Security Audit

ruvnet/ruflo/.agents/skills/security-audit

作者 ruvnet6051f6702b61無授權條款74K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

包含腳本Security
AI 產生的概覽

掃描程式碼庫中的弱點,例如注入缺陷、路徑遍歷、硬編碼密鑰和已知 CVE。

功能
此技能會對程式碼庫執行安全掃描與弱點偵測,涵蓋輸入驗證、路徑遍歷、SQL 注入、XSS、硬編碼密鑰和相依套件 CVE。它也支援威脅建模分析,並可產生完整的安全稽核報告,報告可選用 markdown 格式。它附帶兩個可執行指令碼,一個用於完整掃描流程,一個用於自動修復已知 CVE。
適用情境
適用於實作身分驗證、授權邏輯、付款處理、使用者資料處理、API 端點、檔案上傳、資料庫查詢或外部 API 整合時。對於公開資料的唯讀操作、內部開發工具、靜態文件與樣式變更,建議略過。
執行需求
需要 npx 指令與 @claude-flow/cli 套件,該套件透過網路取得。它附帶兩個可執行指令碼 security-scan.sh 與 cve-remediate.sh,並引用文件 docs/security-checklist.md 與 docs/owasp-top10.md。

Security Audit Skill

Purpose

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement.

When to Trigger

  • authentication implementation
  • authorization logic
  • payment processing
  • user data handling
  • API endpoint creation
  • file upload handling
  • database queries
  • external API integration

When to Skip

  • read-only operations on public data
  • internal development tooling
  • static documentation
  • styling changes

Commands

Full Security Scan

Run comprehensive security analysis on the codebase

bash
npx @claude-flow/cli security scan --depth full

Example:

bash
npx @claude-flow/cli security scan --depth full --output security-report.json

Input Validation Check

Check for input validation issues

bash
npx @claude-flow/cli security scan --check input-validation

Example:

bash
npx @claude-flow/cli security scan --check input-validation --path ./src/api

Path Traversal Check

Check for path traversal vulnerabilities

bash
npx @claude-flow/cli security scan --check path-traversal

SQL Injection Check

Check for SQL injection vulnerabilities

bash
npx @claude-flow/cli security scan --check sql-injection

XSS Check

Check for cross-site scripting vulnerabilities

bash
npx @claude-flow/cli security scan --check xss

CVE Scan

Scan dependencies for known CVEs

bash
npx @claude-flow/cli security cve --scan

Example:

bash
npx @claude-flow/cli security cve --scan --severity high

Security Audit Report

Generate full security audit report

bash
npx @claude-flow/cli security audit --report

Example:

bash
npx @claude-flow/cli security audit --report --format markdown --output SECURITY.md

Threat Modeling

Run threat modeling analysis

bash
npx @claude-flow/cli security threats --analyze

Validate Secrets

Check for hardcoded secrets

bash
npx @claude-flow/cli security validate --check secrets

Scripts

ScriptPathDescription
security-scan.agents/scripts/security-scan.shRun full security scan pipeline
cve-remediate.agents/scripts/cve-remediate.shAuto-remediate known CVEs

References

DocumentPathDescription
Security Checklistdocs/security-checklist.mdSecurity review checklist
OWASP Guidedocs/owasp-top10.mdOWASP Top 10 mitigation guide

Best Practices

  1. Check memory for existing patterns before starting
  2. Use hierarchical topology for coordination
  3. Store successful patterns after completion
  4. Document any new learnings

來源與署名

來源:ruvnet/ruflo位於.agents/skills/security-audit提交6051f67

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架