بنقرة واحدة
security-audit
Scans the codebase for OWASP Top 10 vulnerabilities (Secrets, Injection, Auth) and manages SECURITY.md.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
القائمة
Scans the codebase for OWASP Top 10 vulnerabilities (Secrets, Injection, Auth) and manages SECURITY.md.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
Comprehensive code review covering Functionality, Security (OWASP), Performance, and Maintainability. Includes good/bad examples.
Generates robust, cross-platform launcher scripts (Windows .bat, Unix .sh, Mac .sh) with dependency checking, .env handling, and graceful shutdown logic.
Automates the creation of professional-grade Antigravity skills. Incorporates best practices for progressive disclosure, resource organization, and automatic agent registration.
Scans the current conversation thread and updates a project work log. Useful for tracking progress and generating release notes.
A strict, scientific debugging protocol (The "Iron Law"). No fixes allowed without root cause investigation.
Generates standardized API documentation (OpenAPI/Markdown) for backend endpoints.
استنادا إلى تصنيف SOC المهني
| name | security_audit |
| description | Scans the codebase for OWASP Top 10 vulnerabilities (Secrets, Injection, Auth) and manages SECURITY.md. |
Use this skill to perform a "Paranoid Mode" security sweep.
grep_search to find secrets ("API_KEY", "password") and vulnerable patterns (innerHTML, eval).view_file to check auth logic..env. Add .env to .gitignore.$1 vs string concat).innerHTML or dangerouslySetInnerHTML./admin, /delete) have middleware checks?package.json or requirements.txt for known vulnerable versions.SECURITY.md)Create/Update the report in the root:
SECURITY.md is updated.When auditing APIs specifically, verify the following patterns: