用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/Hbin77/codex-kit --skill security-review命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
基于 SOC 职业分类
| name | security-review |
| description | Security audit of the project or specified scope |
Run a security audit on the current project or specified scope: the task/scope the user described when invoking this skill (if none given, ask or infer from context)
Identify vulnerabilities yourself using the process below. Be evidence-based — cite file:line for every finding.
grep -rniE "password|secret|api_key|apikey|token|private_key" \
--include="*.js" --include="*.ts" --include="*.jsx" --include="*.tsx" \
--include="*.py" --include="*.go" --include="*.rb" --include="*.env" .
(or rg -ni "password|secret|api_key|apikey|token|private_key" -g '*.{js,ts,jsx,tsx,py,go,rb,env}').env files are gitignored; look for committed credentials.npm audit / pip-audit / govulncheck or equivalent.Severity scale (canonical): CRITICAL / WARNING / INFO.
## Security Audit Report
### CRITICAL
[Immediate action required — blocks deployment]
### WARNING
[Should be fixed soon]
### INFO
[Advisory / good to fix when convenient]
### Secure Patterns Found
[Positive findings — things done well]
Include remediation steps for each finding.