスクにする", "詳細要件定義", "full-spec plan", "EARS要件".

    974 GitHub stars~2.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Run

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-run", "自動実装", "タスクを一括実装", "auto implement", "run all tasks", "タスクを自動実行", "バッチ実装", "dev-run auth 001 005".

    974 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Screen Spec

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-screen-spec", "画面仕様を生成", "画面仕様を更新", "screen spec", "generate screen spec", "update screen spec", "画面仕様ドキュメント".

    974 GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Dev Webtest

    classmethod/tsumiki

    This skill should be used when the user asks to "dev-webtest", "Webテスト", "画面の動作確認", "E2Eテスト", "web test", "visual check", "モンキーテスト", "アクセシビリティチェック", "レスポンシブテスト", "フォームテスト".

    974 GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Ipa Security Guide

What does Ipa Security Guide do?

ipa-security-check をはじめとするセキュリティ診断ツールが出力したレポートを読み込み、各検出項目を優先順位付きの dev-debug 依頼リストに変換する。対象プロジェクトの言語・FWを問わず汎用的に使える。コードベースを直接読んでアーキテクチャ判断を行う。. Ipa Security Guide is an agent skill from classmethod/tsumiki.

How do I install Ipa Security Guide in Claude Code?

Run `npx skills add classmethod/tsumiki --skill ipa-security-guide -a claude-code`. Or copy the skill folder (skills/ipa-security-guide in classmethod/tsumiki) into .claude/skills/ipa-security-guide in your project. Claude Code loads it when a task matches its description.

How do I install Ipa Security Guide in Codex?

Run `npx skills add classmethod/tsumiki --skill ipa-security-guide -a codex`. Or copy the skill folder (skills/ipa-security-guide in classmethod/tsumiki) into .agents/skills/ipa-security-guide in your project. Codex loads it when a task matches its description.

Can I use Ipa Security Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add classmethod/tsumiki --skill ipa-security-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ipa-security-guide, .gemini/skills/ipa-security-guide, .github/skills/ipa-security-guide and .opencode/skills/ipa-security-guide in your project.

What does Ipa Security Guide need to run?

SKILL.md names no scripts, command-line tools or credentials: Ipa Security Guide is instructions for the agent only.

Does Ipa Security Guide access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Ipa Security Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ipa Security Guide use?

Ipa Security Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ipa Security Guide use?

About 783 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ipa Security Guide?

Skills that share tags, products or a category with Ipa Security Guide: Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Pp Openipa (mvanhorn/printing-press-library, 2.1k stars), Lang Tables Figures (brycewang-stanford/Awesome-Journal-Skills, 1.2k stars) and Grad Phenomenology (asgard-ai-platform/skills, 241 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ipa Security Guide?

classmethod (a GitHub organization) maintains it in classmethod/tsumiki, which has 974 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on August 7, 2026.

Source: classmethod/tsumiki on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.