跳到主内容
智客 ZICQ

技能库 智客分类:安全测试 audit-website

Audit Website

审计一个网站 与松鼠扫描CLI 并固定 发现代码。 运行SEO,性能,安全性,技术,内容,可访问性等15个其它规则类别(260+规则),返回LLM-优化报告,再驱动迭接固定回路,将问题映射到源文件,应用修正,并重新审计直到站点得分良好. 用于发现和评估网站或网络应用问题并驱动它们固定.

70947 安装量

官方网址:skills.sh

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

审计一个网站 与松鼠扫描CLI 并固定 发现代码。 运行SEO,性能,安全性,技术,内容,可访问性等15个其它规则类别(260+规则),返回LLM-优化报告,再驱动迭接固定回路,将问题映射到源文件,应用修正,并重新审计直到站点得分良好. 用于发现和评估网站或网络应用问题并驱动它们固定.

何时用

官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Audit a Website and Fix It、Rule docs、Running the audit、Scan progression、The fix loop、Score targets。

文件分析

文件分析:除 SKILL.md 外,正文引用了 references/OUTPUT-FORMAT.md,属于带资源的技能包,这些文件按需再读。

官方 description(原文)

Audit a website with the squirrelscan CLI and fix the findings in code. Runs SEO, performance, security, technical, content, accessibility, and 15 other rule categories (260+ rules), returns an LLM-optimized report, then drives an iterative fix loop, mapping issues to source files, applying fixes, and re-auditing until the site scores well. Use to discover and assess website or webapp issues and drive them to fixed.

Audit a Website and Fix ItRule docsRunning the auditScan progressionThe fix loopScore targetsVerifying regressionsCompletionReport format

兼容:Requires squirrel CLI installed and accessible in PATH · 许可:See LICENSE file in repository root · allowed-tools:Bash(squirrel:*) Read Edit Grep Glob

来源分类:skills.sh agent-skill

SKILL.md 与 Agent 调用

官方规范 ↗
name
audit-website
description
Audit a website with the squirrelscan CLI and fix the findings in code. Runs SEO, performance, security, technical, content, accessibility, and 15 other rule categories (260+ rules), returns an LLM-optimized report, then drives an iterative fix loop, mapping issues to source files, applying fixes, and re-auditing until the site scores well. Use to discover and assess website or webapp issues and drive them to fixed.
compatibility
Requires squirrel CLI installed and accessible in PATH
allowed-tools
Bash(squirrel:*) Read Edit Grep Glob实验字段,支持情况取决于客户端;字段声明本身不会授予工具权限。
许可
See LICENSE file in repository root
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。
指令中引用的文件 · 1
  • references/OUTPUT-FORMAT.md

以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「audit-website」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-2b17a76fa7775978-Audit-Website.html
请存为 .cursor/skills/audit-website/SKILL.md 或 .claude/skills/audit-website/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
该技能还带 scripts/、references/、assets/ 等文件,请从 https://github.com/squirrelscan/skills 取完整目录,不要只建一个 SKILL.md。

GitHub 完整包 ↗

终端安装 · Skills CLI

需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。

npx skills add 'https://github.com/squirrelscan/skills' --list

npx skills add 'https://github.com/squirrelscan/skills' --skill 'audit-website'

CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。

阅读排版
--- name: audit-website description: Audit a website with the squirrelscan CLI and fix the findings in code. Runs SEO, performance, security, technical, content, accessibility, and 15 other rule categories (260+ rules), returns an LLM-optimized report, then drives an iterative fix loop, mapping issues to source files, applying fixes, and re-auditing until the site scores well. Use to discover and assess website or webapp issues and drive them to fixed. license: See LICENSE file in repository root compatibility: Requires squirrel CLI installed and accessible in PATH metadata: author: squirrelscan version: "2.1" allowed-tools: Bash(squirrel:*) Read Edit Grep Glob --- # Audit a Website and Fix It Run a squirrelscan audit against a website, read the LLM report, map each issue to the code or content that causes it, fix in batches, and re-audit until the score target is met. Requires the `squirrel` CLI ([squirrelscan.com/download](https://squirrelscan.com/download); verify with `squirrel --version`). For CLI setup, login, publishing, MCP, and general CLI usage, use the companion `squirrelscan` skill. ## Rule docs Look up any rule at `https://docs.squirrelscan.com/rules/{rule_category}/{rule_id}`, for example: https://docs.squirrelscan.com/rules/links/external-links ## Running the audit ```bash squirrel audit https://example.com --format llm ``` - Use `--format llm`: it is compact, exhaustive, and made for agents. - If the user doesn't provide a URL, ask which site to audit. - Prefer auditing the live site: only there do you see true rendering, performance, and redirect behavior. If both a local dev server and a live site exist, suggest the live one; apply the fixes to the local code either way. - Audits are cached locally. Re-render later without recrawling: `squirrel report --format llm`. ### Scan progression 1. **First pass, quick coverage** (the default): a fast, shallow scan to learn the site's structure, technology, and biggest problems without impacting the site. 2. **Second pass, deeper coverage**: `-C surface` (one page per URL pattern) for template-level coverage, or `-C full` for a comprehensive crawl before sign-off. | Mode | Default pages | Use | |------|---------------|-----| | `quick` | 25 | First look, CI checks | | `surface` | 100 | Template-level coverage (one sample per pattern like `/blog/{slug}`) | | `full` | 500 | Final verification, deep analysis | Useful flags: `--refresh` (ignore cache, full re-fetch), `--resume` (continue an interrupted crawl), `-m ` (page cap), `--verbose` (progress detail). If the site blocks unknown crawlers (Shopify / Cloudflare), pass Web Bot Auth headers with repeated `-H "Name: Value"` flags. Header values are secrets and are redacted in output. See https://docs.squirrelscan.com/guides/web-bot-auth ## The fix loop 1. **Present the report**: score, grade, top issues by severity. 2. **Propose fixes**: list the issues you can fix and confirm with the user before changing anything. 3. **Map issues to source**: find the template, component, or content file behind each finding. 4. **Fix in batches**: apply the approved fixes. 5. **Re-audit** (use `--refresh` after deploys or content changes) and show before/after scores. 6. **Repeat** until the target is met or only judgment calls remain (for example "should this link be removed?"). Flag those for user review instead of guessing. After each batch, verify the project still builds and existing checks pass. ### Score targets | Starting score | Target | Expected work | |----------------|--------|---------------| | < 50 (F) | 75+ (C) | Major fixes | | 50-70 (D) | 85+ (B) | Moderate fixes | | 70-85 (C) | 90+ (A) | Polish | | > 85 (B+) | 95+ | Fine-tuning | Sign off against a `-C full` crawl, since the quick pass samples only part of the site. Rules carry a level (error, warning, notice) and a rank (1-10): fix errors first, then high-rank warnings. Findings that need a content edit count the same as ones that need a code edit. Broken links usually need a human decision (remove, replace, or keep): flag them rather than guessing. ## Verifying regressions Compare against a baseline to prove improvement or catch regressions: ```bash squirrel report --diff --format llm squirrel report --regression-since example.com --format llm ``` ## Completion Done means: all errors fixed; warnings fixed or documented as needing human review; a re-audit confirms the improvement; and the user has seen the before/after score comparison plus a summary of every change made. Re-audit regularly to keep the site healthy. If the user wants to share results, offer a published report (see the `squirrelscan` skill). ## Report format The LLM report is a compact XML/text hybrid optimized for token efficiency: summary with health score, issues grouped by category with affected URLs, broken links, and prioritized recommendations. Full spec: [OUTPUT-FORMAT.md](references/OUTPUT-FORMAT.md)

相关技能

安全测试

Skill Vetter

人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.

安全测试

Moltguard

MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…

安全测试

Security Auditor

用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.

安全测试

Skill Vetter

安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .