W Security

blockmatic/basilic-skills/skills/workflow/w-security

作者 blockmatic7e05e2abd052dc6b526e8a28e36d102d42bfd635无许可证1 个星标收录于 2026年10月9日更新于 2026年10月9日仓库6天前更新

Review the change or tree against repository security docs and existing checks.

仅含说明Security
AI 生成的概览

依据仓库安全文档和现有检查,审查代码变更或代码树中的安全缺陷。

功能
该技能以仓库自身的安全文档和现有扫描器为基准,对变更集或代码树进行仅报告式的安全审查。它先阅读这些文档,再针对变更路径派出两到三个只读探查代理,分别覆盖身份认证与授权、密钥泄露和输入校验,并自行核对每个疑似问题的触发条件与后果。在获得授权时,它可以运行现有的安全脚本或 CI 任务,并记录通过、失败或未运行;在用户授权修复时,它可以修改根本原因。
适用场景
当代码变更或代码树需要基于项目已记录的安全标准和现有检查进行安全审查时使用。它适用于合并前审查、审计式检查和加固工作,且发现应以报告形式呈现而非凭空编造。它不适合没有仓库安全文档的团队,因为此时它会停止并询问,而不会自行设定标准。
运行要求
需要存在仓库安全文档,并能访问变更路径;在运行检查时,还需要项目的安全脚本或 CI 任务(例如通过 package.json)。它本身不附带脚本,仅为指令。它可能启动只读探查子代理,并在获得修复授权时修改代码;策略变更交由人工处理。

Find security defects relative to repository security docs and existing scanners. Do not invent CORS, encryption, password, or header policy. Stay report-only unless the user asked to fix.

  1. Read the repository security docs. If missing, stop and ask; do not invent a bar.
  2. Spawn 2–3 read-only explorers on authn/authz, secret/exposure, and input validation for the changed paths. Reconcile trigger and consequence yourself.
  3. Validate each suspected issue with a trigger and consequence. Skip invented CVEs and timings.
  4. If authorized, run existing security scripts or CI jobs from the docs or package.json. Record passed, failed, or not run.
  5. If fixes are authorized, change the owning cause. Policy changes need a human. Docs: /w-docs if behavior or commands changed.

来源与署名

来源:blockmatic/basilic-skills位于skills/workflow/w-security提交7e05e2a

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架