一键导入
security
Review security-sensitive changes and local secret exposure before commit or release.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Review security-sensitive changes and local secret exposure before commit or release.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Guided git commit workflow — review changes, draft message, stage, commit
Manage context pressure during large codebase work without losing critical state.
Create a pull request with structured summary and test plan
Interactive debugging — reproduce, isolate, trace, fix
Explore a codebase or directory to understand its structure and purpose
Implement a requested code change end-to-end with scoped edits and verification.
| name | security |
| description | Review security-sensitive changes and local secret exposure before commit or release. |
| when_to_use | Use when code touches auth, input handling, secrets, network boundaries, data storage, or release packaging. |
| required_tools | ["bash","imports"] |
| tags | ["security","review"] |
| activation | {"input_patterns":["(?i)(security|secret|auth|token|安全|密钥|权限|认证)"]} |
${ARGS}
Identify trust boundaries: user input, filesystem, network, database, provider calls, credentials, and channel delivery.
Run local CLI secret scanning (git grep, grep, or the repository's scanner) and inspect dependency manifests. Treat any hardcoded credential as a release blocker.
Check validation, authorization, error messages, logging, and unsafe shell/process use. Prefer concrete exploit paths over generic warnings.
Report findings by severity, include file locations, and state what was verified.