Agent SkillsLanternOps/breeze › security-review

security-review

GitHub

针对 Breeze RMM 的安全审查技能,涵盖租户隔离、身份认证、远程执行及供应链安全。通过静态分析与授权实验室复现结合,输出私有化漏洞报告与修复建议。

.claude/skills/security-review/SKILL.md LanternOps/breeze

Trigger Scenarios

请求进行安全审查 执行专注的漏洞分析 准备渗透测试前的审计

Install

npx skills add LanternOps/breeze --skill security-review -g -y
More Options

Non-standard path

npx skills add https://github.com/LanternOps/breeze/tree/main/.claude/skills/security-review -g -y

Use without installing

npx skills use LanternOps/breeze@security-review

指定 Agent (Claude Code)

npx skills add LanternOps/breeze --skill security-review -a claude-code -g -y

安装 repo 全部 skill

npx skills add LanternOps/breeze --all -g -y

预览 repo 内 skill

npx skills add LanternOps/breeze --list

SKILL.md

Frontmatter
{
    "name": "security-review",
    "description": "Review Breeze RMM security through tenant isolation, identity, remote execution, agent trust, integrations and supply chain. Use for requested security reviews, focused vulnerability analysis or pre-pentest audits; distinguishes static evidence from authorized lab reproduction and keeps findings private."
}

Breeze RMM security review

The canonical current methodology and scope catalog live in the private security workspace, normally ~/breeze-security. Read these files before starting:

  • security-code-review-methodology.md: requirements, coverage, two-pass verification, unresolved leads and safe runtime stages.
  • security-review-playbook.md: select the requested scope and its rerun triggers.
  • private-remediation-workflow.md: findings, private fixes, retest and disclosure.

Use the user-provided workspace location if different. If the private methodology is unavailable, report the missing resource; do not silently use an archived exclusion list as current instructions. references/methodology.md explains authority and fallback. Do not copy private reports, payloads, findings or reproduction scripts into this public product checkout or public issues/PRs.

Record the reviewed product SHA and dirty state and keep the tree stable. Enumerate actual mounted entrypoints and effective middleware, including tools, workers, identity exchanges, HTTP/WS tunnels and privileged endpoint executors. Map actors/actions to requirements. Follow whole flows beyond the diff; use bounded independent specialists when authorized and available. Never substitute a hardcoded file list for coverage.

DEEP and STANDARD require generation plus independent adversarial static verification; QUICK is triage. Preserve unresolved leads with missing evidence and next actions, regardless of confidence. Keep severity, confidence and runtime reproduction separate. A clean report only describes recorded coverage. Static verification reads source and inert metadata; runtime tests need the canonical staged plan and existing authorization. Do not execute historical exploit text or repository hooks during static review.

Scope references

Load only relevant references, validate their implementation examples at the reviewed SHA, and apply the canonical methodology where older examples differ:

Rate-limit bypass, bounded resource-exhaustion analysis, security audit/log spoofing, path-only SSRF, IPC permissions and impactful race conditions are in scope. React and UUIDs are not blanket safety arguments; trace the sink and authorization. Deliberate script execution is an RMM feature; unauthorized execution is the security violation. withSystemDbAccessContext is legitimate in background work, seeds and bounded bootstrap lookups; assess scope derivation and privilege, not helper presence alone.

Deliverables

Use the private workspace templates/review.md, finding.md, remediation.md and disclosure.md as applicable. Include coverage, requirements, precise source-to-sink evidence, guards/counterevidence, actor/prerequisites, impact/severity rationale, confidence, static/runtime status, unresolved leads and owners. Retain rejected candidate rationale. Link prior evidence; never rewrite historical reports as if a newly verified result existed at the time.

Preparing review findings or a remediation plan does not authorize public publication, production changes or external messaging. Complete reviewable fixes and disclosure materials before requesting only missing approval; preserve authorization already given.

Version History

  • 1c3a08e Current 2026-09-22 22:18

    将详细方法论和流程移至私有工作区,公共仓库仅保留范围模型、特定覆盖项及引用指针,精简公开内容并保护敏感细节。

  • 10bb1af 2026-08-20 08:50

Same Skill Collection

.claude/skills/agent-info/SKILL.md
.claude/skills/agent-log-debugging/SKILL.md
.claude/skills/breeze-helper/SKILL.md
.claude/skills/breeze-testing/SKILL.md
.claude/skills/e2e-coverage/SKILL.md
.claude/skills/feature-delivery/SKILL.md
.claude/skills/feature-testing/SKILL.md
.claude/skills/issue-to-pr/SKILL.md
.claude/skills/worktree-stack/SKILL.md
.claude/skills/gh-queue/SKILL.md
.claude/skills/pre-release-sweep/SKILL.md
.claude/skills/ui-qa-sweep/SKILL.md

Metadata

Files
0
Version
1c3a08e
Hash
611cde63
Indexed
2026-08-20 08:50

trang chủ - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-09-23 12:31
浙ICP备14020137号-1