Agent Skills › Hmbown/Codewhale › security-review

security-review

GitHub

针对代码变更、模块或网络表面进行安全审查,识别可利用缺陷。涵盖信任边界、认证授权、注入攻击、密钥泄露及依赖风险,确保每个发现都具备可验证的可达路径和修复建议。

crates/tui/assets/skills/security-review/SKILL.md Hmbown/Codewhale

Trigger Scenarios

用户请求对具体代码进行安全审查 用户请求漏洞检查或安全审计

Install

npx skills add Hmbown/Codewhale --skill security-review -g -y
More Options

Non-standard path

npx skills add https://github.com/Hmbown/Codewhale/tree/main/crates/tui/assets/skills/security-review -g -y

Use without installing

npx skills use Hmbown/Codewhale@security-review

指定 Agent (Claude Code)

npx skills add Hmbown/Codewhale --skill security-review -a claude-code -g -y

安装 repo 全部 skill

npx skills add Hmbown/Codewhale --all -g -y

预览 repo 内 skill

npx skills add Hmbown/Codewhale --list

SKILL.md

Frontmatter
{
    "name": "security-review",
    "invocation": "model+user",
    "description": "Review a change, module, or surface for exploitable defects — trust boundaries, authn\/authz, injection, secret exposure, filesystem and network reach, dependency risk. Use when the user asks for a security review, audit, or vulnerability check of concrete code. Not for general code review, lint, or compliance paperwork."
}

Security Review

Produce findings a reviewer can verify, not a vibes pass. Every finding names the file, the reachable path that makes it real, and the fix.

Scope the review first

  • What is under review: a diff, a module, a plugin bundle, a network surface. Say the boundary out loud before reading.
  • Trust boundaries: where untrusted input enters (HTTP handlers, MCP tool args, file parsers, CLI flags, env vars, rendered content) and where authority is exercised (fs writes, network egress, process spawn, credential reads, signing).
  • Prerequisites: a checked-out tree and the project's own test runner. Ask for credentials only if a live path genuinely needs them; never read secrets from the environment or keychain yourself.

Procedure

  1. Map entry points and sinks. rg for the handlers, deserializers, and exec/fs/net calls in scope. Follow data from entry to sink before judging it.
  2. Authn/authz. Every mutating or sensitive handler checks identity and object-level authorization. Look for checks that exist on one path but not its sibling, and for checks done on the client only.
  3. Injection. Command lines, SQL, template eval, shell expansion, path joins under user influence, and markup that will render later — including generated HTML/markdown that carries repo content into a browser surface.
  4. Secrets. rg for token/key/secret patterns and git log -p the diff for credentials. Also check what gets logged or embedded in receipts, exports, or error messages.
  5. Dependencies. Run the project's audit gate if it exists (cargo audit, npm audit, osv-scanner) — report versions and CVEs, not "deps look old".
  6. Denial and abuse paths. Unbounded reads/allocations, missing timeouts on network calls, resource leaks in error paths, retry storms.
  7. Verify a finding before reporting it. Trace the real call path or write a minimal proof. A finding that "looks suspicious" but has no reachable path is a note, not a finding.

Findings format

For each: severity (exploitability × impact), file:line, the reachable path, a one-paragraph explanation, and the fix. Order by severity. Then a short "checked and clean" list naming what was audited and cleared — the scope statement means something only if the clear list is honest.

Recovery and limits

  • If you cannot prove reachability, downgrade the claim and say what evidence is missing.
  • Do not claim a formal audit, certification, or absence of vulnerabilities. This review finds defects; it does not prove none exist.
  • Never fix-and-stay-quiet on a security finding in someone else's in-flight code — report it first.

Completion criteria

  • Every entry point in scope was traced to its sinks.
  • Findings carry file:line + reachability + fix; the clear list names what was actually checked.
  • Severity ordering is defensible by exploitability, not by how loudly the code smells.

Version History

  • 6e005de Current 2026-09-22 10:00

    细化了审查流程,增加了具体步骤(映射入口/汇点、验证发现可达性),明确了输出格式和完成标准,从通用指南升级为结构化操作规范。

  • b0e4926 2026-07-24 17:43

Same Skill Collection

crates/tui/assets/skills/batch/SKILL.md
crates/tui/assets/skills/best-of-n/SKILL.md
crates/tui/assets/skills/contributor-onboarding/SKILL.md
crates/tui/assets/skills/dataviz/SKILL.md
crates/tui/assets/skills/debug/SKILL.md
crates/tui/assets/skills/delegate/SKILL.md
crates/tui/assets/skills/dependency-update/SKILL.md
crates/tui/assets/skills/docx/SKILL.md
crates/tui/assets/skills/feishu/SKILL.md
crates/tui/assets/skills/fleet-manager/SKILL.md
crates/tui/assets/skills/forget/SKILL.md
crates/tui/assets/skills/frontend-design/SKILL.md
crates/tui/assets/skills/gmail/SKILL.md
crates/tui/assets/skills/google-calendar/SKILL.md
crates/tui/assets/skills/handoff/SKILL.md
crates/tui/assets/skills/help/SKILL.md
crates/tui/assets/skills/implement/SKILL.md
crates/tui/assets/skills/interview/SKILL.md
crates/tui/assets/skills/mcp-builder/SKILL.md
crates/tui/assets/skills/mcp-discovery/SKILL.md
crates/tui/assets/skills/pdf/SKILL.md
crates/tui/assets/skills/photos/SKILL.md
crates/tui/assets/skills/plan/SKILL.md
crates/tui/assets/skills/plugin-creator/SKILL.md
crates/tui/assets/skills/pptx/SKILL.md
crates/tui/assets/skills/research/SKILL.md
crates/tui/assets/skills/review/SKILL.md
crates/tui/assets/skills/simplify/SKILL.md
crates/tui/assets/skills/skill-creator/SKILL.md
crates/tui/assets/skills/skill-installer/SKILL.md
crates/tui/assets/skills/test/SKILL.md
crates/tui/assets/skills/v4-best-practices/SKILL.md
crates/tui/assets/skills/verify/SKILL.md
crates/tui/assets/skills/webapp-testing/SKILL.md
crates/tui/assets/skills/xlsx/SKILL.md
docs/skills/codew-release-qa-sweep/SKILL.md
docs/skills/contributor-onboarding/SKILL.md
docs/skills/cw-dogfood/SKILL.md
docs/skills/cw-gates/SKILL.md
docs/skills/cw-handoff/SKILL.md
docs/skills/cw-land/SKILL.md
docs/skills/cw-orient/SKILL.md
docs/skills/cw-slice/SKILL.md
docs/skills/gh-assign-issues/SKILL.md
docs/skills/gh-close-issues/SKILL.md
docs/skills/gh-compile-issues/SKILL.md
docs/skills/gh-credit-harvest/SKILL.md
docs/skills/gh-file-issue/SKILL.md
docs/skills/gh-find-prs/SKILL.md

Metadata

Files
0
Version
94130d9
Hash
3d84c797
Indexed
2026-07-24 17:43

ホーム - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-28 09:47
浙ICP备14020137号-1