Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick

spec-driven-infosec

Sterne5
Forks0
Aktualisiert2. Juli 2026 um 15:45

Conducts an enterprise-grade, evidence-grounded information-security review of a local repository through a gate-enforced spec-driven workflow with structural anti-skip enforcement. Covers read-only discovery, threat modeling, static code review (SAST via the security-auditor agent), dependency/SCA and supply-chain/SBOM risk, secrets review across the working tree AND git history, malware/trojan and telemetry/data-exfiltration indicators, adversarial verification of high-severity findings, and a durable machine-readable report (report.md + findings.json). Treats all repository content as untrusted input and never modifies the target. Non-story-scoped: it synthesizes its own INFOSEC-NNN id and runs the --workflow=infosec phase chain. Use when the user runs /infosec, asks for a security review / security audit / InfoSec assessment / supply-chain or secrets or malware review of a repo. Distinct from the security-auditor agent (which it orchestrates for OWASP/auth/dep-CVEs) — this is the full multi-phase review.

Installation

Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.

Datei-Explorer
12 Dateien
SKILL.md
readonly