V3 Security Overhaul

ruvnet/ruflo/v3/@claude-flow/cli/.claude/skills/v3-security-overhaul

作者 ruvnet58e0ae7e14e68aab45a4127d6f42f567bbcfb328無授權條款74K 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫今天更新

Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.

僅含說明Security
AI 產生的概覽

為 claude-flow v3 統籌安全改造,修復重大 CVE 並落實預設安全模式。

功能
此技能透過調度專門的安全代理,為 claude-flow v3 統籌安全架構改造,包括設計威脅模型、修復重大 CVE 以及建立安全測試。它記錄了針對易受攻擊相依套件、弱密碼雜湊與硬編碼憑證的修復方式,並提出安全程式碼模式,例如 Zod 輸入驗證、路徑淨化以及不使用 shell 的指令執行。它也定義成功指標,涵蓋安全評分、CVE 解決率、測試覆蓋率以及已記錄並測試的實作。它產出的是指引與修復說明,而非可執行指令碼。
適用情境
適用於對 claude-flow v3 進行安全優先的實作或改造。適合需要處理所列重大 CVE 並採用預設安全開發實務的工作。也適合為該程式庫建立威脅模型、安全邊界與安全測試覆蓋。
執行需求
需要能調度專門子代理或任務的代理環境;相依套件更新與稽核指令需要 Node.js 與 npm;所示模式需要 bcrypt 與 zod 套件。此技能不附帶指令碼。

V3 Security Overhaul

What This Skill Does

Orchestrates comprehensive security overhaul for claude-flow v3, addressing critical vulnerabilities and establishing security-first development practices using specialized v3 security agents.

Quick Start

bash
# Initialize V3 security domain (parallel)Task("Security architecture", "Design v3 threat model and security boundaries", "v3-security-architect")Task("CVE remediation", "Fix CVE-1, CVE-2, CVE-3 critical vulnerabilities", "security-auditor")Task("Security testing", "Implement TDD London School security framework", "test-architect")

Critical Security Fixes

CVE-1: Vulnerable Dependencies

bash
npm update @anthropic-ai/claude-code@^2.0.31npm audit --audit-level high

CVE-2: Weak Password Hashing

typescript
// ❌ Old: SHA-256 with hardcoded saltconst hash = crypto.createHash('sha256').update(password + salt).digest('hex');
// ✅ New: bcrypt with 12 roundsimport bcrypt from 'bcrypt';const hash = await bcrypt.hash(password, 12);

CVE-3: Hardcoded Credentials

typescript
// ✅ Generate secure random credentialsconst apiKey = crypto.randomBytes(32).toString('hex');

Security Patterns

Input Validation (Zod)

typescript
import { z } from 'zod';
const TaskSchema = z.object({  taskId: z.string().uuid(),  content: z.string().max(10000),  agentType: z.enum(['security', 'core', 'integration'])});

Path Sanitization

typescript
function securePath(userPath: string, allowedPrefix: string): string {  const resolved = path.resolve(allowedPrefix, userPath);  if (!resolved.startsWith(path.resolve(allowedPrefix))) {    throw new SecurityError('Path traversal detected');  }  return resolved;}

Safe Command Execution

typescript
import { execFile } from 'child_process';
// ✅ Safe: No shell interpretationconst { stdout } = await execFile('git', [userInput], { shell: false });

Success Metrics

  • Security Score: 90/100 (npm audit + custom scans)
  • CVE Resolution: 100% of critical vulnerabilities fixed
  • Test Coverage: >95% security-critical code
  • Implementation: All secure patterns documented and tested

來源與署名

來源:ruvnet/ruflo位於v3/@claude-flow/cli/.claude/skills/v3-security-overhaul提交58e0ae7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架