一键导入
security-audit
Security audit: check secrets, XSS, auth, rate limits
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Security audit: check secrets, XSS, auth, rate limits
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | security-audit |
| description | Security audit: check secrets, XSS, auth, rate limits |
rg -i "password|api_key|secret|token|credential" --type py -l
rg "sk-|ghp_|gho_|xoxb-" --type-add 'env:.env*' -l
Verify no secrets in code. Check .gitignore includes .env*.
Search for string concatenation in SQL:
rg "f\".*SELECT|f\".*INSERT|f\".*UPDATE|f\".*DELETE" --type py
All queries should use parameterized (%s) placeholders.
Search for innerHTML with user data:
rg "innerHTML.*\+" web/js/ --type js
User-provided content must go through escapeHtml().
Depends(get_current_user)TEST_MODE guards in dev-only coderg "@limiter.limit" api/routers/ --type py -l
Critical endpoints (login, payment, message send) must be rate-limited.
rg "allow_origins|CORSMiddleware" api_server.py
Production should NOT use * for allowed origins.
pip-audit
pip-audit --desc
rg -i "chmod|777|666" --type py
No overly permissive file operations.
Debug frontend vanilla JS issues - console errors, rendering bugs, SPA navigation, WebSocket
Automates the process of setting up the first admin user or adding new admins via the bootstrap endpoint. Includes a Python script for easy execution.
Push to remote and wait for CI to pass. If CI fails, read logs, fix bugs, and re-push. Repeat until green.
Use when building or debugging LangGraph multi-agent systems - eval-first execution, task decomposition, model routing by complexity, and cost discipline
Use when AI agent modifies API routes or backend logic - catch systematic blind spots where the same model writes and reviews code
Use when making or recording significant architectural decisions - capture context, alternatives, and rationale as structured ADRs