Skip to main content

eastsword-dfyx-code-security-review

Expert-level code security audit skill using deep data flow analysis, taint tracking, and business logic understanding across 9 languages

Datos de origen

Repositorio
reason-machines/security-skills
Última actividad en el origen
8 de junio de 2026 a las 11:18
Idioma detectado de SKILL.md
inglés
Estrellas
12
Forks
1

Opciones de instalación

De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.

Revisa los archivos de origen

Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.

Mostrando SKILL.md

SKILL.md
Instrucciones de origen · Vista previa de solo lectura
name
eastsword-dfyx-code-security-review
description
Expert-level code security audit skill using deep data flow analysis, taint tracking, and business logic understanding across 9 languages
triggers
["audit this code for security vulnerabilities","perform a security code review","find security issues in this project","analyze code for security flaws","run security audit on codebase","check for vulnerabilities in source code","conduct white-box security analysis","review code security with dfyx methodology"]
# EastSword DFYX Code Security Review > Skill by [ara.so](https://ara.so) — Security Skills collection. Expert-level code security audit skill developed by the EastSword (东方隐侠) team. Performs comprehensive white-box static analysis using a five-phase standardized audit protocol with deep data flow analysis, taint tracking, and business logic understanding. ## Overview **dfyx_code_security_review** is a professional code security audit skill designed for AI coding agents. It employs white-box static analysis methodology through a five-phase standardized protocol to systematically discover and validate security vulnerabilities in source code. ### Core Capabilities - **9 Languages**: Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C#, Ruby, Rust - **14 Frameworks**: Spring Boot, Django, Flask, FastAPI, Express, Koa, Gin, Laravel, Rails, ASP.NET Core, Rust Web, NestJS, Fastify, MyBatis - **10 Security Dimensions**: Injection, Authentication, Authorization, Deserialization, File Operations, SSRF, Cryptography, Configuration, Business Logic, Supply Chain - **Triple-Track Audit Model**: Sink-driven + Control-driven + Config-driven - **Five-Phase Protocol**: Reconnaissance → Pattern Matching → Taint Tracking → Validation → Reporting - **Rich Case Library**: Based on real-world WooYun vulnerability cases (2010-2016) ## Installation Clone or copy this skill to your AI client's skills directory: ```bash # For Claude Code git clone https://github.com/EastSword/skill-dfyx_code_security_review.git ~/.claude/skills/eastsword-dfyx-code-security-review # For Cursor git clone https://github.com/EastSword/skill-dfyx_code_security_review.git ~/Library/Application\ Support/Cursor/skills/eastsword-dfyx-code-security-review # Install Python dependencies (optional, for helper scripts) cd ~/.claude/skills/eastsword-dfyx-code-security-review pip install -r requirements.txt ``` ## Five-Phase Audit Protocol ### Phase 1: Reconnaissance & Mapping (10%) **Objective**: Understand architecture and identify attack surface. ```python # Example: Architecture Analysis Output [RECON] Technology Stack: Spring Boot 2.7.3 + MyBatis 3.5.10 + Shiro 1.9.0 [RECON] Attack Surface: - REST API: 47 endpoints (28 authenticated, 19 public) - File Upload: 3 endpoints (/api/upload, /admin/import, /user/avatar) - Template Engine: Thymeleaf (potential SSTI) - Database: MySQL 8.0.30 (84 SQL queries identified) [RECON] Security Controls: - Authentication: Shiro + JWT - Authorization: @RequiresPermissions annotations (coverage: 67%) - Input Validation: @Validated + Hibernate Validator (coverage: 45%) ``` **Key Activities**: - Identify entry points (REST endpoints, file uploads, external integrations) - Map data flows from sources to sinks - Enumerate security controls and their coverage - Build architectural diagram with trust boundaries ### Phase 2: Parallel Pattern Matching (30%) **Objective**: Identify high-risk code patterns across all dimensions. ```python # Example: Pattern Scanner Usage from scripts.pattern_scanner import PatternScanner scanner = PatternScanner(language='java') results = scanner.scan('/path/to/project', dimensions=['D1', 'D2', 'D3', 'D4', 'D5']) # Output Example [PATTERN] SQL Injection Candidates: 12 locations - UserService.java:145 - String concatenation in SQL query - OrderDao.xml:78 - Dynamic SQL with ${} placeholder [PATTERN] Command Injection Candidates: 3 locations - FileProcessor.java:234 - Runtime.exec() with user input [PATTERN] Authentication Bypass Candidates: 5 locations - AdminController.java:89 - Missing @RequiresAuthentication - ReportController.java:156 - Direct database authentication check ``` **Detection Rules**: ```yaml # SQL Injection (Java) - pattern: executeQuery\s*\(\s*[\w\s]+\s*\+ severity: CRITICAL description: String concatenation in SQL query - pattern: \$\{[\w\.]+\} file_types: [.xml] severity: CRITICAL description: MyBatis unsafe placeholder # Command Injection (Python) - pattern: os\.system\(.*input.*\) severity: CRITICAL description: User input in os.system() - pattern: subprocess\.(call|run|Popen)\(.*request\. severity: CRITICAL description: User input in subprocess execution ``` ### Phase 3: Deep Taint Tracking & Validation (40%) **Objective**: Trace data flows from sources to sinks and validate exploitability. ```python # Example: Taint Analysis from scripts.data_flow_analyzer import TaintAnalyzer analyzer = TaintAnalyzer() result = analyzer.trace_flow( source='HttpServletRequest.getParameter("id")', sink='executeQuery(sql)', project_path='/path/to/project' ) # Output Example [TAINT] Flow Found: REQUEST → SQL_QUERY Source: UserController.java:45 → String userId = request.getParameter("userId"); Flow Path: 1. UserController.java:45 → userId (TAINTED) 2. UserController.java:47 → userService.getUserById(userId) (TAINTED) 3. UserService.java:89 → buildQuery(userId) (TAINTED) 4. UserService.java:102 → "SELECT * FROM users WHERE id=" + userId (TAINTED) 5. UserService.java:103 → statement.executeQuery(sql) (SINK - NO SANITIZATION) Sanitization: NONE Validation: NONE Exploitable: YES POC: GET /api/user?userId=1' UNION SELECT password FROM admin_users-- ``` **Taint Analysis Features**: - **Source Identification**: HTTP parameters, file reads, environment variables, database queries - **Sanitization Detection**: Input validation, encoding, parameterized queries, allowlist filtering - **Sink Detection**: SQL execution, command execution, file operations, template rendering, JNDI lookup - **Context-Aware Analysis**: Different rules for different contexts (SQL, OS command, XSS, etc.) ```python # Example: Multi-Stage Taint Flow [TAINT] Complex Flow: REQUEST → SESSION → DATABASE → TEMPLATE Stage 1: User input stored in session UserController.java:67 → session.setAttribute("theme", themeParam) Stage 2: Session value retrieved in different request ThemeController.java:34 → String theme = session.getAttribute("theme") Stage 3: Theme value used in database query ThemeService.java:89 → "SELECT * FROM themes WHERE name='" + theme + "'" Stage 4: Query result rendered in template theme.html:12 → <div th:text="${themeName}"></div> (XSS via SQLi) Attack Chain: Stored XSS via SQL Injection Exploitable: YES ``` ### Phase 4: Validation & Attack Chain Construction (15%) **Objective**: Validate vulnerabilities and construct multi-stage attack chains. ```python # Example: Vulnerability Validation [VALIDATION] SQL Injection in UserService.getUserById() Test 1: Syntax Error Injection Input: userId=1' Expected: SQL syntax error Result: ✓ "You have an error in your SQL syntax" Test 2: Boolean-based Blind SQLi Input: userId=1 AND 1=1 Response Time: 0.123s Input: userId=1 AND 1=2 Response Time: 0.125s Result: ✓ Different responses confirm vulnerability Test 3: Union-based SQLi Input: userId=1 UNION SELECT 1,2,3,4,5-- Result: ✓ Column count: 5 Test 4: Data Extraction Input: userId=1 UNION SELECT null,username,password,null,null FROM admin_users-- Result: ✓ Admin credentials leaked [ATTACK_CHAIN] Privilege Escalation via SQL Injection Step 1: Exploit SQLi to extract admin password hash → /api/user?userId=1 UNION SELECT password FROM admin_users WHERE role='ADMIN'-- Step 2: Crack password hash (MD5 without salt) → hashcat -m 0 -a 0 hash.txt rockyou.txt Step 3: Login as admin → POST /api/login {"username":"admin","password":"cracked_password"} Step 4: Access admin panel → GET /admin/dashboard Impact: Complete system compromise Likelihood: HIGH (weak password hashing + no rate limiting) ``` **Attack Chain Patterns**: ```yaml # Privilege Escalation Chain chain_type: privilege_escalation vulnerabilities: - SQL Injection → Password Hash Extraction - Weak Cryptography → Hash Cracking - Missing Rate Limiting → Brute Force - Insufficient Authorization → Admin Access # Data Exfiltration Chain chain_type: data_exfiltration vulnerabilities: - Path Traversal → Configuration File Read - Hardcoded Credentials → Database Access - Missing Network Segmentation → Internal Network Access - SSRF → Cloud Metadata API Access ``` ### Phase 5: Structured Reporting (5%) **Objective**: Generate comprehensive, actionable security audit report. ```python # Example: Report Generation from scripts.report_generator import ReportGenerator report = ReportGenerator() report.add_vulnerability({ 'id': 'VUL-001', 'title': 'SQL Injection in User Query', 'severity': 'CRITICAL', 'cvss': 9.8, 'dimension': 'D1-Injection', 'location': 'UserService.java:102', 'description': 'String concatenation in SQL query allows SQL injection', 'exploitation': 'Confirmed via manual testing', 'impact': 'Complete database compromise, authentication bypass', 'poc': 'GET /api/user?userId=1\' UNION SELECT password FROM admin_users--', 'remediation': [ 'Use PreparedStatement with parameterized queries', 'Implement input validation with allowlist', 'Apply least privilege principle to database user' ], 'code_vulnerable': ''' String sql = "SELECT * FROM users WHERE id=" + userId; statement.executeQuery(sql); ''', 'code_fixed': ''' String sql = "SELECT * FROM users WHERE id=?"; PreparedStatement stmt = connection.prepareStatement(sql); stmt.setString(1, userId); stmt.executeQuery(); ''' }) report.generate('audit_report.md', format='markdown') ``` ## 10 Security Dimensions ### D1: Injection Vulnerabilities **Coverage**: SQL, Command, LDAP, SSTI, SpEL, JNDI, XSS, XXE ```python # SQL Injection Detection patterns = { 'java': [ r'executeQuery\s*\(\s*[\w\s]+\s*\+', # String concatenation r'createQuery\s*\(\s*".*"\s*\+', # JPA concatenation r'\$\{[\w\.]+\}' # MyBatis unsafe placeholder ], 'python': [ r'execute\s*\(\s*["\'].*%.*["\']', # String formatting r'execute\s*\(\s*f["\'].*\{.*\}', # f-string in SQL r'raw\s*\(\s*["\'].*["\'].*\+' # Django raw query concat ], 'php': [ r'mysql_query\s*\(\s*\$', # mysql_query with variable r'->query\s*\(\s*\$', # PDO query with variable r'DB::select\s*\(\s*["\'].*\.', # Laravel string concat ] } # Command Injection Detection patterns = { 'java': [ r'Runtime\.getRuntime\(\)\.exec\(', r'ProcessBuilder\s*\(\s*.*request', r'new\s+Process\w*\s*\(', ], 'python': [ r'os\.system\s*\(', r'subprocess\.(call|run|Popen)\(', r'eval\s*\(', r'exec\s*\(', ], 'php': [ r'exec\s*\(', r'shell_exec\s*\(', r'system\s*\(', r'passthru\s*\(', r'popen\s*\(', r'proc_open\s*\(', ] } ``` **Example: SSTI Detection (Python)** ```python # Vulnerable Code (Flask) from flask import Flask, request, render_template_string @app.route('/hello') def hello(): name = request.args.get('name', 'Guest') template = '<h1>Hello ' + name + '!</h1>' return render_template_string(template) # SSTI vulnerability # Exploitation POC # GET /hello?name={{config.items()}} # GET /hello?name={{''.__class__.__mro__[1].__subclasses__()}} # Fixed Code from flask import Flask, request, render_template from markupsafe import escape @app.route('/hello') def hello(): name = escape(request.args.get('name', 'Guest')) return render_template('hello.html', name=name) ``` ### D2: Authentication Vulnerabilities **Coverage**: Token management, Session handling, JWT flaws, Filter chain bypass ```java // Vulnerable: Hardcoded Credentials public class DatabaseConfig { private static final String DB_USER = "admin"; private static final String DB_PASS = "P@ssw0rd123"; // CRITICAL public Connection getConnection() { return DriverManager.getConnection( "jdbc:mysql://localhost:3306/db", DB_USER, DB_PASS ); } } // Fixed: Environment Variables public class DatabaseConfig { private final String dbUser = System.getenv("DB_USER"); private final String dbPass = System.getenv("DB_PASSWORD"); public Connection getConnection() { if (dbUser == null || dbPass == null) { throw new IllegalStateException("Database credentials not configured"); } return DriverManager.getConnection(
Ver en GitHub
Este SKILL.md es muy grande, por eso SkillsMP muestra aqui solo la primera seccion. Ver en GitHub