BEST Practices Skill
Security, modern web APIs, 與 code quality 模式。
逐篇公開審查紀錄
桌面審查結論
best-practices 已通過四項桌面門檻。實用性評為 high:Condenses Lighthouse best-practices findings and OWASP guidance into copy-paste fixes, so you skip hunting across MDN, OWASP, and blog posts for each warning.
工作與觸發邊界、完整內容、來源授權依賴,以及安全測試方式均可確認;保留為已審核,但不占固定 30 席。
- 它完成什麼工作
- A checklist of modern web development standards covering HTTPS, CSP headers, input sanitization, deprecated API avoidance, and HTML validity. Based on Lighthouse best practices audits, it gives concrete before/after code examples for common security and compatibility issues.
- 實質幫助
- 高 — Condenses Lighthouse best-practices findings and OWASP guidance into copy-paste fixes, so you skip hunting across MDN, OWASP, and blog posts for each warning.
- 應該啟用
- Reviewing a site for mixed HTTP content before a production push
- Writing a Content Security Policy with nonces for inline scripts
- Replacing document.write and synchronous XHR in legacy code
- Adding passive touchstart listeners to fix scroll jank
- 不該啟用
- 需求不屬於「best-practices」的工作範圍,或只是名稱相近但交付物不同。
- 無法提供必要輸入、適用技術棧或可隔離的測試環境。
- 輸入
- 明確授權的測試範圍、目標內容、威脅模型與合規標準
- 輸出
- 可重現的發現、風險分級與安全修正建議
來源、授權與依賴
來源:原始來源:https://github.com/addyosmani/web-quality-skills/tree/main/skills/best-practices;於 2026-08-08T15:34:07.434Z 取得 642 行,SHA-256 432875ade263e2509fa6888ebc5cf6c65f93074be73924ad6cceb7ec3ba9ccef。
授權:上游授權檔檢出 MIT;本館 catalog 欄位依 README 正式授權章節維持 MIT。
依賴:原文未明示需另行安裝的套件;仍須依實際執行環境確認工具可用性。
快照:開啟審查來源 · 642 行 · SHA-256 432875ade263… · 2026-08-08T15:34:07.434Z
安全測試邊界
使用合成、非敏感的明確授權的測試範圍、目標內容、威脅模型與合規標準,只評估可重現的發現、風險分級與安全修正建議;不連線到正式環境,不提交或發布結果。
- 不得使用真實憑證、敏感資料或正式環境
- 不得發布、交易、寄送訊息或執行不可逆變更
這是可安全執行的測試方案;只有固定 30 席推薦 Skill 另有三類實測通過證據。
價值證據
- 642 行內容、12 個主要小節
- 33 個程式碼區塊、0 個編號步驟、21 個檢查項
限制
桌面審查未發現額外限制;仍不等同推薦或正式環境保證。
啟用時機
當你需要Security, modern web APIs, 與 code quality 模式時使用。
適合使用情境
- 需要Security, modern web APIs, 與 code quality 模式。
- 想使用 addyosmani/best-practices 這類已整理好的 Agent Skill,而不是從零撰寫 prompt。
- 需要從 awesome-agent-skills 索引快速找到 - Google Chrome team - Addy Osmani (Web Quality) 相關 Skill。
Skill 檔案
awesome-agent-skills README catalog entry
工作流程
- 先開啟原始來源,確認該 Skill 的安裝方式、支援工具與限制。
- 把 Skill 放到對應 agent 或 IDE 的 skills 目錄。
- 用一個小型真實任務測試 Skill 是否會在正確時機啟用。
- 確認輸出符合原始 Skill 的工作契約,再匯入日常工作流。
使用注意事項
- 這筆是 awesome-agent-skills 的索引項,本 workspace 未包含完整 SKILL.md。
- 實際安裝前請回到原始來源確認最新內容、授權與目錄結構。
來源
來源頁標題:BEST Practices Skill
來源識別名稱:addyosmani/best-practices
Security, modern web APIs, and code quality patterns
software-engineering-prompt-repos/awesome-agent-skills/README.md
開啟來源這個 Skill 在做什麼
Security, modern web APIs, 與 code quality 模式。這筆資料來自 awesome-agent-skills 的索引清單,原始專案是 addyosmani/best-practices。
為什麼值得收錄
它屬於 - Google Chrome team - Addy Osmani (Web Quality) 相關的 Agent Skill,可作為尋找、安裝或評估同類 Skill 的入口。因為來源 repo 本身沒有把完整 Skill 檔案放在本地,所以此頁保留 catalog 資訊與原始連結,避免把索引項誤認為完整 SKILL.md。
來源 Skill
這筆資料來自 awesome-agent-skills 的上游索引清單;本 workspace 沒有下載完整 SKILL.md。請開啟來源連結檢視或安裝原始 Skill。
開啟原始 Skill