Security

作者 parcadeid07ff4b06b62无许可证3.9K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库8个月前更新

Security audit workflow - vulnerability scan → verification

仅含说明Security
AI 生成的概览

运行两阶段安全审计工作流:漏洞扫描,然后验证修复。

功能
该技能定义了一套安全审计工作流,先扫描代码中的漏洞,再验证修复情况。它覆盖注入攻击、身份认证与授权问题、数据保护、配置问题以及依赖风险,并按严重程度报告发现的问题,附上位置和修复步骤。第二阶段会重新检查已报告的问题,运行安全相关测试和依赖审计,并确认修复不会引入回归。
适用场景
当被要求进行安全审计、漏洞检查,或审查身份认证、支付相关代码时使用。它面向身份认证、支付、用户数据等安全敏感场景,也用于修复后重新验证。
运行要求
仅为说明性指令,不附带脚本。它依赖名为 aegis 和 arbiter 的代理子代理类型,并提到 npm audit、pip audit 等依赖审计命令。

/security - Security Audit Workflow

Dedicated security analysis for sensitive code.

When to Use

  • "Security audit"
  • "Check for vulnerabilities"
  • "Is this secure?"
  • "Review authentication code"
  • "Check for injection attacks"
  • Before handling auth, payments, user data
  • After adding security-sensitive features

Workflow Overview

┌─────────┐    ┌───────────┐│  aegis  │───▶│ arbiter  ││         │    │           │└─────────┘    └───────────┘  Security       Verify  audit          fixes

Agent Sequence

#AgentRoleOutput
1aegisComprehensive security scanVulnerability report
2arbiterVerify fixes, run security testsVerification report

Why Dedicated Security?

The /review workflow focuses on code quality. Security needs:

  • Specialized vulnerability patterns
  • Dependency scanning
  • Secret detection
  • OWASP Top 10 checks
  • Authentication/authorization review

Execution

Phase 1: Security Audit

Task(  subagent_type="aegis",  prompt="""  Security audit: [SCOPE]
  Scan for:
  **Injection Attacks:**  - SQL injection  - Command injection  - XSS (Cross-Site Scripting)  - LDAP injection
  **Authentication/Authorization:**  - Broken authentication  - Session management issues  - Privilege escalation  - Insecure direct object references
  **Data Protection:**  - Sensitive data exposure  - Hardcoded secrets/credentials  - Insecure cryptography  - Missing encryption
  **Configuration:**  - Security misconfigurations  - Default credentials  - Verbose error messages  - Missing security headers
  **Dependencies:**  - Known vulnerable packages  - Outdated dependencies  - Supply chain risks
  Output: Detailed report with:  - Severity (CRITICAL/HIGH/MEDIUM/LOW)  - Location (file:line)  - Description  - Remediation steps  """)

Phase 2: Verification (After Fixes)

Task(  subagent_type="arbiter",  prompt="""  Verify security fixes: [SCOPE]
  Run:  - Security-focused tests  - Dependency audit (npm audit, pip audit)  - Re-check reported vulnerabilities  - Verify fixes don't introduce regressions
  Output: Verification report  """)

Security Scopes

Full Codebase

User: /security→ Scan entire codebase

Specific Area

User: /security authentication→ Focus on auth-related code

Single File

User: /security src/api/auth.py→ Deep dive on one file

Dependencies Only

User: /security --deps→ Only dependency vulnerabilities

Example

User: /security the payment processing code
Claude: Starting /security audit for payment code...
Phase 1: Security audit...[Spawns aegis]
┌─────────────────────────────────────────────────────────────┐│ Security Audit Report                                       │├─────────────────────────────────────────────────────────────┤│ Scope: src/services/payment/                                ││ Files scanned: 12                                           ││ Lines analyzed: 2,847                                       │├─────────────────────────────────────────────────────────────┤│ CRITICAL (1)                                                ││ ──────────                                                  ││ [C1] SQL Injection in payment.py:89                         ││      query = f"SELECT * FROM orders WHERE id = {order_id}"  ││      Fix: Use parameterized queries                         ││                                                             ││ HIGH (2)                                                    ││ ────────                                                    ││ [H1] Hardcoded API key in stripe_client.py:12               ││      STRIPE_KEY = "sk_live_..."                             ││      Fix: Move to environment variable                      ││                                                             ││ [H2] Missing input validation in refund.py:45               ││      amount = request.json['amount']  # No validation       ││      Fix: Validate amount is positive number                ││                                                             ││ MEDIUM (1)                                                  ││ ──────────                                                  ││ [M1] Verbose error messages in error_handler.py:23          ││      return {"error": str(e)}  # Leaks internal details     ││      Fix: Return generic message, log details internally    ││                                                             ││ LOW (0)                                                     ││ ───────                                                     ││ None                                                        │├─────────────────────────────────────────────────────────────┤│ Summary: 1 critical, 2 high, 1 medium, 0 low                ││ Status: BLOCKING - Fix critical issues before release       │└─────────────────────────────────────────────────────────────┘
Fix the critical and high issues, then run:/security --verify

After Fixes

User: /security --verify
Claude: Phase 2: Verifying fixes...[Spawns arbiter]
✅ C1: SQL injection fixed - using parameterized queries✅ H1: API key moved to environment variable✅ H2: Input validation added✅ M1: Error messages sanitized
All security tests passing.Security audit: PASSED

OWASP Top 10 Coverage

RiskChecked
A01 Broken Access Control✅
A02 Cryptographic Failures✅
A03 Injection✅
A04 Insecure Design✅
A05 Security Misconfiguration✅
A06 Vulnerable Components✅
A07 Auth Failures✅
A08 Data Integrity Failures✅
A09 Logging Failures✅
A10 SSRF✅

Flags

  • --deps: Dependencies only
  • --verify: Re-run after fixes
  • --owasp: Explicit OWASP Top 10 report
  • --secrets: Focus on secret detection

来源与署名

来源:parcadei/continuous-claude-v3位于.claude/skills/security提交d07ff4b

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架