W Security

blockmatic/basilic-skills/skills/workflow/w-security

作者 blockmatic7e05e2abd052dc6b526e8a28e36d102d42bfd635無授權條款1 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫6 天前更新

Review the change or tree against repository security docs and existing checks.

僅含說明Security
AI 產生的概覽

依據儲存庫安全文件與現有檢查,審查程式碼變更或程式碼樹中的安全缺陷。

功能
此技能以儲存庫自身的安全文件與現有掃描器為基準,對變更集或程式碼樹進行僅報告式的安全審查。它會先閱讀這些文件,再針對變更路徑派出二到三個唯讀探查代理,分別涵蓋身分驗證與授權、機密外洩及輸入驗證,並自行核對每個疑似問題的觸發條件與後果。在獲得授權時,它可以執行現有的安全指令碼或 CI 工作,並記錄通過、失敗或未執行;在使用者授權修復時,它可以修改根本原因。
適用情境
當程式碼變更或程式碼樹需要依據專案已記錄的安全標準與現有檢查進行安全審查時使用。它適合合併前審查、稽核式檢查與加固工作,且發現應以報告形式呈現而非憑空編造。它不適合沒有儲存庫安全文件的團隊,因為此時它會停止並詢問,而不會自行設定標準。
執行需求
需要存在儲存庫安全文件,並能存取變更路徑;在執行檢查時,還需要專案的安全指令碼或 CI 工作(例如透過 package.json)。它本身不附帶指令碼,僅為指示。它可能啟動唯讀探查子代理,並在獲得修復授權時修改程式碼;原則變更交由人工處理。

Find security defects relative to repository security docs and existing scanners. Do not invent CORS, encryption, password, or header policy. Stay report-only unless the user asked to fix.

  1. Read the repository security docs. If missing, stop and ask; do not invent a bar.
  2. Spawn 2–3 read-only explorers on authn/authz, secret/exposure, and input validation for the changed paths. Reconcile trigger and consequence yourself.
  3. Validate each suspected issue with a trigger and consequence. Skip invented CVEs and timings.
  4. If authorized, run existing security scripts or CI jobs from the docs or package.json. Record passed, failed, or not run.
  5. If fixes are authorized, change the owning cause. Policy changes need a human. Docs: /w-docs if behavior or commands changed.

來源與署名

來源:blockmatic/basilic-skills位於skills/workflow/w-security提交7e05e2a

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架