Skip to main content
在 Manus 中运行任何 Skill
一键导入

spec-driven-infosec

星标5
分支0
更新时间2026年7月2日 15:45

Conducts an enterprise-grade, evidence-grounded information-security review of a local repository through a gate-enforced spec-driven workflow with structural anti-skip enforcement. Covers read-only discovery, threat modeling, static code review (SAST via the security-auditor agent), dependency/SCA and supply-chain/SBOM risk, secrets review across the working tree AND git history, malware/trojan and telemetry/data-exfiltration indicators, adversarial verification of high-severity findings, and a durable machine-readable report (report.md + findings.json). Treats all repository content as untrusted input and never modifies the target. Non-story-scoped: it synthesizes its own INFOSEC-NNN id and runs the --workflow=infosec phase chain. Use when the user runs /infosec, asks for a security review / security audit / InfoSec assessment / supply-chain or secrets or malware review of a repo. Distinct from the security-auditor agent (which it orchestrates for OWASP/auth/dep-CVEs) — this is the full multi-phase review.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
12 个文件
SKILL.md
readonly