BREAKING CHANGES: - Remove -cskill suffix from all skill names (use standard kebab-case) - Simplify marketplace.json to only official fields (fixes Issue #5) - SKILL.md body must be <500 lines (progressive disclosure via references/) New features: - Cross-platform support for 8+ platforms (Claude Code, Copilot, Cursor, Windsurf, Cline, Codex CLI, Gemini CLI) - scripts/install-template.sh: Auto-detect platform installer with --dry-run - scripts/validate.py: Spec compliance checker for generated skills - scripts/security_scan.py: Security scanner for hardcoded keys and dangerous patterns - MIGRATION.md: v3.x to v4.0 migration guide - 6 new reference files for progressive disclosure from lean SKILL.md Key changes: - SKILL.md: 4,116 → 272 lines with spec-compliant YAML frontmatter - marketplace.json: Stripped to {name, plugins} only - article-to-prototype-cskill/ → article-to-prototype/ - stock-analyzer-cskill/ → stock-analyzer/ - Export system integrates validation + security scanning - README.md rewritten for all supported platforms - Phase 5 pipeline outputs SKILL.md-first, spec-compliant skills Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
965 B
965 B
SC-037: Phase 5 Runs Security Scan After Generating All Files
Covers: FR-025 — Phase 5 SHOULD run security scan after generating all files Type: Happy Path
Given
- The meta-skill has completed Phases 1-4
- Phase 5 has generated all files and passed validation
When
- Phase 5 reaches the security scan step (step i in the pipeline)
Then
- The security scan function is invoked automatically on the generated skill directory
- The security scan result is reported to the user
- Any security findings are listed with file locations and descriptions
Verification Method
Method: Manual test
Steps:
- Run the meta-skill to completion
- Observe Phase 5 output for security scan step
- Verify a security report is shown
Expected evidence: Phase 5 output includes a security scan report section, such as:
Security Scan: PASSED
- No hardcoded secrets found
- No .env files detected
- No shell injection patterns found