Code Audit

zhaoxuya520/reverse-skill/skills/code-audit

by zhaoxuya520cab634bd855fNo license40K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 2 weeks ago

Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

Instructions onlySecurity
AI-generated overview

Guides authorized source-code security review and SAST workflows, from threat modeling to verified findings and fixes.

What it does
Provides a workflow for white-box source code security audits: scoping and threat modeling, running SAST tools such as Semgrep, CodeQL, Bandit, gosec and SpotBugs, then manually validating each hit for reachability and exploitability. Produces findings with location, data flow, proof of concept and remediation advice, optionally tagged with CWE or ATT&CK identifiers. Includes a checklist reference for SAST review.
When to use it
Use for authorized security review of your own source code, including pull-request or diff security checks. Suited to hunting dangerous APIs, injection points, missing authorization, IDOR and crypto misuse. Dependency and pipeline concerns are directed to a separate supply-chain skill.
Requirements
Requires authorized source or repository access and a known language stack and scope. Relies on external SAST tooling such as Semgrep, CodeQL, Bandit, gosec or SpotBugs, which must be installed and run by the agent. Ships no scripts; instructions and one reference checklist only.

Source Code Security Audit

ACTION REQUIRED(读完后立刻执行)

  1. NOW: 读取 ../field-journal/precedent-pentest.md 或代码审计授权
  2. NOW: 确认有源码/仓库访问(无源码二进制 → 转 RE skill)
  3. NOW: 明确语言栈与范围(目录/服务/PR diff)
  4. NEXT: tool-index;semgrep 等
  5. ACT: 威胁建模草图 → 自动扫描 → 人工验证

适用场景

  • 白盒审计、PR/差分安全审查
  • Semgrep / CodeQL / Bandit / gosec 等 SAST
  • 危险 API、注入点、鉴权缺失、加密误用
  • 与 supply-chain-security/ 分工:本 skill 偏自有代码逻辑,供应链偏依赖与管道

工作流

1. 范围与威胁模型

text
□ 信任边界:用户输入、文件、反序列化、SSRF、鉴权中间件□ 高价值资产:鉴权、支付、管理端、密钥处理

2. 自动扫描

bash
semgrep --config auto .# 或项目规则包semgrep --config p/owasp-top-ten .

3. 人工验证(MUST)

text
□ 每个 SAST 命中:可达性?可利用性?误报?□ 鉴权:IDOR/越权、缺校验、错误的多租户隔离□ 注入:SQL/命令/模板/LDAP□ 加密:硬编码密钥、ECB、自定义 crypto

4. 产出

text
Finding:位置 + 数据流 + PoC + 修复建议可选 ATT&CK / CWE 编号

工具链

工具语言/场景
Semgrep多语言快速规则
CodeQL深数据流(GitHub)
BanditPython
gosec / staticcheckGo
SpotBugs / FindSecBugsJava

参考

  • references/sast-review-checklist.md
  • ../supply-chain-security/ ../api-security/ ../llm-security/(Agent 代码)

路由上下文

上游: MASTER R26
角色: ops/role-map.md cae
下游: 依赖漏洞 → supply-chain;运行时验证 → pentest-tools

任务完成自检

  • 是否人工验证而非只贴扫描器输出?
  • 是否含修复建议?
  • 是否限定在授权仓库范围?
  • Checklist?

Source and attribution

Source:zhaoxuya520/reverse-skillinskills/code-auditat commitcab634b

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

Code Audit · skills/code-audit Agent Skill | SourceWeft