Skip to main content
在 Manus 中运行任何 Skill
一键导入

security-audit

星标12
分支6
更新时间2026年7月9日 13:28

Security audit of a repository, tiered by risk — run before it is made public and periodically afterwards. Use when asked to run a security audit or review, or to complete the mandatory security step of the open-source audit. Builds a threat model, runs SAST / dependency / supply-chain tooling, manually reviews security-sensitive surfaces (deserialization, injection, memory safety / FFI, crypto, ML model loading), and for high-risk repositories adds threat-model-driven adversarial tests and bounded fuzzing. Produces a pass/fail Markdown report with CWE-tagged findings. Reports findings and gates publication; it does not fix code or flip repository visibility itself.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly