一键导入
这个仓库中的 skills
Use when animaOS initiative or feature work involves status, definition, revision, PRD, plan, tickets, claim, assignment, resume, block, completion, next-ticket selection, ticket-ID execution, parent-child reconciliation, or explicitly requested publish, PR, Codex review, or monitor-until-clean; exclude explanation, diagnosis-only, and isolated edits unless publish or review is explicitly requested.
Review code, configs, prompts, and design claims for cryptographic implementation flaws, broken key-management lifecycles, unsafe encryption usage, vault/export integrity gaps, and security guarantees that are claimed but not enforced. Use when the user asks for a crypto audit, key-management review, passphrase/KDF/AEAD review, vault/export/import hardening, secure deletion validation, or thesis/design-to-code guarantee-gap analysis. Do not use for broad AppSec review; use security-auditor for general security audits and security-threat-model for repo-level threat modeling.
Review code, configs, prompts, and runtime flows for exploitable security issues. Use when the user asks for a security audit, vulnerability review, AppSec review, auth/authz review, crypto review, attack-surface analysis, or hardening guidance grounded in implementation. Do not use for general code review or architecture-only threat modeling; use security-threat-model for repo-level threat models.