docs: update guide content, examples, tools, and reference files
- guide/ultimate-guide.md — content updates - guide/workflows/README.md, guide/README.md — navigation improvements - guide/diagrams/ — diagram updates (context/sessions, config, MCP ecosystem) - guide/third-party-tools.md — additions - examples/README.md, hooks/README.md, scripts/README.md — examples updates - examples/skills/pr-triage/SKILL.md — expanded skill - machine-readable/reference.yaml — reference sync - tools/audit-prompt.md, tools/onboarding-prompt.md — tooling updates - docs/for-cto.md, docs/for-tech-leads.md, docs/resource-evaluations/README.md — doc updates - .gitignore — gitignore update Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
parent
9c02214bb8
commit
8f1dcecfa2
19 changed files with 639 additions and 104 deletions
|
|
@ -29,7 +29,7 @@ Full breakdown: WP06 — Privacy & GDPR Compliance *(whitepaper, coming soon)* (
|
|||
|
||||
### Threat landscape
|
||||
|
||||
This is the only public resource tracking AI coding tool CVEs: **24 vulnerabilities and 655 malicious skills catalogued**. Key vectors relevant to enterprise:
|
||||
This is the only public resource tracking AI coding tool vulnerabilities: **15 vulnerabilities and 655 malicious skills catalogued**. Key vectors relevant to enterprise:
|
||||
|
||||
- Prompt injection via untrusted file content (e.g. malicious comments in dependencies)
|
||||
- Supply chain attacks via MCP servers (treat like npm packages)
|
||||
|
|
|
|||
|
|
@ -66,7 +66,7 @@ See [Guide Ch.7.4 — Security Hooks](../guide/ultimate-guide.md#74-security-hoo
|
|||
|
||||
## Security posture overview
|
||||
|
||||
This guide maintains the **only public threat database for Claude Code**: 24 CVEs and 655 malicious skills catalogued. Key risks for teams:
|
||||
This guide maintains the **only public threat database for Claude Code**: 15 vulnerabilities and 655 malicious skills catalogued. Key risks for teams:
|
||||
|
||||
- **Prompt injection** via untrusted file content or MCP servers
|
||||
- **Overly permissive settings** — `allowedTools: ["*"]` in production
|
||||
|
|
|
|||
|
|
@ -77,4 +77,4 @@ Ressources surveillées mais pas encore intégrées : [watch-list.md](./watch-li
|
|||
|
||||
---
|
||||
|
||||
**Dernier update**: 2026-02-28 (72 évaluations)
|
||||
**Dernier update**: 2026-03-09 (115 évaluations)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue