OlympHill
Explain Decision (Grade A) logo

Explain Decision (Grade A)セキュリティテスト済みデータ-AIスキル for Claude AI。A評価。 AxonFlow ポリシーディシジョンの全理由を取得 — マッチしたポリシー、リスクレベル、オーバーライド可用性、リレントヒットカウント

(0)
Daniel Nikulshynレビュー: Daniel Nikulshyn·更新 2026年7月

概要

ExplainDecisonは、セキュリティテスト済みのデータ-AIスキルで、Claude AIに使用して AxonFlowポリシーディシジョンの全理由を提供します。これは、前のポリシーコンターの決定_idが必要であり、パスされた決定_idとリスクレベル、オーバーライド可用性、リクエストのオーバーライドを含むダイジェストを戻します。

主な機能

  • マッチしたポリシーの取得 — ポリシーIDとポリシーナメ
  • リスクレベル (クリティカル、高、平均、低)
  • オーバーライド可用性の表示
  • 24 時間のウィンドウ内でのリレントヒットカウントの提供

料金

モデル
Free
カテゴリー
東学サェソー
評価
まだレビューはありません

ユースケース

ポリシーファンのトラブルシューティング

特定のアクションがブロックされていたり許容されていたりする AxonFlowポリシーを理解するために使用

オーバーライドのリクエスト

ポリシーファンの場合にオーバーライドが利用可能であり、オーバーライドをリクエストするための支援を提供する

メリット & デメリット

メリット

  • ポリシーファンの詳細な説明を提供
  • セキュリティなりすましに関する理解と対処を支援
  • オーバーライドオプションの提案

デメリット

  • 特定の決定_idが必要
  • 存在するポリシーファンの説明のみ

レビュー

レビューを投稿するにはログインしてください。

まだレビューはありません。最初の一人になりましょう!

Q&A

What gets checked

AxonFlow ships with 80+ built-in system policies that apply to Claude Code automatically. No configuration required — new policies added to the platform are immediately enforced in every session. | Category | Coverage | |---|---| | Dangerous commands | Reverse shells (nc -e, bash -i, /dev/tcp/), rm -rf /, dd if=, curl \| bash, credential file access (cat ~/.ssh/, cat ~/.aws/), path traversal | | SQL injection | 30+ patterns including UNION injection, stacked queries, auth bypass, encoding tricks | | PII detection | SSN, credit card, Aadhaar, PAN, email, phone, NRIC/FIN (Singapore), and more — with redaction | | Secrets exposure | API keys, connection strings, hardcoded credentials, code secrets | | SSRF | Cloud metadata endpoint (169.254.169.254) and internal-network blocking | | Prompt injection | Instruction override, jailbreak attempts, role hijacking | | Claude Code-specific | .claude/settings.json write protection, .claude/hooks/.json modification warnings (enabled via AXONFLOWINTEGRATIONS=claude-code) | Custom policies are easy — POST /api/v1/dynamic-policies or the Customer Portal. See Policy Enforcement. ---

Asked by Lena Fischer · Mar 31, 2026

How it works

Governed tools: Bash, Write, Edit, NotebookEdit, and all MCP server tools (mcp). Read-only tools (Read, Glob, Grep) are not governed by default — they don't modify state or send data externally. Fail behavior:** AxonFlow unreachable (network) → fail-open, tool execution continues AxonFlow auth/config error → fail-closed, tool call denied until config is fixed PostToolUse failures → never block (audit and PII scan are best-effort) ---

Asked by Adaeze Uche · Mar 22, 2026

Why you'd add this

Claude Code is Anthropic's official CLI — a fast, agentic coding assistant that edits files, runs shell commands, and calls MCP servers. It's excellent at developer productivity. It was never designed to be the layer where your security and compliance team lives. The gaps start surfacing the moment Claude Code moves from one developer's laptop to a team or production setting: | Production requirement | Claude Code alone | With this plugin | |---|---|---| | Policy enforcement before tool execution | Hooks available, no governance logic | 80+ built-in policies evaluated on every governed tool call | | Dangerous command blocking (rm -rf /, reverse shells, curl \| bash) | Not addressed | Blocked before execution with decision context | | PII / secrets detection in tool outputs | Developer responsibility | Auto-scan; Claude is instructed to use redacted version | | SQL-injection detection on MCP queries | MCP server's problem | 30+ patterns evaluated on every MCP tool call | | Compliance-grade audit trail | Session logs, not compliance-formatted | Every governed call recorded with policies, decision, duration | | Decision explainability after a block | Generic hook failure message | decisionid surfaced in deny reason; explaindecision MCP tool returns the full record | | Self-service, time-bounded exceptions | Not available | createoverride with mandatory justification, fully audited | | Cloud metadata / SSRF / path traversal blocking | Not addressed | Built in** | You get all of t

Asked by Hana Kobayashi · Jan 29, 2026

質問する

東学サェソーの代替

Manage Headers (Grade A) logo

Manage Headers (Grade A)

東学サェソー

セキュリティテストで検証されたClaude AIの開発スキルの「Aレベル」。「Power Pagesサイトからのブラウザへのセキュリティヘッダーの検査および構成」のためのもの。Content Security Policy、フレームとクリックジャッキング保護

(0)
Free
Using Git Worktrees (Grade A) logo

Using Git Worktrees (Grade A)

東学サェソー

セキュリティテスト済みデータAISHILL(Grade A)。クリュードAIと併用する。

(0)
Free
Ga4 Bigquery Schema (Grade A) logo

Ga4 Bigquery Schema (Grade A)

東学サェソー

セキュリティテスト済みのデータ・AIスキル用Claude AI。 Grade A。GA4 BigQuery Export Schemaの参照情報大全、ネスト構造、検索パターン、パフォーマンスのヒント

(0)
Free
Meta Capi (Grade A) logo

Meta Capi (Grade A)

東学サェソー

Security-checked data-ai skill for Claude AI. Grade A. (Meta Conversions API (CAPI)のセットアップガイド — アーキテクチャ、イベントタイプ、顧客情報のハッシュ、削除、実装例、AEM)

(0)
Free
Callees (Grade A) logo

Callees (Grade A)

東学サェソー

Claude AI向けセキュリティ検証済開発スキル。 Grade A. 関数/メソッドはどこにコールしているかをリストする

(0)
Free
Test Module Name (Grade A) logo

Test Module Name (Grade A)

東学サェソー

セキュリティテスト済みデータ-AIスキル、クラウド AI用 Grade A。 モジュールをテストするモジュールと同じネームスペースのSpecサフィックスでモジュール名を付ける。 クラウド AIのテストモジュールライティングまたはレビューに使用してください。

(0)
Free
Board Of Directors (Grade A) logo

Board Of Directors (Grade A)

東学サェソー

SECURITY TESTED DATA-AI SKILL FOR CLAUDE AI. GRADE A. マジョルな決定を実行者 5 人が協議しながらの実行者 5 人によるディレクトオフィス議論シミュレーション。プランの評価やアーキテクチャーセレクション、機能デザイン評価など、複数視点の専門分析を必要とするあらゆる決定を評価するには使用してください。

(0)
Free
Advpl Mvc Avancado (Grade A) logo

Advpl Mvc Avancado (Grade A)

東学サェソー

セキュリティテスト開発スキル for Claude AI. AランクのMVCアドバンス

(0)
Free