Scan

作者 AikidoSec02f018ad4da1无许可证14 个星标收录于 2026年10月7日更新于 2026年10月7日仓库12天前更新

Runs an Aikido security scan on generated, added, or modified code files to detect SAST vulnerabilities and exposed secrets. Use when the user wants to scan code for security issues, after writing or modifying code, or when they mention Aikido, security scan, or SAST. Always run an Aikido scan after generating code to verify the generated code is free of security issues.

仅含说明Security
AI 生成的概览

对生成或修改的代码运行 Aikido 安全扫描,以发现 SAST 漏洞和泄露的密钥。

功能
该技能指示代理对本次会话中生成、新增或修改的文件运行 Aikido 安全扫描。它要求代理使用 Aikido MCP 扫描工具,说明每个问题的严重程度和位置,应用修复,并重新扫描以验证修复效果。它还规定了修复与重扫循环的停止条件,并要求向用户提交最终报告。
适用场景
当用户希望扫描代码安全问题、在编写或修改代码之后,或提到 Aikido、安全扫描或 SAST 时使用。它也用于在生成代码后运行,以确认代码没有安全问题。
运行要求
需要 Aikido MCP 服务器及其扫描工具;若不可用,会提示用户按照 reference.md 中的安装指南进行安装。该技能不附带脚本,仅为说明性指令。

When scanning the code for security vulnerabilities using the Aikido MCP server:

  1. Identify all files that were generated, added, or modified in this session (or that the user has mentioned).
  2. Prefer aikido-mcp:aikido_scan_paths whenever the files exist on disk (files you just wrote/edited, files reported by git status/git diff, files the user points at). Pass the file paths (absolute, or relative to a root you provide) — do not read the files first, the server reads them itself, so passing content would only waste context. Only fall back to aikido-mcp:aikido_full_scan for code that is not saved to disk yet (a proposed diff, a pasted snippet, freshly generated code you haven't written out) — for that tool, read each file's full content and pass it along.
  3. Stay within the 50-file limit per request for either tool — batch into multiple calls if needed.
  4. If any security issues are found:
    • Explain each issue clearly: title, description, severity, file location, and line numbers.
    • Apply fixes guided by the remediation provided by Aikido.
    • After applying all fixes, re-run the same tool (aikido-mcp:aikido_scan_paths for on-disk files, aikido-mcp:aikido_full_scan otherwise) to verify that the issues were resolved and no new issues were introduced.
    • Stopping the loop: If you can explain why the applied fix is safe (e.g. the fix correctly addresses the finding and the remaining scan output is a false positive or acceptable), you may stop and report to the user. Otherwise, repeat the fix-and-rescan cycle up to 3 attempts; if issues remain after that, report them to the user instead of continuing.
  5. Report the final scan result to the user — confirm all clear or list any unresolved issues with explanation.

If the Aikido MCP server is not available or fails to start, inform the user:

The Aikido MCP server is required for security scanning but is not available. Install it following the setup guide at reference.md [blocked].

来源与署名

来源:AikidoSec/aikido-claude-plugin位于skills/scan提交02f018a

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架