Home / leeyudok / doksam-skills · skills/finguard/SKILL.md · GitHub

finguard skillA

finguard is agent-read markdown (skill) from leeyudok/doksam-skills: FinGuard CLI로 소스코드 취약점을 점검하고 심각도 기반 보안 게이트와 제한된 수정·재검증 루프를 수행할 때 사용한다. 일반 코드 품질 리뷰나 SCA·모의해킹은 범위 밖이다..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# finguard

FinGuard의 로컬 `scan`을 코드 변경 워크플로에 연결하는 보안 검토자다. 원본
도구와 룰의 계약은 [LeeYudok/finguard](https://github.com/LeeYudok/finguard)가
단일 진실원천이며, 이 스킬은 탐지 규칙이나 금보원 근거 문구를 복제하지 않는다.

## 경계

FinGuard는 Semgrep 기반 정적 분석으로 `rules/`와 `mapping/rules.yaml`에 포함된
항목만 찾는다. 다음을 결과에 반드시 반영한다.

- 통과는 "탐지된 차단 대상 없음"이지 "취약점 없음"이 아니다.
- SCA/CVE, 동적 분석, 모의해킹, 인가·세션 설계 전수 검토를 대체하지 않는다.
- 파일 간 데이터 흐름은 Semgrep OSS의 한계로 놓칠 수 있다.
- 개인정보·결제정보는 코드에 하드코딩되거나 룰에 걸리는 패턴만 검사한다.
  운영 데이터의 노출 여부를 검증했다고 말하지 않는다.
- 일반 코드 품질 리뷰는 이 스킬의 범위가 아니다.

## 입력과 사전 조건

점검 대상 저장소 경로와 차단 심각도를 확정한다. 차단 심각도 기본값은
`ERROR`이며, 사용자가 조직 정책을 주면 그대로 쓴다. `finguard`, `semgrep`,
FinGuard의 `rules/`, `mapping/rules.yaml`이 실행 가능한 위치에 있어야 한다.
없으면 설치를 추측하지 말고 누락 항목과 필요한 경로를 보고한다.

로컬 `finguard scan`은 발견 건수가 있어도 exit 0일 수 있다. 자동 게이트에는
반드시 이 스킬의 래퍼를 사용한다.

```sh
python3 <스킬경로>/scripts/run_gate.py \
  --dir <저장소> --block-on ERROR
```

FinGuard 자산이 실행 파일 옆에 없으면 `--rules`와 `--mapping`을 명시한다.

## 워크플로

1. `git status`와 대상 범위를 확인한다. 사용자 변경을 보안 수정이라는 이유로
   되돌리거나 범위 밖 코드를 함께 정리하지 않는다.
2. 게이트 래퍼로 전체 대상 경로를 스캔한다. 변경 라인만 보는 MR 코멘트와 달리
   로컬 `scan --dir`은 저장소 전체 기준선이다.
3. 각 finding의 파일·줄·심각도·메시지를 실제 코드와 대조해 다음으로 분류한다.
   - 실제 취약점: 가장 작은 안전한 수정으로 제거한다.
…

Read the whole file at its exact version.

How to install

Latest version
mdr add leeyudok/doksam-skills/finguard@git:20260822.5b50a42
Exact content
mdr add leeyudok/doksam-skills/finguard@sha256:abf58373f1a3e5d4

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_32pqsvjri7lfhktu.svg)](https://markdownregistry.com/a/art_32pqsvjri7lfhktu)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260822.5b50a42 latest2026-08-22 5b50a42 4,206 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (4206 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

leeyudok/doksam-skills · 12 stars · license MIT · pushed 2026-09-23 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_32pqsvjri7lfhktu
GET https://markdownregistry.com/api/v1/resolve?ref=leeyudok/doksam-skills/finguard
GET https://markdownregistry.com/api/v1/blob/abf58373f1a3e5d42174a70370e757c15ad220306bc792b2d3d64133934e4181

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from leeyudok/doksam-skills

AGENTS.md agents
leeyudok/doksam-skills · AGENTS.md
git:20260823.e6897b6 · audit A · 12 stars
CLAUDE.md claude
leeyudok/doksam-skills · CLAUDE.md
git:20260725.cd734ff · audit B · 12 stars
db-expert skill
leeyudok/doksam-skills · skills/db-expert/SKILL.md · 관계형 스키마를 설계·검토하거나 인덱스·쿼리 튜닝·트랜잭션·마이그레이션을 다룰 때, 그리고 doksam pig 의 공유 PostgreSQL 클러스터를 운영할 때 사용한다. SQLite 고유 주제는…
git:20260922.6ef3683 · audit A · 12 stars
doksam-ui skill
leeyudok/doksam-skills · skills/doksam-ui/SKILL.md · doksam 프로젝트의 UI 를 만들거나 수정할 때, 사용자가 "ui.doksam.com 참고" / "doksam-ui" / "독삼 표준 UI" 라고 말할 때, 프론트엔드 작업이 doksam 인프라를 대상으로 할…
git:20260802.0245e6a · audit B · 12 stars
frontend-build skill
leeyudok/doksam-skills · skills/frontend-build/SKILL.md · pnpm 워크스페이스와 Vite 빌드를 설정·정비하거나, 의존성·락파일·번들 크기·폐쇄망 self-host 문제를 다룰 때 사용한다. 프레임워크 자체의 코드 작성이 아니라 빌드/패키징 층이 대상이다.
git:20260803.36bddec · audit A · 12 stars
go-expert skill
leeyudok/doksam-skills · skills/go-expert/SKILL.md · Go 코드를 작성·리뷰·리팩터링하거나 에러 처리, 동시성, 테스트, net/http 서버, go:embed 를 다룰 때 사용한다. Go 1.22+ 기준.
git:20260803.36bddec · audit A · 12 stars
handoff skill
leeyudok/doksam-skills · skills/handoff/SKILL.md · 세션을 끊고 다음 세션에 넘긴다 — 협업 인프라(GitHub·GitLab·Forgejo·Jira·Plane·Slack)가 있으면 재개 가능한 상태를 그 트래커 이슈 본문으로 남기고 HANDOFF.md 에는 이슈…
git:20260923.9bb4288 · audit B · 12 stars
memory-factcheck skill
leeyudok/doksam-skills · skills/memory-factcheck/SKILL.md · 에이전트 영속 메모리를 실제 근거(코드·DB·이슈 트래커·파일시스템)와 대조해 낡은 기억을 교정하고 죽은 기억을 아카이브 후보로 보고하는 감사 스킬. 메모리가 ~30개 파일을 넘었을 때, 큰 스택/인프라…
git:20260801.f018038 · audit A · 12 stars
mobile-web-planner skill
leeyudok/doksam-skills · skills/mobile-web-planner/SKILL.md · 사용자가 모바일 웹/앱의 기획서 / 화면설계서 / 스토리보드(storyboard) / 와이어프레임(wireframe) / IA / 화면기획을 요청할 때 도메인 불문(쇼핑, 커뮤니티, 예약, 뉴스, O2O, ...)…
git:20260922.6ef3683 · audit B · 12 stars
nextjs-implementer skill
leeyudok/doksam-skills · skills/nextjs-implementer/SKILL.md · mobile-web-planner의 Storyboard와 Business Rules를 동작하는 웹앱으로 구현할 때 사용한다. 프론트는 Next.js App Router 또는 Vite + React SPA 중…
git:20260823.e6897b6 · audit B · 12 stars
react-expert skill
leeyudok/doksam-skills · skills/react-expert/SKILL.md · React 컴포넌트를 설계·구현·리팩터링하거나 상태 관리, useEffect 남용, 리렌더 성능, 접근성 문제를 다룰 때 사용한다. React 19 기준.
git:20260922.6ef3683 · audit A · 12 stars
sdlc-orchestrator skill
leeyudok/doksam-skills · skills/sdlc-orchestrator/SKILL.md · 사용자가 "홈페이지 만들어줘" 등 단일 요청으로 서비스 전체 제작을 원할 때 기획(mobile-web-planner), 구현(nextjs-implementer), 보안(finguard)을 순차적으로 위임하고…
git:20260822.a48271f · audit A · 12 stars

Every file in leeyudok/doksam-skills

Browse by kind, by grade A, or by owner.