一键导入
security-auditor
Load when the user asks to audit code or config for security issues, find vulnerabilities, hunt for hardcoded secrets, or do an OWASP review.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Load when the user asks to audit code or config for security issues, find vulnerabilities, hunt for hardcoded secrets, or do an OWASP review.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Load when the user asks to queue, enqueue, or add a coding task to the fleet, dispatch a job to a repo, or ask the fleet worker to fix something. Trigger phrases: "add to fleet", "queue a job for", "send to fleet", "dispatch to".
Load when the user provides stock trading recommendations and wants positions sized and bracket orders placed on the Alpaca paper-trading account.
Load when the user wants to navigate a website, click through a flow, fill a form, extract data from a page, or record an interaction as a reusable playbook.
Load when the user asks to review code, audit a PR, find bugs in code they paste, or assess code quality. Trigger phrases: "review this", "look at my code", "is this right", "what's wrong with X".
Load when the user is responding to a customer inquiry, complaint, or support ticket and needs help drafting a reply with the right tone.
Load when the user wants analysis on a dataset — trends, distributions, summary statistics, or insights from a CSV/JSON/Excel file.
| name | Security Auditor |
| slug | security-auditor |
| description | Load when the user asks to audit code or config for security issues, find vulnerabilities, hunt for hardcoded secrets, or do an OWASP review. |
| icon | ShieldCheck |
| color | #dc2626 |
| version | 1.1.0 |
| category | coding |
| tools | ["read_file","search_files"] |
| config_schema | {"type":"object","properties":{"severity_threshold":{"type":"string","enum":["critical","high","medium","low"],"default":"high"}}} |
Report findings at {severity_threshold} severity and above.
For full OWASP Top 10 coverage and remediation patterns, read references/owasp.md.
Always do a secrets sweep before concluding — search_files for api_key, secret, password, token, bearer, plus common cloud key prefixes (AKIA, ASIA, ghp_, sk-).
For each finding: Severity | file:line | Vulnerability | Evidence | Remediation. The remediation is concrete code, not advice.
Don't pad findings — a clean audit with three real issues beats a wall of "consider", "may want to", "could be".