Scan

作者 AikidoSec02f018ad4da1無授權條款14 個星標收錄於 2026年10月7日更新於 2026年10月7日儲存庫12 天前更新

Runs an Aikido security scan on generated, added, or modified code files to detect SAST vulnerabilities and exposed secrets. Use when the user wants to scan code for security issues, after writing or modifying code, or when they mention Aikido, security scan, or SAST. Always run an Aikido scan after generating code to verify the generated code is free of security issues.

僅含說明Security
AI 產生的概覽

對產生或修改的程式碼執行 Aikido 安全掃描,以找出 SAST 漏洞與外洩的密鑰。

功能
此技能指示代理對本次工作階段中產生、新增或修改的檔案執行 Aikido 安全掃描。它要求代理使用 Aikido MCP 掃描工具,說明每個問題的嚴重程度與位置,套用修正,並重新掃描以驗證修正結果。它也訂出修正與重掃循環的停止條件,並要求向使用者提出最終報告。
適用情境
當使用者想要掃描程式碼的安全問題、在撰寫或修改程式碼之後,或提到 Aikido、安全掃描或 SAST 時使用。它也用于在產生程式碼後執行,以確認程式碼沒有安全問題。
執行需求
需要 Aikido MCP 伺服器及其掃描工具;若無法使用,會提示使用者依照 reference.md 中的安裝指南進行安裝。此技能不附帶指令碼,僅為說明性指示。

When scanning the code for security vulnerabilities using the Aikido MCP server:

  1. Identify all files that were generated, added, or modified in this session (or that the user has mentioned).
  2. Prefer aikido-mcp:aikido_scan_paths whenever the files exist on disk (files you just wrote/edited, files reported by git status/git diff, files the user points at). Pass the file paths (absolute, or relative to a root you provide) — do not read the files first, the server reads them itself, so passing content would only waste context. Only fall back to aikido-mcp:aikido_full_scan for code that is not saved to disk yet (a proposed diff, a pasted snippet, freshly generated code you haven't written out) — for that tool, read each file's full content and pass it along.
  3. Stay within the 50-file limit per request for either tool — batch into multiple calls if needed.
  4. If any security issues are found:
    • Explain each issue clearly: title, description, severity, file location, and line numbers.
    • Apply fixes guided by the remediation provided by Aikido.
    • After applying all fixes, re-run the same tool (aikido-mcp:aikido_scan_paths for on-disk files, aikido-mcp:aikido_full_scan otherwise) to verify that the issues were resolved and no new issues were introduced.
    • Stopping the loop: If you can explain why the applied fix is safe (e.g. the fix correctly addresses the finding and the remaining scan output is a false positive or acceptable), you may stop and report to the user. Otherwise, repeat the fix-and-rescan cycle up to 3 attempts; if issues remain after that, report them to the user instead of continuing.
  5. Report the final scan result to the user — confirm all clear or list any unresolved issues with explanation.

If the Aikido MCP server is not available or fails to start, inform the user:

The Aikido MCP server is required for security scanning but is not available. Install it following the setup guide at reference.md [blocked].

來源與署名

來源:AikidoSec/aikido-claude-plugin位於skills/scan提交02f018a

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架