Commit Security Scan

codexstar69/bug-hunter/skills/commit-security-scan

作者 codexstar693be69733a27aa04d4f5620df203c05350d162067無授權條款519 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫7 週前更新

Scan code changes for security vulnerabilities using Bug Hunter-native artifacts and STRIDE context. Use whenever the user asks for PR security review, commit-diff scanning, staged-change security checks, branch-comparison security review, or pre-merge security analysis of changed code.

僅含說明Security
AI 產生的概覽

使用 STRIDE 分析與 Bug Hunter 產物,審查變更程式碼中的安全漏洞。

功能
僅針對變更的程式碼進行安全掃描,包括拉取請求、暫存差異、分支差異或提交範圍。它會解析變更檔案範圍,讀取這些檔案的完整內容,並依 STRIDE 類別(如假冒、竄改、資訊揭露與權限提升)進行分析。發現結果帶有 STRIDE 與 CWE 標籤及信心分數,寫入 Bug Hunter 原生產物,例如發現結果 JSON 檔案或渲染報告。
適用情境
當使用者要求在合併前對拉取請求、暫存變更、分支比較或提交範圍進行安全審查時使用。它定位為輕量、僅限差異範圍的快速路徑,而非全儲存庫稽核。
執行需求
僅為說明文件,技能不隨附指令碼。它需要 Bug Hunter 產物路徑中的威脅模型脈絡,並依賴 git diff 指令來解析範圍。它引用隨附的配套技能進行威脅模型產生與漏洞驗證,並將發現結果寫入 Bug Hunter 產物檔案。

Commit Security Scan

This is a bundled local Bug Hunter companion skill. It is portable and self-contained: use .bug-hunter/* artifacts, never .factory/* paths.

Purpose

Review changed code for security issues only. This skill is optimized for:

  • PR review
  • staged diff review
  • branch diff review
  • commit / commit-range security scanning

Inputs

Resolve the scan scope from the user request:

  • PR review → use scripts/pr-scope.cjs
  • staged review → use git diff --cached --name-only
  • branch diff → use git diff --name-only <base>...<head>
  • commit range → use git diff --name-only <base>..<head>

Workflow

  1. Ensure threat-model context exists.

    • Preferred artifacts:
      • .bug-hunter/threat-model.md
      • .bug-hunter/security-config.json
    • If missing, run the bundled threat-model-generation skill first.
  2. Resolve the changed-file scope.

  3. Read the full contents of the changed source files, not just the patch.

  4. Focus on STRIDE-oriented issues in changed code:

    • Spoofing: auth/session/token mistakes
    • Tampering: SQLi, XSS, path traversal, command injection, mass assignment
    • Repudiation: security-sensitive actions with no auditability
    • Information Disclosure: IDOR, secret exposure, verbose errors
    • DoS: unbounded input, missing limits, expensive regex/queries
    • Elevation of Privilege: missing authorization, role bypass, privilege escalation
  5. Reuse Bug Hunter-native security conventions:

    • findings should be compatible with .bug-hunter/hunter-findings.json
    • use STRIDE + CWE labels
    • include confidence scores
  6. If the user wants only a focused security diff review, stop after the findings report. If the user wants deeper validation, hand off to the bundled vulnerability-validation skill.

Output

Preferred outputs:

  • .bug-hunter/hunter-findings.json when integrating with the main Bug Hunter pipeline
  • .bug-hunter/report.md as a rendered companion if needed

Notes

  • This skill is intentionally diff-scoped; it does not replace full-repository audits.
  • Use it as the lightweight security fast-path before invoking the broader security-review flow.

來源與署名

來源:codexstar69/bug-hunter位於skills/commit-security-scan提交3be6973

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架