Skip to content
Back to skills

Cc Core Defensive

ASecurity

通用防御性编码规范,适用于跨语言代码修改中的最小改动、真实边界处理、定向验证,以及约束假想风险驱动的过度兜底或抽象;不负责语言细节、正式 review 或结构化 debug。

  • 1,035 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 28, 2026
ai-agents

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned May 28, 2026

npx -y skills add doccker/cc-use-exp --skill cc-core-defensive --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cc Core Defensive?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cc Core Defensive
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/doccker-cc-core-defensive/badge)](https://www.skillsdirectory.com/skills/doccker-cc-core-defensive)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cc-core-defensive
description: 通用防御性编码规范,适用于跨语言代码修改中的最小改动、真实边界处理、定向验证,以及约束假想风险驱动的过度兜底或抽象;不负责语言细节、正式 review 或结构化 debug。
---

# CC Core Defensive

在修改现有代码、配置或脚本时,优先使用本技能控制改动范围、决策方式和验证深度。

不要用于:

- 语言或框架细节
- 正式 code review 工作流
- 结构化 debug 工作流
- 生产环境或系统级操作安全

## 核心规则

- 优先做最小有效改动。
- 优先复用现有模式,再考虑新抽象。
- 根因清楚时修根因;根因不清楚时先继续收集证据。
- 不修改测试去适配错误实现。
- 缺失真实边界上的必要校验和错误处理、明显回归都算真实问题。
- 不要为了假想风险增加吞错逻辑、额外包装层或无需求的容灾状态。
- 改动后做受影响范围内最小但有意义的验证。

## 工作方式

1. 先读相关代码路径,再决定怎么改。
2. 明确当前问题边界和直接影响面。
3. 做最小改动。
4. 做定向验证。
5. 若必须扩大范围,先明确说明原因。

## 按需展开

- 边界判断:`references/change-boundary.md`
- 验证深度:`references/verification.md`
- 决策原则:`references/decision-principles.md`

Files in this skill

  • SKILL.md1.4 KB
  • agents/openai.yaml194 B
  • references/change-boundary.md361 B
  • references/decision-principles.md407 B
  • references/verification.md292 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…