Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/AsiaOstrich/universal-dev-standards --skill scan명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
[UDS] 以 Claude 原生 Agent tool 编排多任务执行计划(DAG-based,无外部引擎)。 Use when: executing a plan.json file with parallel/sequential task dependencies. Keywords: orchestrate, plan, execute, DAG, task plan, 编排, 执行计划, 并行.
[UDS] 从 Spec 文档、OpenSpec 变更或自由文本需求生成 plan.json。 Use when: converting specifications into executable task plans for /orchestrate. Keywords: plan, spec, task plan, 计划, 规格, 任务, plan.json, DAG.
[UDS] AI 辅助 git push 安全层:质量门禁 + 协作护栏。 Use when: pushing commits, force pushing, pushing to protected branches, pushing feature branches. Keywords: git push, force push, protected branch, quality gate, push receipt, PR automation, 推送, 保护分支, 质量门禁.
SOC 직업 분류 기준
SKILL.md 표시 중
| source | ../../../../skills/security-scan-assistant/SKILL.md |
| source_version | 1.0.0 |
| translation_version | 1.0.0 |
| last_synced | "2026-03-23T00:00:00.000Z" |
| status | current |
| description | [UDS] 引導自動化安全掃描、相依套件審計和機密偵測 |
| name | scan |
| allowed-tools | Read, Grep, Glob, Bash(npm:audit, npx:*) |
| scope |
| universal |
| argument-hint | [scan type or target | 掃描類型或目標] |
語言: English | 繁體中文
自動化相依套件、機密資訊和授權合規的安全掃描。
| 類型 | 工具範例 | 用途 |
|---|---|---|
| 相依套件審計 | npm audit, pip-audit, Snyk | 檢測已知 CVE |
| 機密偵測 | gitleaks, trufflehog | 偵測洩漏的憑證 |
| 授權合規 | license-checker, SPDX | 驗證開源授權相容性 |
| SAST | Semgrep, CodeQL | 靜態分析程式碼模式 |
| 工具 | 指令 | 範圍 |
|---|---|---|
| npm audit | npm audit --json | Node.js 相依套件 |
| Snyk | npx snyk test | 多語言相依套件 |
| Trivy | trivy fs . | 檔案系統與容器 |
| gitleaks | gitleaks detect | Git 歷史機密 |
| SPDX | npx spdx-tool | 授權 SBOM 產出 |
| 嚴重程度 | SLA | 標準 |
|---|---|---|
| Critical | 24 小時 | 遠端執行、認證繞過、資料外洩 |
| High | 72 小時 | 權限提升、SQL 注入 |
| Medium | 2 週 | XSS、CSRF、資訊洩漏 |
| Low | 下個 Sprint | 缺少 Header、冗長錯誤訊息 |
SCAN ──► TRIAGE ──► PRIORITIZE ──► FIX ──► VERIFY
/scan - 完整掃描(相依套件 + 機密 + 授權)/scan --deps - 僅相依套件審計/scan --secrets - 僅機密偵測/scan --license - 授權合規檢查/scan 完成後,AI 助手應建議:
掃描完成。建議下一步:
- 執行
/security深入安全審查- 執行
/checkin確認修復符合提交規範- 執行
/commit提交安全修復- 更新相依套件 →
npm update或pip install --upgrade