Commit Security Scan

codexstar69/bug-hunter/skills/commit-security-scan

作者 codexstar693be69733a27aa04d4f5620df203c05350d162067无许可证519 个星标收录于 2026年10月9日更新于 2026年10月9日仓库7周前更新

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. Use whenever the user asks for PR security review, commit-diff scanning, staged-change security checks, branch-comparison security review, or pre-merge security analysis of changed code.

仅含说明Security
AI 生成的概览

使用 STRIDE 分析和 Bug Hunter 产物,审查变更代码中的安全漏洞。

功能
仅针对变更代码进行安全扫描,包括拉取请求、暂存差异、分支差异或提交范围。它会确定变更文件范围,读取这些文件的完整内容,并按照 STRIDE 类别(如仿冒、篡改、信息泄露和权限提升)进行分析。发现结果带有 STRIDE 和 CWE 标签及置信度评分,写入 Bug Hunter 原生产物,例如发现结果 JSON 文件或渲染报告。
适用场景
当用户要求在合并前对拉取请求、暂存变更、分支比较或提交范围进行安全审查时使用。它定位为轻量级、仅限差异范围的快速通道,而非全仓库审计。
运行要求
仅为说明文档,技能不附带脚本。它需要 Bug Hunter 产物路径中的威胁模型上下文,并依赖 git diff 命令确定范围。它引用捆绑的配套技能进行威胁模型生成和漏洞验证,并将发现结果写入 Bug Hunter 产物文件。

Commit Security Scan

This is a bundled local Bug Hunter companion skill. It is portable and self-contained: use .bug-hunter/* artifacts, never .factory/* paths.

Purpose

Review changed code for security issues only. This skill is optimized for:

  • PR review
  • staged diff review
  • branch diff review
  • commit / commit-range security scanning

Inputs

Resolve the scan scope from the user request:

  • PR review → use scripts/pr-scope.cjs
  • staged review → use git diff --cached --name-only
  • branch diff → use git diff --name-only <base>...<head>
  • commit range → use git diff --name-only <base>..<head>

Workflow

  1. Ensure threat-model context exists.

    • Preferred artifacts:
      • .bug-hunter/threat-model.md
      • .bug-hunter/security-config.json
    • If missing, run the bundled threat-model-generation skill first.
  2. Resolve the changed-file scope.

  3. Read the full contents of the changed source files, not just the patch.

  4. Focus on STRIDE-oriented issues in changed code:

    • Spoofing: auth/session/token mistakes
    • Tampering: SQLi, XSS, path traversal, command injection, mass assignment
    • Repudiation: security-sensitive actions with no auditability
    • Information Disclosure: IDOR, secret exposure, verbose errors
    • DoS: unbounded input, missing limits, expensive regex/queries
    • Elevation of Privilege: missing authorization, role bypass, privilege escalation
  5. Reuse Bug Hunter-native security conventions:

    • findings should be compatible with .bug-hunter/hunter-findings.json
    • use STRIDE + CWE labels
    • include confidence scores
  6. If the user wants only a focused security diff review, stop after the findings report. If the user wants deeper validation, hand off to the bundled vulnerability-validation skill.

Output

Preferred outputs:

  • .bug-hunter/hunter-findings.json when integrating with the main Bug Hunter pipeline
  • .bug-hunter/report.md as a rendered companion if needed

Notes

  • This skill is intentionally diff-scoped; it does not replace full-repository audits.
  • Use it as the lightweight security fast-path before invoking the broader security-review flow.

来源与署名

来源:codexstar69/bug-hunter位于skills/commit-security-scan提交3be6973

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架