- name
- eastsword-dfyx-code-security-review
- description
- Expert-level code security audit skill using deep data flow analysis, taint tracking, and business logic understanding across 9 languages
- triggers
- ["audit this code for security vulnerabilities","perform a security code review","find security issues in this project","analyze code for security flaws","run security audit on codebase","check for vulnerabilities in source code","conduct white-box security analysis","review code security with dfyx methodology"]
# EastSword DFYX Code Security Review
> Skill by [ara.so](https://ara.so) — Security Skills collection.
Expert-level code security audit skill developed by the EastSword (东方隐侠) team. Performs comprehensive white-box static analysis using a five-phase standardized audit protocol with deep data flow analysis, taint tracking, and business logic understanding.
## Overview
**dfyx_code_security_review** is a professional code security audit skill designed for AI coding agents. It employs white-box static analysis methodology through a five-phase standardized protocol to systematically discover and validate security vulnerabilities in source code.
### Core Capabilities
- **9 Languages**: Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C#, Ruby, Rust
- **14 Frameworks**: Spring Boot, Django, Flask, FastAPI, Express, Koa, Gin, Laravel, Rails, ASP.NET Core, Rust Web, NestJS, Fastify, MyBatis
- **10 Security Dimensions**: Injection, Authentication, Authorization, Deserialization, File Operations, SSRF, Cryptography, Configuration, Business Logic, Supply Chain
- **Triple-Track Audit Model**: Sink-driven + Control-driven + Config-driven
- **Five-Phase Protocol**: Reconnaissance → Pattern Matching → Taint Tracking → Validation → Reporting
- **Rich Case Library**: Based on real-world WooYun vulnerability cases (2010-2016)
## Installation
Clone or copy this skill to your AI client's skills directory:
```bash
# For Claude Code
git clone https://github.com/EastSword/skill-dfyx_code_security_review.git ~/.claude/skills/eastsword-dfyx-code-security-review
# For Cursor
git clone https://github.com/EastSword/skill-dfyx_code_security_review.git ~/Library/Application\ Support/Cursor/skills/eastsword-dfyx-code-security-review
# Install Python dependencies (optional, for helper scripts)
cd ~/.claude/skills/eastsword-dfyx-code-security-review
pip install -r requirements.txt
```
## Five-Phase Audit Protocol
### Phase 1: Reconnaissance & Mapping (10%)
**Objective**: Understand architecture and identify attack surface.
```python
# Example: Architecture Analysis Output
[RECON] Technology Stack: Spring Boot 2.7.3 + MyBatis 3.5.10 + Shiro 1.9.0
[RECON] Attack Surface:
- REST API: 47 endpoints (28 authenticated, 19 public)
- File Upload: 3 endpoints (/api/upload, /admin/import, /user/avatar)
- Template Engine: Thymeleaf (potential SSTI)
- Database: MySQL 8.0.30 (84 SQL queries identified)
[RECON] Security Controls:
- Authentication: Shiro + JWT
- Authorization: @RequiresPermissions annotations (coverage: 67%)
- Input Validation: @Validated + Hibernate Validator (coverage: 45%)
```
**Key Activities**:
- Identify entry points (REST endpoints, file uploads, external integrations)
- Map data flows from sources to sinks
- Enumerate security controls and their coverage
- Build architectural diagram with trust boundaries
### Phase 2: Parallel Pattern Matching (30%)
**Objective**: Identify high-risk code patterns across all dimensions.
```python
# Example: Pattern Scanner Usage
from scripts.pattern_scanner import PatternScanner
scanner = PatternScanner(language='java')
results = scanner.scan('/path/to/project', dimensions=['D1', 'D2', 'D3', 'D4', 'D5'])
# Output Example
[PATTERN] SQL Injection Candidates: 12 locations
- UserService.java:145 - String concatenation in SQL query
- OrderDao.xml:78 - Dynamic SQL with ${} placeholder
[PATTERN] Command Injection Candidates: 3 locations
- FileProcessor.java:234 - Runtime.exec() with user input
[PATTERN] Authentication Bypass Candidates: 5 locations
- AdminController.java:89 - Missing @RequiresAuthentication
- ReportController.java:156 - Direct database authentication check
```
**Detection Rules**:
```yaml
# SQL Injection (Java)
- pattern: executeQuery\s*\(\s*[\w\s]+\s*\+
severity: CRITICAL
description: String concatenation in SQL query
- pattern: \$\{[\w\.]+\}
file_types: [.xml]
severity: CRITICAL
description: MyBatis unsafe placeholder
# Command Injection (Python)
- pattern: os\.system\(.*input.*\)
severity: CRITICAL
description: User input in os.system()
- pattern: subprocess\.(call|run|Popen)\(.*request\.
severity: CRITICAL
description: User input in subprocess execution
```
### Phase 3: Deep Taint Tracking & Validation (40%)
**Objective**: Trace data flows from sources to sinks and validate exploitability.
```python
# Example: Taint Analysis
from scripts.data_flow_analyzer import TaintAnalyzer
analyzer = TaintAnalyzer()
result = analyzer.trace_flow(
source='HttpServletRequest.getParameter("id")',
sink='executeQuery(sql)',
project_path='/path/to/project'
)
# Output Example
[TAINT] Flow Found: REQUEST → SQL_QUERY
Source: UserController.java:45
→ String userId = request.getParameter("userId");
Flow Path:
1. UserController.java:45 → userId (TAINTED)
2. UserController.java:47 → userService.getUserById(userId) (TAINTED)
3. UserService.java:89 → buildQuery(userId) (TAINTED)
4. UserService.java:102 → "SELECT * FROM users WHERE id=" + userId (TAINTED)
5. UserService.java:103 → statement.executeQuery(sql) (SINK - NO SANITIZATION)
Sanitization: NONE
Validation: NONE
Exploitable: YES
POC:
GET /api/user?userId=1' UNION SELECT password FROM admin_users--
```
**Taint Analysis Features**:
- **Source Identification**: HTTP parameters, file reads, environment variables, database queries
- **Sanitization Detection**: Input validation, encoding, parameterized queries, allowlist filtering
- **Sink Detection**: SQL execution, command execution, file operations, template rendering, JNDI lookup
- **Context-Aware Analysis**: Different rules for different contexts (SQL, OS command, XSS, etc.)
```python
# Example: Multi-Stage Taint Flow
[TAINT] Complex Flow: REQUEST → SESSION → DATABASE → TEMPLATE
Stage 1: User input stored in session
UserController.java:67 → session.setAttribute("theme", themeParam)
Stage 2: Session value retrieved in different request
ThemeController.java:34 → String theme = session.getAttribute("theme")
Stage 3: Theme value used in database query
ThemeService.java:89 → "SELECT * FROM themes WHERE name='" + theme + "'"
Stage 4: Query result rendered in template
theme.html:12 → <div th:text="${themeName}"></div> (XSS via SQLi)
Attack Chain: Stored XSS via SQL Injection
Exploitable: YES
```
### Phase 4: Validation & Attack Chain Construction (15%)
**Objective**: Validate vulnerabilities and construct multi-stage attack chains.
```python
# Example: Vulnerability Validation
[VALIDATION] SQL Injection in UserService.getUserById()
Test 1: Syntax Error Injection
Input: userId=1'
Expected: SQL syntax error
Result: ✓ "You have an error in your SQL syntax"
Test 2: Boolean-based Blind SQLi
Input: userId=1 AND 1=1
Response Time: 0.123s
Input: userId=1 AND 1=2
Response Time: 0.125s
Result: ✓ Different responses confirm vulnerability
Test 3: Union-based SQLi
Input: userId=1 UNION SELECT 1,2,3,4,5--
Result: ✓ Column count: 5
Test 4: Data Extraction
Input: userId=1 UNION SELECT null,username,password,null,null FROM admin_users--
Result: ✓ Admin credentials leaked
[ATTACK_CHAIN] Privilege Escalation via SQL Injection
Step 1: Exploit SQLi to extract admin password hash
→ /api/user?userId=1 UNION SELECT password FROM admin_users WHERE role='ADMIN'--
Step 2: Crack password hash (MD5 without salt)
→ hashcat -m 0 -a 0 hash.txt rockyou.txt
Step 3: Login as admin
→ POST /api/login {"username":"admin","password":"cracked_password"}
Step 4: Access admin panel
→ GET /admin/dashboard
Impact: Complete system compromise
Likelihood: HIGH (weak password hashing + no rate limiting)
```
**Attack Chain Patterns**:
```yaml
# Privilege Escalation Chain
chain_type: privilege_escalation
vulnerabilities:
- SQL Injection → Password Hash Extraction
- Weak Cryptography → Hash Cracking
- Missing Rate Limiting → Brute Force
- Insufficient Authorization → Admin Access
# Data Exfiltration Chain
chain_type: data_exfiltration
vulnerabilities:
- Path Traversal → Configuration File Read
- Hardcoded Credentials → Database Access
- Missing Network Segmentation → Internal Network Access
- SSRF → Cloud Metadata API Access
```
### Phase 5: Structured Reporting (5%)
**Objective**: Generate comprehensive, actionable security audit report.
```python
# Example: Report Generation
from scripts.report_generator import ReportGenerator
report = ReportGenerator()
report.add_vulnerability({
'id': 'VUL-001',
'title': 'SQL Injection in User Query',
'severity': 'CRITICAL',
'cvss': 9.8,
'dimension': 'D1-Injection',
'location': 'UserService.java:102',
'description': 'String concatenation in SQL query allows SQL injection',
'exploitation': 'Confirmed via manual testing',
'impact': 'Complete database compromise, authentication bypass',
'poc': 'GET /api/user?userId=1\' UNION SELECT password FROM admin_users--',
'remediation': [
'Use PreparedStatement with parameterized queries',
'Implement input validation with allowlist',
'Apply least privilege principle to database user'
],
'code_vulnerable': '''
String sql = "SELECT * FROM users WHERE id=" + userId;
statement.executeQuery(sql);
''',
'code_fixed': '''
String sql = "SELECT * FROM users WHERE id=?";
PreparedStatement stmt = connection.prepareStatement(sql);
stmt.setString(1, userId);
stmt.executeQuery();
'''
})
report.generate('audit_report.md', format='markdown')
```
## 10 Security Dimensions
### D1: Injection Vulnerabilities
**Coverage**: SQL, Command, LDAP, SSTI, SpEL, JNDI, XSS, XXE
```python
# SQL Injection Detection
patterns = {
'java': [
r'executeQuery\s*\(\s*[\w\s]+\s*\+', # String concatenation
r'createQuery\s*\(\s*".*"\s*\+', # JPA concatenation
r'\$\{[\w\.]+\}' # MyBatis unsafe placeholder
],
'python': [
r'execute\s*\(\s*["\'].*%.*["\']', # String formatting
r'execute\s*\(\s*f["\'].*\{.*\}', # f-string in SQL
r'raw\s*\(\s*["\'].*["\'].*\+' # Django raw query concat
],
'php': [
r'mysql_query\s*\(\s*\$', # mysql_query with variable
r'->query\s*\(\s*\$', # PDO query with variable
r'DB::select\s*\(\s*["\'].*\.', # Laravel string concat
]
}
# Command Injection Detection
patterns = {
'java': [
r'Runtime\.getRuntime\(\)\.exec\(',
r'ProcessBuilder\s*\(\s*.*request',
r'new\s+Process\w*\s*\(',
],
'python': [
r'os\.system\s*\(',
r'subprocess\.(call|run|Popen)\(',
r'eval\s*\(',
r'exec\s*\(',
],
'php': [
r'exec\s*\(',
r'shell_exec\s*\(',
r'system\s*\(',
r'passthru\s*\(',
r'popen\s*\(',
r'proc_open\s*\(',
]
}
```
**Example: SSTI Detection (Python)**
```python
# Vulnerable Code (Flask)
from flask import Flask, request, render_template_string
@app.route('/hello')
def hello():
name = request.args.get('name', 'Guest')
template = '<h1>Hello ' + name + '!</h1>'
return render_template_string(template) # SSTI vulnerability
# Exploitation POC
# GET /hello?name={{config.items()}}
# GET /hello?name={{''.__class__.__mro__[1].__subclasses__()}}
# Fixed Code
from flask import Flask, request, render_template
from markupsafe import escape
@app.route('/hello')
def hello():
name = escape(request.args.get('name', 'Guest'))
return render_template('hello.html', name=name)
```
### D2: Authentication Vulnerabilities
**Coverage**: Token management, Session handling, JWT flaws, Filter chain bypass
```java
// Vulnerable: Hardcoded Credentials
public class DatabaseConfig {
private static final String DB_USER = "admin";
private static final String DB_PASS = "P@ssw0rd123"; // CRITICAL
public Connection getConnection() {
return DriverManager.getConnection(
"jdbc:mysql://localhost:3306/db",
DB_USER, DB_PASS
);
}
}
// Fixed: Environment Variables
public class DatabaseConfig {
private final String dbUser = System.getenv("DB_USER");
private final String dbPass = System.getenv("DB_PASSWORD");
public Connection getConnection() {
if (dbUser == null || dbPass == null) {
throw new IllegalStateException("Database credentials not configured");
}
return DriverManager.getConnection(
Auf GitHub ansehen