Secure Code Review

securityskills/skills/secure-code-review/secure-code-review

作者 securityskillsb2b6b5200ee91a249816df209a0b89ff01ae450a无许可证收录于 2026年10月9日更新于 2026年10月9日

Perform a security-focused code review — map trust boundaries, audit input paths and auth flows, and use vulnerability-class-driven checklists instead of line-by-line skimming. Use on any PR or codebase with security implications.

仅含说明Security

添加到 SourceWeft 工作区

  1. 在控制台中打开该技能,并将它添加到工作区。
  2. 为需要使用它的对话启用该技能。

该技能仅含说明:不附带任何可执行的脚本。

添加到 SourceWeft

系统会先要求你登录,然后直接带你回到这个技能。

让你的智能体来安装

把这段提示词粘贴到 Claude Code、Codex、Cursor 或其他能运行命令的智能体中,也可以粘贴到 SourceWeft 对话里。智能体会阅读这个技能的安装说明,向你展示它的来源、许可证和脚本情况,在你同意后用 SourceWeft CLI 安装。

阅读 https://sourceweft.com/skills/gh-securityskills-skills-secure-code-review-secure-code-review-secure-code-review-e5cf0aa631c0f5d2/install.md 中的说明,按说明安装这个技能。安装前先告诉我它的来源、许可证以及是否附带脚本,等我确认。修改我电脑上的其他任何内容之前也要先问我。

查看智能体所遵循的安装说明

用命令行自行安装

适用于 Claude Code、Codex、Cursor 及其他本地智能体。SourceWeft CLI 会从源代码仓库中获取此处扫描过的那次提交,并根据扫描时记录的哈希值逐一校验每个文件。只要有任何不一致,就不会写入任何内容。

npx @sourceweft/cli skills install @securityskills/secure-code-review

添加 --agent claude-code、codex、cursor 或 universal 来选择安装给哪个智能体(默认为 Claude Code)。

上游安装器——未经 SourceWeft 校验

开源的 skills 安装器会获取同一个固定的提交,但不会根据 SourceWeft 记录的哈希值校验文件。

npx skills add https://github.com/securityskills/skills/tree/b2b6b5200ee91a249816df209a0b89ff01ae450a/secure-code-review/secure-code-review

来源与署名

来源:securityskills/skills位于secure-code-review/secure-code-review提交b2b6b52

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架