Skip to main content

eastsword-dfyx-code-security-review

Expert-level code security audit skill using deep data flow analysis, taint tracking, and business logic understanding across 9 languages

Quellinformationen

Repository
reason-machines/security-skills
Letzte Quellaktivität
8. Juni 2026 um 11:18
Erkannte Sprache von SKILL.md
Englisch
Sterne
12
Forks
1

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
eastsword-dfyx-code-security-review
description
Expert-level code security audit skill using deep data flow analysis, taint tracking, and business logic understanding across 9 languages
triggers
["audit this code for security vulnerabilities","perform a security code review","find security issues in this project","analyze code for security flaws","run security audit on codebase","check for vulnerabilities in source code","conduct white-box security analysis","review code security with dfyx methodology"]
# EastSword DFYX Code Security Review > Skill by [ara.so](https://ara.so) — Security Skills collection. Expert-level code security audit skill developed by the EastSword (东方隐侠) team. Performs comprehensive white-box static analysis using a five-phase standardized audit protocol with deep data flow analysis, taint tracking, and business logic understanding. ## Overview **dfyx_code_security_review** is a professional code security audit skill designed for AI coding agents. It employs white-box static analysis methodology through a five-phase standardized protocol to systematically discover and validate security vulnerabilities in source code. ### Core Capabilities - **9 Languages**: Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C#, Ruby, Rust - **14 Frameworks**: Spring Boot, Django, Flask, FastAPI, Express, Koa, Gin, Laravel, Rails, ASP.NET Core, Rust Web, NestJS, Fastify, MyBatis - **10 Security Dimensions**: Injection, Authentication, Authorization, Deserialization, File Operations, SSRF, Cryptography, Configuration, Business Logic, Supply Chain - **Triple-Track Audit Model**: Sink-driven + Control-driven + Config-driven - **Five-Phase Protocol**: Reconnaissance → Pattern Matching → Taint Tracking → Validation → Reporting - **Rich Case Library**: Based on real-world WooYun vulnerability cases (2010-2016) ## Installation Clone or copy this skill to your AI client's skills directory: ```bash # For Claude Code git clone https://github.com/EastSword/skill-dfyx_code_security_review.git ~/.claude/skills/eastsword-dfyx-code-security-review # For Cursor git clone https://github.com/EastSword/skill-dfyx_code_security_review.git ~/Library/Application\ Support/Cursor/skills/eastsword-dfyx-code-security-review # Install Python dependencies (optional, for helper scripts) cd ~/.claude/skills/eastsword-dfyx-code-security-review pip install -r requirements.txt ``` ## Five-Phase Audit Protocol ### Phase 1: Reconnaissance & Mapping (10%) **Objective**: Understand architecture and identify attack surface. ```python # Example: Architecture Analysis Output [RECON] Technology Stack: Spring Boot 2.7.3 + MyBatis 3.5.10 + Shiro 1.9.0 [RECON] Attack Surface: - REST API: 47 endpoints (28 authenticated, 19 public) - File Upload: 3 endpoints (/api/upload, /admin/import, /user/avatar) - Template Engine: Thymeleaf (potential SSTI) - Database: MySQL 8.0.30 (84 SQL queries identified) [RECON] Security Controls: - Authentication: Shiro + JWT - Authorization: @RequiresPermissions annotations (coverage: 67%) - Input Validation: @Validated + Hibernate Validator (coverage: 45%) ``` **Key Activities**: - Identify entry points (REST endpoints, file uploads, external integrations) - Map data flows from sources to sinks - Enumerate security controls and their coverage - Build architectural diagram with trust boundaries ### Phase 2: Parallel Pattern Matching (30%) **Objective**: Identify high-risk code patterns across all dimensions. ```python # Example: Pattern Scanner Usage from scripts.pattern_scanner import PatternScanner scanner = PatternScanner(language='java') results = scanner.scan('/path/to/project', dimensions=['D1', 'D2', 'D3', 'D4', 'D5']) # Output Example [PATTERN] SQL Injection Candidates: 12 locations - UserService.java:145 - String concatenation in SQL query - OrderDao.xml:78 - Dynamic SQL with ${} placeholder [PATTERN] Command Injection Candidates: 3 locations - FileProcessor.java:234 - Runtime.exec() with user input [PATTERN] Authentication Bypass Candidates: 5 locations - AdminController.java:89 - Missing @RequiresAuthentication - ReportController.java:156 - Direct database authentication check ``` **Detection Rules**: ```yaml # SQL Injection (Java) - pattern: executeQuery\s*\(\s*[\w\s]+\s*\+ severity: CRITICAL description: String concatenation in SQL query - pattern: \$\{[\w\.]+\} file_types: [.xml] severity: CRITICAL description: MyBatis unsafe placeholder # Command Injection (Python) - pattern: os\.system\(.*input.*\) severity: CRITICAL description: User input in os.system() - pattern: subprocess\.(call|run|Popen)\(.*request\. severity: CRITICAL description: User input in subprocess execution ``` ### Phase 3: Deep Taint Tracking & Validation (40%) **Objective**: Trace data flows from sources to sinks and validate exploitability. ```python # Example: Taint Analysis from scripts.data_flow_analyzer import TaintAnalyzer analyzer = TaintAnalyzer() result = analyzer.trace_flow( source='HttpServletRequest.getParameter("id")', sink='executeQuery(sql)', project_path='/path/to/project' ) # Output Example [TAINT] Flow Found: REQUEST → SQL_QUERY Source: UserController.java:45 → String userId = request.getParameter("userId"); Flow Path: 1. UserController.java:45 → userId (TAINTED) 2. UserController.java:47 → userService.getUserById(userId) (TAINTED) 3. UserService.java:89 → buildQuery(userId) (TAINTED) 4. UserService.java:102 → "SELECT * FROM users WHERE id=" + userId (TAINTED) 5. UserService.java:103 → statement.executeQuery(sql) (SINK - NO SANITIZATION) Sanitization: NONE Validation: NONE Exploitable: YES POC: GET /api/user?userId=1' UNION SELECT password FROM admin_users-- ``` **Taint Analysis Features**: - **Source Identification**: HTTP parameters, file reads, environment variables, database queries - **Sanitization Detection**: Input validation, encoding, parameterized queries, allowlist filtering - **Sink Detection**: SQL execution, command execution, file operations, template rendering, JNDI lookup - **Context-Aware Analysis**: Different rules for different contexts (SQL, OS command, XSS, etc.) ```python # Example: Multi-Stage Taint Flow [TAINT] Complex Flow: REQUEST → SESSION → DATABASE → TEMPLATE Stage 1: User input stored in session UserController.java:67 → session.setAttribute("theme", themeParam) Stage 2: Session value retrieved in different request ThemeController.java:34 → String theme = session.getAttribute("theme") Stage 3: Theme value used in database query ThemeService.java:89 → "SELECT * FROM themes WHERE name='" + theme + "'" Stage 4: Query result rendered in template theme.html:12 → <div th:text="${themeName}"></div> (XSS via SQLi) Attack Chain: Stored XSS via SQL Injection Exploitable: YES ``` ### Phase 4: Validation & Attack Chain Construction (15%) **Objective**: Validate vulnerabilities and construct multi-stage attack chains. ```python # Example: Vulnerability Validation [VALIDATION] SQL Injection in UserService.getUserById() Test 1: Syntax Error Injection Input: userId=1' Expected: SQL syntax error Result: ✓ "You have an error in your SQL syntax" Test 2: Boolean-based Blind SQLi Input: userId=1 AND 1=1 Response Time: 0.123s Input: userId=1 AND 1=2 Response Time: 0.125s Result: ✓ Different responses confirm vulnerability Test 3: Union-based SQLi Input: userId=1 UNION SELECT 1,2,3,4,5-- Result: ✓ Column count: 5 Test 4: Data Extraction Input: userId=1 UNION SELECT null,username,password,null,null FROM admin_users-- Result: ✓ Admin credentials leaked [ATTACK_CHAIN] Privilege Escalation via SQL Injection Step 1: Exploit SQLi to extract admin password hash → /api/user?userId=1 UNION SELECT password FROM admin_users WHERE role='ADMIN'-- Step 2: Crack password hash (MD5 without salt) → hashcat -m 0 -a 0 hash.txt rockyou.txt Step 3: Login as admin → POST /api/login {"username":"admin","password":"cracked_password"} Step 4: Access admin panel → GET /admin/dashboard Impact: Complete system compromise Likelihood: HIGH (weak password hashing + no rate limiting) ``` **Attack Chain Patterns**: ```yaml # Privilege Escalation Chain chain_type: privilege_escalation vulnerabilities: - SQL Injection → Password Hash Extraction - Weak Cryptography → Hash Cracking - Missing Rate Limiting → Brute Force - Insufficient Authorization → Admin Access # Data Exfiltration Chain chain_type: data_exfiltration vulnerabilities: - Path Traversal → Configuration File Read - Hardcoded Credentials → Database Access - Missing Network Segmentation → Internal Network Access - SSRF → Cloud Metadata API Access ``` ### Phase 5: Structured Reporting (5%) **Objective**: Generate comprehensive, actionable security audit report. ```python # Example: Report Generation from scripts.report_generator import ReportGenerator report = ReportGenerator() report.add_vulnerability({ 'id': 'VUL-001', 'title': 'SQL Injection in User Query', 'severity': 'CRITICAL', 'cvss': 9.8, 'dimension': 'D1-Injection', 'location': 'UserService.java:102', 'description': 'String concatenation in SQL query allows SQL injection', 'exploitation': 'Confirmed via manual testing', 'impact': 'Complete database compromise, authentication bypass', 'poc': 'GET /api/user?userId=1\' UNION SELECT password FROM admin_users--', 'remediation': [ 'Use PreparedStatement with parameterized queries', 'Implement input validation with allowlist', 'Apply least privilege principle to database user' ], 'code_vulnerable': ''' String sql = "SELECT * FROM users WHERE id=" + userId; statement.executeQuery(sql); ''', 'code_fixed': ''' String sql = "SELECT * FROM users WHERE id=?"; PreparedStatement stmt = connection.prepareStatement(sql); stmt.setString(1, userId); stmt.executeQuery(); ''' }) report.generate('audit_report.md', format='markdown') ``` ## 10 Security Dimensions ### D1: Injection Vulnerabilities **Coverage**: SQL, Command, LDAP, SSTI, SpEL, JNDI, XSS, XXE ```python # SQL Injection Detection patterns = { 'java': [ r'executeQuery\s*\(\s*[\w\s]+\s*\+', # String concatenation r'createQuery\s*\(\s*".*"\s*\+', # JPA concatenation r'\$\{[\w\.]+\}' # MyBatis unsafe placeholder ], 'python': [ r'execute\s*\(\s*["\'].*%.*["\']', # String formatting r'execute\s*\(\s*f["\'].*\{.*\}', # f-string in SQL r'raw\s*\(\s*["\'].*["\'].*\+' # Django raw query concat ], 'php': [ r'mysql_query\s*\(\s*\$', # mysql_query with variable r'->query\s*\(\s*\$', # PDO query with variable r'DB::select\s*\(\s*["\'].*\.', # Laravel string concat ] } # Command Injection Detection patterns = { 'java': [ r'Runtime\.getRuntime\(\)\.exec\(', r'ProcessBuilder\s*\(\s*.*request', r'new\s+Process\w*\s*\(', ], 'python': [ r'os\.system\s*\(', r'subprocess\.(call|run|Popen)\(', r'eval\s*\(', r'exec\s*\(', ], 'php': [ r'exec\s*\(', r'shell_exec\s*\(', r'system\s*\(', r'passthru\s*\(', r'popen\s*\(', r'proc_open\s*\(', ] } ``` **Example: SSTI Detection (Python)** ```python # Vulnerable Code (Flask) from flask import Flask, request, render_template_string @app.route('/hello') def hello(): name = request.args.get('name', 'Guest') template = '<h1>Hello ' + name + '!</h1>' return render_template_string(template) # SSTI vulnerability # Exploitation POC # GET /hello?name={{config.items()}} # GET /hello?name={{''.__class__.__mro__[1].__subclasses__()}} # Fixed Code from flask import Flask, request, render_template from markupsafe import escape @app.route('/hello') def hello(): name = escape(request.args.get('name', 'Guest')) return render_template('hello.html', name=name) ``` ### D2: Authentication Vulnerabilities **Coverage**: Token management, Session handling, JWT flaws, Filter chain bypass ```java // Vulnerable: Hardcoded Credentials public class DatabaseConfig { private static final String DB_USER = "admin"; private static final String DB_PASS = "P@ssw0rd123"; // CRITICAL public Connection getConnection() { return DriverManager.getConnection( "jdbc:mysql://localhost:3306/db", DB_USER, DB_PASS ); } } // Fixed: Environment Variables public class DatabaseConfig { private final String dbUser = System.getenv("DB_USER"); private final String dbPass = System.getenv("DB_PASSWORD"); public Connection getConnection() { if (dbUser == null || dbPass == null) { throw new IllegalStateException("Database credentials not configured"); } return DriverManager.getConnection(
Auf GitHub ansehen
Diese SKILL.md ist sehr gross, daher zeigt SkillsMP hier nur den ersten Abschnitt. Auf GitHub ansehen