Find Bugs

作者 getsentryd18b7aa8ba87无许可证1K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库5天前更新

Find bugs, security vulnerabilities, and code quality issues in local branch changes. Use when asked to review changes, find bugs, security review, or audit code on the current branch.

AI 生成的概览

审查本地分支改动中的缺陷、安全漏洞和代码质量问题,仅报告发现而不修改代码。

功能
引导智能体对当前分支的差异进行五阶段审查:获取完整差异、梳理改动文件的攻击面、逐项执行安全检查清单、验证每个潜在问题,并在得出结论前进行复核。最终产出按优先级排序的问题报告,包含文件与行号、严重程度、问题描述、证据和修复建议。该技能明确不修改代码,由用户决定如何处理。
适用场景
适用于被要求审查改动、查找缺陷、进行安全审查或审计当前分支代码的场景。适合合并前或提交前对本地分支差异的审查,而非全仓库或依赖项审计。
运行要求
需要 git 以获取差异,并需要 GitHub CLI(gh)来确定默认分支;该命令可能需要访问 GitHub 的网络连接。仅为说明文档,不附带脚本。

Find Bugs

Review changes on this branch for bugs, security vulnerabilities, and code quality issues.

Phase 1: Complete Input Gathering

  1. Get the FULL diff: git diff $(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')...HEAD
  2. If output is truncated, read each changed file individually until you have seen every changed line
  3. List all files modified in this branch before proceeding

Phase 2: Attack Surface Mapping

For each changed file, identify and list:

  • All user inputs (request params, headers, body, URL components)
  • All database queries
  • All authentication/authorization checks
  • All session/state operations
  • All external calls
  • All cryptographic operations

Phase 3: Security Checklist (check EVERY item for EVERY file)

  • Injection: SQL, command, template, header injection
  • XSS: All outputs in templates properly escaped?
  • Authentication: Auth checks on all protected operations?
  • Authorization/IDOR: Access control verified, not just auth?
  • CSRF: State-changing operations protected?
  • Race conditions: TOCTOU in any read-then-write patterns?
  • Session: Fixation, expiration, secure flags?
  • Cryptography: Secure random, proper algorithms, no secrets in logs?
  • Information disclosure: Error messages, logs, timing attacks?
  • DoS: Unbounded operations, missing rate limits, resource exhaustion?
  • Business logic: Edge cases, state machine violations, numeric overflow?

Phase 4: Verification

For each potential issue:

  • Check if it's already handled elsewhere in the changed code
  • Search for existing tests covering the scenario
  • Read surrounding context to verify the issue is real

Phase 5: Pre-Conclusion Audit

Before finalizing, you MUST:

  1. List every file you reviewed and confirm you read it completely
  2. List every checklist item and note whether you found issues or confirmed it's clean
  3. List any areas you could NOT fully verify and why
  4. Only then provide your final findings

Output Format

Prioritize: security vulnerabilities > bugs > code quality

Skip: stylistic/formatting issues

For each issue:

  • File:Line - Brief description
  • Severity: Critical/High/Medium/Low
  • Problem: What's wrong
  • Evidence: Why this is real (not already fixed, no existing test, etc.)
  • Fix: Concrete suggestion
  • References: OWASP, RFCs, or other standards if applicable

If you find nothing significant, say so - don't invent issues.

Do not make changes - just report findings. I'll decide what to address.

来源与署名

来源:getsentry/skills位于skills/find-bugs提交d18b7aa

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架