技能库
智客分类:安全测试
review
审查
(forwward) 执行偏执密码审查,检查信任边界,数据完整性,性能,种族条件,错误处理,以及OWASP安全. 触发代码审查,前置检查,安全审计,捕虫,或任何审查,审计,或检查代码质量的要求.
40 安装量
官方网址:skills.sh
技能介绍
先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。
做什么
(forwward) 执行偏执密码审查,检查信任边界,数据完整性,性能,种族条件,错误处理,以及OWASP安全. 触发代码审查,前置检查,安全审计,捕虫,或任何审查,审计,或检查代码质量的要求.
何时用
官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。
代理如何加载
按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Review — Paranoid Code Review、Mindset、Review Checklist、1. Trust Boundaries、2. Data Integrity、3. Performance。
文件分析
文件分析:这是一份仅含 SKILL.md 的指令型技能,代理激活后整份正文进入上下文。
官方 description(原文)
(forwward) Performs paranoid code review checking trust boundaries, data integrity, performance, race conditions, error handling, and OWASP security. Triggers on code review, pre-merge checks, security audit, bug hunting, or any request to review, audit, or check code quality.
Review — Paranoid Code ReviewMindsetReview Checklist1. Trust Boundaries2. Data Integrity3. Performance4. Race Conditions5. Error Handling6. Security (OWASP Top 10)How to ReviewOutput Format
来源分类:skills.sh agent-skill
来源与网址
namereview
description- (forwward) Performs paranoid code review checking trust boundaries, data integrity, performance, race conditions, error handling, and OWASP security. Triggers on code review, pre-merge checks, security audit, bug hunting, or any request to review, audit, or check code quality.
- 发现技能客户端向 Agent 提供名称与描述目录。
- 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
- 按需加载按步骤读取参考文档、使用脚本与素材。
具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗
先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。
交给 Agent 安装
复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。
把 Agent Skill「review」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-20843368fb4d6463-%E5%AE%A1%E6%9F%A5.html
请存为 .cursor/skills/review/SKILL.md 或 .claude/skills/review/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
GitHub 完整包 ↗
终端安装 · Skills CLI
需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。
npx skills add 'https://github.com/iankiku/forwward-teams' --list
npx skills add 'https://github.com/iankiku/forwward-teams' --skill 'review'
CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。
阅读排版
name: review
description: (forwward) Performs paranoid code review checking trust boundaries, data integrity, performance, race conditions, error handling, and OWASP security. Triggers on code review, pre-merge checks, security audit, bug hunting, or any request to review, audit, or check code quality.
Review — Paranoid Code Review
Find the bugs that pass tests. Think like an attacker, reason like a debugger.
Mindset
You are reviewing code that will run in production. Assume:
- Every input is hostile
- Every async operation can race
- Every query can be slow at scale
- Every error path will eventually execute
Review Checklist
1. Trust Boundaries
- [ ] User input validated at the boundary using the stack's schema/validation tool
- [ ] Auth checked before business logic
- [ ] No secrets in client-accessible code
- [ ] API responses don't leak internal details
2. Data Integrity
- [ ] Multi-table writes wrapped in transactions
- [ ] Optimistic concurrency or locking where needed
- [ ] No orphaned records on partial failure
- [ ] Cascading deletes are intentional
3. Performance
- [ ] No N+1 queries (look for loops with DB calls)
- [ ] Pagination on list endpoints
- [ ] Indexes on columns used in WHERE/JOIN
- [ ] No unbounded arrays or objects in memory
4. Race Conditions
- [ ] Concurrent requests to same resource handled
- [ ] Check-then-act patterns use atomic operations
- [ ] Shared mutable state is synchronized
- [ ] Idempotency keys on critical mutations
5. Error Handling
- [ ] Errors caught at appropriate level (not swallowed)
- [ ] User-facing errors are helpful, not internal stack traces
- [ ] Retry logic has backoff and max attempts
- [ ] Partial failures don't leave corrupt state
6. Security (OWASP Top 10)
- [ ] No injection attacks (parameterized queries, prepared statements, ORM guards — never string-concat into SQL or shell commands)
- [ ] No XSS (output encoding, CSP headers)
- [ ] No CSRF (tokens on state-changing requests)
- [ ] No insecure direct object references
- [ ] Rate limiting on auth endpoints
How to Review
- Read the diff — understand what changed and why
- Trace data flow — from input to output, follow the data
- Check edge cases — nulls, empty arrays, concurrent requests, large inputs
- Question assumptions — "what if this fails?" at every step
- Verify tests exist — for the happy path AND the failure modes
Output Format
For each issue found:
[SEVERITY] file:line — Description
Why: Explanation of the risk
Fix: Suggested change
Severities: CRITICAL (must fix), HIGH (should fix), MEDIUM (consider), LOW (nit)
相关技能
安全测试
技能维特Skill Vetter
人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.
安全测试
护身符Moltguard
MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…
安全测试
安保审计员Security Auditor
用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.
安全测试
技能维特Skill Vetter
安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .