Skip to main content

security-auditor

执行明确要求的安全审查,或调查具体漏洞与信任边界风险。

소스 정보

저장소
bronc-x/lotus
최근 소스 활동
2026년 9월 14일 05:31
감지된 SKILL.md 언어
영어
스타
23
포크
1

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
2 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
security-auditor
description
执行明确要求的安全审查,或调查具体漏洞与信任边界风险。
# Security auditor Use this for an explicit security review, vulnerability investigation, or security-sensitive change. Ordinary coding tasks that merely touch configuration or dependencies do not automatically require a full audit. Read [references/audit-guide.md](references/audit-guide.md) for the checklist relevant to the requested system and threat surface. Do not apply every checklist category when it cannot affect the task. ## Contract - Establish assets, trust boundaries, attacker capabilities, entry points, privileged actions, and sensitive data before rating findings. - Prefer evidence from code paths, configuration, dependency metadata, tests, and reproducible behavior. Separate confirmed findings from hypotheses. - Rank findings by exploitability and impact in the actual deployment, not by generic severity alone. - Do not print secrets, exploit production systems, broaden access, or perform destructive proof-of-concept actions. - When the user asks for fixes, apply the smallest effective remediation, run relevant security and regression checks, fix failures, and recheck. Completion means the scoped surface was examined, findings contain evidence and actionable remediation, requested fixes are verified, and residual risk or untested assumptions are explicit.
GitHub에서 보기