원클릭으로
redteam-source-audit
Focused source-code security review workflow for web applications, CMS extensions, APIs, and supporting services.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Focused source-code security review workflow for web applications, CMS extensions, APIs, and supporting services.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
| name | redteam-source-audit |
| description | Focused source-code security review workflow for web applications, CMS extensions, APIs, and supporting services. |
Focused source-code security review workflow for web applications, CMS extensions, APIs, and supporting services.
Activate when the user asks to:
SC-001, SC-002, etc.Return Markdown with:
Scope interpretedSource mapRisk-ranked review targetsCandidate findings
IDClaimEvidenceSource → sink tracePreconditionsImpactVerification stepsNegative controlConfidenceWhat could falsify thisNon-findings / dead endsCommands and files reviewedVerifier handoffReport notesA candidate must cite observable repository evidence: file path, symbol, route, config, package metadata, or command result. If the evidence is incomplete, label it as a hypothesis and state the missing proof.
.github/workflows/), GitLab CI, and Jenkinsfiles for script injection, vulnerable runners, or token exposure (e.g., pull_request_target).unserialize() (PHP), pickle.loads() (Python), or ObjectInputStream (Java). Identify gadget chains using ysoserial or phpggc.Focused methodology for authorized CMS fingerprinting, component inventory, misconfiguration review, and vulnerability validation.
Focused workflow for validating exploitability safely and turning candidate issues into reproducible, bounded proof.
Focused reconnaissance workflow for authorized security assessments, bug bounty triage, lab targets, and CTF infrastructure.
Focused reporting workflow for converting verified red-team work into clear, reproducible assessment artifacts.
Expertise in offensive security research, vulnerability analysis, CMS-focused application testing, and red team operations.