원클릭으로
security-review
Run a security audit covering OWASP Top 10, deps, secrets, auth
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Run a security audit covering OWASP Top 10, deps, secrets, auth
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Manage the project backlog — add, list, filter, update, prioritize, and suggest work items
Daily session wrapper — start with backlog, work, commit, retro
End-of-session retrospective — summarize work, update backlog statuses, update MEMORY.md
Commit, branch, PR, self-review, fix — then stop for human approval before merge
Pre-flight for parallel work — pick items, check file overlap, set statuses, generate terminal commands
Manage project backlog — add, list, filter, update, prioritize, suggest
| name | security-review |
| description | Run a security audit covering OWASP Top 10, deps, secrets, auth |
| user-invocable | true |
Grep for patterns that should never be in code:
.env files committed to gitnpm audit
Flag: CRITICAL and HIGH severity.
WITH CHECK (not just USING)dangerouslySetInnerHTML without sanitizationeval(), innerHTML, or new Function() with user inputVITE_ prefixed secrets (these are exposed to the client).env.example doesn't contain real values| # | Severity | Category | Finding | File | Recommendation |
|---|---|---|---|---|---|
| 1 | CRITICAL | ... | ... | ... | ... |
Severity: CRITICAL / HIGH / MEDIUM / LOW / INFO