Security Review

codexstar69/bug-hunter/skills/security-review

作者 codexstar693be69733a27aa04d4f5620df203c05350d162067無授權條款519 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫7 週前更新

Run a focused STRIDE-based security review using Bug Hunter-native artifacts. Use whenever the user asks for a full security audit, repository security review, weekly security scan, PR security review with deeper validation, or wants dependency CVEs and threat-model context combined into one workflow.

僅含說明Security
AI 產生的概覽

以 STRIDE 為基礎對程式碼儲存庫進行安全審查,結合威脅模型、程式碼掃描與相依性漏洞發現。

功能
此技能引導一套以安全為核心的審查流程,依 STRIDE 掃描程式碼中的威脅,並將威脅模型脈絡與相依性發現結果合併。它支援多種掃描模式,包括提取請求差異、暫存變更、每週提交範圍與完整儲存庫稽核。它會驗證嚴重發現,並將結構化產出(例如 hunter-findings.json、referee.json、report.md 以及選用的 fix-strategy.json)寫入 .bug-hunter 目錄。
適用情境
當使用者要求完整安全稽核、儲存庫或 PR 安全審查、每週安全掃描,或希望把相依性 CVE 與威脅模型脈絡整合到同一個工作流程時使用。它適用於比單純缺陷排查更深入的稽核。
執行需求
需要 Bug Hunter 配套環境,包括內含 threat-model.md、triage.json 與 security-config.json 的 .bug-hunter 目錄,以及內建的 threat-model-generation 與 vulnerability-validation 技能。相依性掃描使用 node scripts/dep-scan.cjs。此技能本身不附帶指令碼,僅為指示文件。

Security Review

This is a bundled local Bug Hunter companion skill. It packages a security-focused review workflow without introducing any external marketplace dependency.

Purpose

Use this skill for deeper security audits than a simple bug hunt, especially when the user wants:

  • a full security review
  • PR security validation
  • weekly security scanning
  • dependency reachability + code review together
  • threat-model-driven analysis

Workflow

  1. Ensure .bug-hunter/threat-model.md exists.

    • If missing, invoke the bundled threat-model-generation skill.
  2. Determine the scan mode from the request:

    • PR → diff-scoped review via commit-security-scan
    • staged → staged-only security review
    • weekly → recent commit range on the default branch
    • full → full repository security audit
  3. If dependency scanning is relevant, run:

    • node scripts/dep-scan.cjs --target <path> --output .bug-hunter/dep-findings.json
  4. Scan code for STRIDE threats using Bug Hunter-native conventions. Reuse:

    • .bug-hunter/triage.json
    • .bug-hunter/threat-model.md
    • .bug-hunter/security-config.json
    • .bug-hunter/dep-findings.json
  5. Validate severe findings using the bundled vulnerability-validation skill.

  6. Produce structured outputs compatible with the Bug Hunter pipeline.

Outputs

Primary artifacts should stay inside .bug-hunter/:

  • .bug-hunter/hunter-findings.json
  • .bug-hunter/referee.json
  • .bug-hunter/report.md
  • .bug-hunter/dep-findings.json when dependency review is enabled
  • .bug-hunter/fix-strategy.json if the user wants remediation planning

Important constraints

  • Keep all paths Bug Hunter-native; do not emit .factory/* artifacts.
  • Prefer validated, exploitability-aware findings over raw volume.
  • For patching requests, hand findings back to the normal Bug Hunter fix pipeline rather than inventing a second patch system.

來源與署名

來源:codexstar69/bug-hunter位於skills/security-review提交3be6973

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架