Skip to main content
Ejecuta cualquier Skill en Manus
con un clic

spec-driven-infosec

Estrellas5
Forks0
Actualizado2 de julio de 2026 a las 15:45

Conducts an enterprise-grade, evidence-grounded information-security review of a local repository through a gate-enforced spec-driven workflow with structural anti-skip enforcement. Covers read-only discovery, threat modeling, static code review (SAST via the security-auditor agent), dependency/SCA and supply-chain/SBOM risk, secrets review across the working tree AND git history, malware/trojan and telemetry/data-exfiltration indicators, adversarial verification of high-severity findings, and a durable machine-readable report (report.md + findings.json). Treats all repository content as untrusted input and never modifies the target. Non-story-scoped: it synthesizes its own INFOSEC-NNN id and runs the --workflow=infosec phase chain. Use when the user runs /infosec, asks for a security review / security audit / InfoSec assessment / supply-chain or secrets or malware review of a repo. Distinct from the security-auditor agent (which it orchestrates for OWASP/auth/dep-CVEs) — this is the full multi-phase review.

Instalación

Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.

Explorador de archivos
12 archivos
SKILL.md
readonly