Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/Hbin77/codex-kit --skill security-review명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | security-review |
| description | Security audit of the project or specified scope |
Run a security audit on the current project or specified scope: the task/scope the user described when invoking this skill (if none given, ask or infer from context)
Identify vulnerabilities yourself using the process below. Be evidence-based — cite file:line for every finding.
grep -rniE "password|secret|api_key|apikey|token|private_key" \
--include="*.js" --include="*.ts" --include="*.jsx" --include="*.tsx" \
--include="*.py" --include="*.go" --include="*.rb" --include="*.env" .
(or rg -ni "password|secret|api_key|apikey|token|private_key" -g '*.{js,ts,jsx,tsx,py,go,rb,env}').env files are gitignored; look for committed credentials.npm audit / pip-audit / govulncheck or equivalent.Severity scale (canonical): CRITICAL / WARNING / INFO.
## Security Audit Report
### CRITICAL
[Immediate action required — blocks deployment]
### WARNING
[Should be fixed soon]
### INFO
[Advisory / good to fix when convenient]
### Secure Patterns Found
[Positive findings — things done well]
Include remediation steps for each finding.