Agent Skillsasamassekou10/ship-safe › ship-safe-red-team

ship-safe-red-team

GitHub

执行多代理红队扫描,检测注入、认证绕过等80+类安全风险。解析结果并按严重性呈现,针对高危漏洞提供深度分析与修复建议,最终给出加固方案。

claude-code-plugin/skills/ship-safe-red-team/SKILL.md asamassekou10/ship-safe

Trigger Scenarios

需要全面安全审计 检测特定攻击向量 发现潜在漏洞

Install

npx skills add asamassekou10/ship-safe --skill ship-safe-red-team -g -y
More Options

Non-standard path

npx skills add https://github.com/asamassekou10/ship-safe/tree/main/claude-code-plugin/skills/ship-safe-red-team -g -y

Use without installing

npx skills use asamassekou10/ship-safe@ship-safe-red-team

指定 Agent (Claude Code)

npx skills add asamassekou10/ship-safe --skill ship-safe-red-team -a claude-code -g -y

安装 repo 全部 skill

npx skills add asamassekou10/ship-safe --all -g -y

预览 repo 内 skill

npx skills add asamassekou10/ship-safe --list

SKILL.md

Frontmatter
{
    "name": "ship-safe-red-team",
    "description": "Run a multi-agent red team scan — 29 specialized security agents scan for 80+ attack classes including injection, auth bypass, SSRF, supply chain, Supabase RLS, MCP security, agentic AI, RAG poisoning, PII compliance, and more. Use when the user wants a deep security analysis beyond just secrets.",
    "argument-hint": "[path] [--agents <list>]"
}

Ship Safe — Red Team Scan

You are running a multi-agent red team scan using Ship Safe's 29 security agents.

Step 1: Run the red team scan

npx ship-safe@latest red-team $ARGUMENTS --json --no-ai 2>/dev/null

If $ARGUMENTS is empty, default to .:

npx ship-safe@latest red-team . --json --no-ai 2>/dev/null

If the user wants specific agents only, use the --agents flag:

npx ship-safe@latest red-team . --agents injection,auth,ssrf --json --no-ai 2>/dev/null

Available agents include: injection, auth, ssrf, supply-chain, config, llm, mobile, git-history, cicd, api, supabase-rls, mcp, agentic, rag, pii, agent-config, memory-poisoning, managed-agent, hermes, agent-attestation, agentic-supply-chain, roblox-security, model-scan, trust-boundary, slopsquat, clickfix, install-guard

Step 2: Parse and present results

The JSON output contains findings from each agent. Present results grouped by agent:

For each agent that found issues:

  1. Agent name and category (e.g., "InjectionTester — Code Vulnerabilities")
  2. Finding count by severity
  3. Top findings — list critical and high severity findings with:
    • File and line number
    • Rule name and description
    • Code context (if available, show the flagged line with surrounding lines)
    • Suggested fix
    • Confidence level

Agent summary table

Show a table: Agent | Findings | Critical | High | Medium

Agents with zero findings

List them briefly as clean — this is useful context.

Step 3: Deep dive and remediation

For the most critical findings:

  1. Read the actual source file for full context
  2. Explain the vulnerability in plain language — what could an attacker do?
  3. Offer to fix it with a concrete code change
  4. After fixing, offer to re-run just that agent to verify: npx ship-safe@latest red-team . --agents <agent>

Step 4: Recommendations

Based on the results, suggest:

  • Which agents to focus on (highest finding count or most critical findings)
  • Whether to create a baseline (/ship-safe-baseline) for the current state
  • Framework-specific hardening tips based on detected stack (from recon agent)

Important Notes

  • The scanner includes 29 built-in agents. Recon, verification, and scoring run as supporting phases around the agent pool.
  • Agents run in parallel — the scan should complete in under 60 seconds for most projects
  • Low-confidence findings in test files or documentation are likely false positives
  • Never display actual secret values

Version History

  • 68eeae0 Current 2026-07-25 09:52

Same Skill Collection

claude-code-plugin/skills/ship-safe-baseline/SKILL.md
claude-code-plugin/skills/ship-safe-ci/SKILL.md
claude-code-plugin/skills/ship-safe-deep/SKILL.md
claude-code-plugin/skills/ship-safe-fix/SKILL.md
claude-code-plugin/skills/ship-safe-hooks/SKILL.md
claude-code-plugin/skills/ship-safe-score/SKILL.md
claude-code-plugin/skills/ship-safe/SKILL.md

Metadata

Files
0
Version
2bc9fe3
Hash
685488d8
Indexed
2026-07-25 09:52

inicio - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-22 05:02
浙ICP备14020137号-1 $mapa de visitantes$