跳到主内容
智客 ZICQ

技能库 智客分类:安全测试 security-review

安全审查

对薄弱环节进行安全守则审查。 被请求时用于"安全审查","发现弱点","检查安全问题","审计安全","OWASP审查",或审查注射,XSS,认证,授权,密码问题等代码. 为系统审查提供基于信任的报告.

16908 安装量

官方网址:skills.sh

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

脆弱性安全守则审查

何时用

请求"安全审查","发现弱点","检查安全问题","审计安全","OWASP审查",或审查注射,XSS,认证,授权,加密问题等代码. 提供基于信任的系统审查报告

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Security Review Skill、Scope: Research vs. Reporting、Confidence Levels、Do Not Flag、General Rules、Server-Controlled Values (NOT Attacker-Controlled)。

文件分析

文件分析:除 SKILL.md 外,正文还引用了 references/,属于带资源的技能包,代理会按需再读这些文件。

官方 description(原文)

Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

Security Review SkillScope: Research vs. ReportingConfidence LevelsDo Not FlagGeneral RulesServer-Controlled Values (NOT Attacker-Controlled)SAFE: URL comes from Django settings (server-controlled)VULNERABLE: URL comes from request (attacker-controlled)Framework-Mitigated PatternsReview Process1. Detect Context2. Load Language Guide

· 许可:LICENSE · allowed-tools:Read, Grep, Glob, Bash, Task

来源分类:skills.sh agent-skill

SKILL.md 与 Agent 调用

官方规范 ↗
name
security-review
description
Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.
allowed-tools
Read, Grep, Glob, Bash, Task实验字段,支持情况取决于客户端;字段声明本身不会授予工具权限。
许可
LICENSE
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「security-review」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-ec9ad07b00b01040-%E5%AE%89%E5%85%A8%E5%AE%A1%E6%9F%A5.html
请存为 .cursor/skills/security-review/SKILL.md 或 .claude/skills/security-review/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
该技能还带 scripts/、references/、assets/ 等文件,请从 https://github.com/getsentry/skills 取完整目录,不要只建一个 SKILL.md。

GitHub 完整包 ↗

终端安装 · Skills CLI

需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。

npx skills add 'https://github.com/getsentry/skills' --list

npx skills add 'https://github.com/getsentry/skills' --skill 'security-review'

CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。

阅读排版
--- name: security-review description: Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting. allowed-tools: Read, Grep, Glob, Bash, Task license: LICENSE --- # Security Review Skill Identify exploitable security vulnerabilities in code. Report only **HIGH CONFIDENCE** findings—clear vulnerable patterns with attacker-controlled input. ## Scope: Research vs. Reporting **CRITICAL DISTINCTION:** - **Report on**: Only the specific file, diff, or code provided by the user - **Research**: The ENTIRE codebase to build confidence before reporting Before flagging any issue, you MUST research the codebase to understand: - Where does this input actually come from? (Trace data flow) - Is there validation/sanitization elsewhere? - How is this configured? (Check settings, config files, middleware) - What framework protections exist? **Do NOT report issues based solely on pattern matching.** Investigate first, then report only what you're confident is exploitable. ## Confidence Levels | Level | Criteria | Action | |-------|----------|--------| | **HIGH** | Vulnerable pattern + attacker-controlled input confirmed | **Report** with severity | | **MEDIUM** | Vulnerable pattern, input source unclear | **Note** as "Needs verification" | | **LOW** | Theoretical, best practice, defense-in-depth | **Do not report** | ## Do Not Flag ### General Rules - Test files (unless explicitly reviewing test security) - Dead code, commented code, documentation strings - Patterns using **constants** or **server-controlled configuration** - Code paths that require prior authentication to reach (note the auth requirement instead) ### Server-Controlled Values (NOT Attacker-Controlled) These are configured by operators, not controlled by attackers: | Source | Example | Why It's Safe | |--------|---------|---------------| | Django settings | `settings.API_URL`, `settings.ALLOWED_HOSTS` | Set via config/env at deployment | | Environment variables | `os.environ.get('DATABASE_URL')` | Deployment configuration | | Config files | `config.yaml`, `app.config['KEY']` | Server-side files | | Framework constants | `django.conf.settings.*` | Not user-modifiable | | Hardcoded values | `BASE_URL = "https://api.internal"` | Compile-time constants | **SSRF Example - NOT a vulnerability:** ```python # SAFE: URL comes from Django settings (server-controlled) response = requests.get(f"{settings.SEER_AUTOFIX_URL}{path}") ``` **SSRF Example - IS a vulnerability:** ```python # VULNERABLE: URL comes from request (attacker-controlled) response = requests.get(request.GET.get('url')) ``` ### Framework-Mitigated Patterns Check language guides before flagging. Common false positives: | Pattern | Why It's Usually Safe | |---------|----------------------| | Django `{{ variable }}` | Auto-escaped by default | | React `{variable}` | Auto-escaped by default | | Vue `{{ variable }}` | Auto-escaped by default | | `User.objects.filter(id=input)` | ORM parameterizes queries | | `cursor.execute("...%s", (input,))` | Parameterized query | | `innerHTML = "Loading..."` | Constant string, no user input | **Only flag these when:** - Django: `{{ var|safe }}`, `{% autoescape off %}`, `mark_safe(user_input)` - React: `dangerouslySetInnerHTML={{__html: userInput}}` - Vue: `v-html="userInput"` - ORM: `.raw()`, `.extra()`, `RawSQL()` with string interpolation ## Review Process ### 1. Detect Context What type of code am I reviewing? | Code Type | Load These References | |-----------|----------------------| | API endpoints, routes | `authorization.md`, `authentication.md`, `injection.md` | | Frontend, templates | `xss.md`, `csrf.md` | | File handling, uploads | `file-security.md` | | Crypto, secrets, tokens | `cryptography.md`, `data-protection.md` | | Data serialization | `deserialization.md` | | External requests | `ssrf.md` | | Business workflows | `business-logic.md` | | GraphQL, REST design | `api-security.md` | | Config, headers, CORS | `misconfiguration.md` | | CI/CD, dependencies | `supply-chain.md` | | Error handling | `error-handling.md` | | Audit, logging | `logging.md` | ### 2. Load Language Guide Based on file extension or imports: | Indicators | Guide | |------------|-------| | `.py`, `django`, `flask`, `fastapi` | `languages/python.md` | | `.js`, `.ts`, `express`, `react`, `vue`, `next` | `languages/javascript.md` | | `.go`, `go.mod` | `languages/go.md` | | `.rs`, `Cargo.toml` | `languages/rust.md` | | `.java`, `spring`, `@Controller` | `languages/java.md` | ### 3. Load Infrastructure Guide (if applicable) | File Type | Guide | |-----------|-------| | `Dockerfile`, `.dockerignore` | `infrastructure/docker.md` | | K8s manifests, Helm charts | `infrastructure/kubernetes.md` | | `.tf`, Terraform | `infrastructure/terraform.md` | | GitHub Actions, `.gitlab-ci.yml` | `infrastructure/ci-cd.md` | | AWS/GCP/Azure configs, IAM | `infrastructure/cloud.md` | ### 4. Research Before Flagging **For each potential issue, research the codebase to build confidence:** - Where does this value actually come from? Trace the data flow. - Is it configured at deployment (settings, env vars) or from user input? - Is there validation, sanitization, or allowlisting elsewhere? - What framework protections apply? Only report issues where you have HIGH confidence after understanding the broader context. ### 5. Verify Exploitability For each potential finding, confirm: **Is the input attacker-controlled?** | Attacker-Controlled (Investigate) | Server-Controlled (Usually Safe) | |-----------------------------------|----------------------------------| | `request.GET`, `request.POST`, `request.args` | `settings.X`, `app.config['X']` | | `request.json`, `request.data`, `request.body` | `os.environ.get('X')` | | `request.headers` (most headers) | Hardcoded constants | | `request.cookies` (unsigned) | Internal service URLs from config | | URL path segments: `/users//` | Database content from admin/system | | File uploads (content and names) | Signed session data | | Database content from other users | Framework settings | | WebSocket messages | | **Does the framework mitigate this?** - Check language guide for auto-escaping, parameterization - Check for middleware/decorators that sanitize **Is there validation upstream?** - Input validation before this code - Sanitization libraries (DOMPurify, bleach, etc.) ### 6. Report HIGH Confidence Only Skip theoretical issues. Report only what you've confirmed is exploitable after research. --- ## Severity Classification | Severity | Impact | Examples | |----------|--------|----------| | **Critical** | Direct exploit, severe impact, no auth required | RCE, SQL injection to data, auth bypass, hardcoded secrets | | **High** | Exploitable with conditions, significant impact | Stored XSS, SSRF to metadata, IDOR to sensitive data | | **Medium** | Specific conditions required, moderate impact | Reflected XSS, CSRF on state-changing actions, path traversal | | **Low** | Defense-in-depth, minimal direct impact | Missing headers, verbose errors, weak algorithms in non-critical context | --- ## Quick Patterns Reference ### Always Flag (Critical) ``` eval(user_input) # Any language exec(user_input) # Any language pickle.loads(user_data) # Python yaml.load(user_data) # Python (not safe_load) unserialize($user_data) # PHP deserialize(user_data) # Java ObjectInputStream shell=True + user_input # Python subprocess child_process.exec(user) # Node.js ``` ### Always Flag (High) ``` innerHTML = userInput # DOM XSS dangerouslySetInnerHTML={user} # React XSS v-html="userInput" # Vue XSS f"SELECT * FROM x WHERE {user}" # SQL injection `SELECT * FROM x WHERE ${user}` # SQL injection os.system(f"cmd {user_input}") # Command injection ``` ### Always Flag (Secrets) ``` password = "hardcoded" api_key = "sk-..." AWS_SECRET_ACCESS_KEY = "..." private_key = "-----BEGIN" ``` ### Check Context First (MUST Investigate Before Flagging) ``` # SSRF - ONLY if URL is from user input, NOT from settings/config requests.get(request.GET['url']) # FLAG: User-controlled URL requests.get(settings.API_URL) # SAFE: Server-controlled config requests.get(f"{settings.BASE}/{x}") # CHECK: Is 'x' user input? # Path traversal - ONLY if path is from user input open(request.GET['file']) # FLAG: User-controlled path open(settings.LOG_PATH) # SAFE: Server-controlled config open(f"{BASE_DIR}/{filename}") # CHECK: Is 'filename' user input? # Open redirect - ONLY if URL is from user input redirect(request.GET['next']) # FLAG: User-controlled redirect redirect(settings.LOGIN_URL) # SAFE: Server-controlled config # Weak crypto - ONLY if used for security purposes hashlib.md5(file_content) # SAFE: File checksums, caching hashlib.md5(password) # FLAG: Password hashing random.random() # SAFE: Non-security uses (UI, sampling) random.random() for token # FLAG: Security tokens need secrets module ``` --- ## Output Format ```markdown ## Security Review: [File/Component Name] ### Summary - **Findings**: X (Y Critical, Z High, ...) - **Risk Level**: Critical/High/Medium/Low - **Confidence**: High/Mixed ### Findings #### [VULN-001] [Vulnerability Type] (Severity) - **Location**: `file.py:123` - **Confidence**: High - **Issue**: [What the vulnerability is] - **Impact**: [What an attacker could do] - **Evidence**: ```python [Vulnerable code snippet] ``` - **Fix**: [How to remediate] ### Needs Verification #### [VERIFY-001] [Potential Issue] - **Location**: `file.py:456` - **Question**: [What needs to be verified] ``` If no vulnerabilities found, state: "No high-confidence vulnerabilities identified." --- ## Reference Files ### Core Vulnerabilities (`references/`) | File | Covers | |------|--------| | `injection.md` | SQL, NoSQL, OS command, LDAP, template injection | | `xss.md` | Reflected, stored, DOM-based XSS | | `authorization.md` | Authorization, IDOR, privilege escalation | | `authentication.md` | Sessions, credentials, password storage | | `cryptography.md` | Algorithms, key management, randomness | | `deserialization.md` | Pickle, YAML, Java, PHP deserialization | | `file-security.md` | Path traversal, uploads, XXE | | `ssrf.md` | Server-side request forgery | | `csrf.md` | Cross-site request forgery | | `data-protection.md` | Secrets exposure, PII, logging | | `api-security.md` | REST, GraphQL, mass assignment | | `business-logic.md` | Race conditions, workflow bypass | | `modern-threats.md` | Prototype pollution, LLM injection, WebSocket | | `misconfiguration.md` | Headers, CORS, debug mode, defaults | | `error-handling.md` | Fail-open, information disclosure | | `supply-chain.md` | Dependencies, build security | | `logging.md` | Audit failures, log injection | ### Language Guides (`languages/`) - `python.md` - Django, Flask, FastAPI patterns - `javascript.md` - Node, Express, React, Vue, Next.js - `go.md` - Go-specific security patterns - `rust.md` - Rust unsafe blocks, FFI security - `java.md` - Spring, Java EE patterns ### Infrastructure (`infrastructure/`) - `docker.md` - Container security - `kubernetes.md` - K8s RBAC, secrets, policies - `terraform.md` - IaC security - `ci-cd.md` - Pipeline security - `cloud.md` - AWS/GCP/Azure security

相关技能

安全测试

技能维特Skill Vetter

人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.

安全测试

护身符Moltguard

MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…

安全测试

安保审计员Security Auditor

用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.

安全测试

技能维特Skill Vetter

安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .