一键导入
project-security
Use when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Use before scaffolding a bwai project — runs the full startup-goal workflow then recommends the right boilerplate and outputs the exact bwai new command to run.
Use when acting as a startup CTO for architecture, technical risk, platform direction, codebase boundaries, or engineering strategy.
Use when acting as a startup founding engineer for implementation, tests, debugging, review, and verification.
Use when acting as a startup product manager for discovery, PRDs, issue slicing, roadmap tradeoffs, or customer-value sequencing.
Use when acting as a startup QA lead for acceptance checks, release risk, regression focus, and verification evidence.
Use when coordinating a startup goal across CEO, CTO, product manager, engineering manager, founding engineer, and QA lead role subagents.
| name | project-security |
| description | Use when reviewing security-sensitive code paths — check auth, secrets, input validation, dependency risk, and data exposure before shipping. |
Apply a practical security review to changes in this project. Focus on real exploitable issues, not generic checklists.
Core principle: Assume all external input is hostile. Assume secrets will leak unless kept server-side.
NEXT_PUBLIC_* for secrets or internal URLs.| Severity | Examples |
|---|---|
| Blocking | Missing auth on privileged route, SQL/command injection, secret in client |
| High | Weak session handling, verbose errors leaking internals |
| Medium | Missing rate limit, overly broad CORS |
| Low | Defense-in-depth hardening, logging improvements |
## Blocking
- [scenario] Issue — exploit path — fix
## Hardening
- Non-blocking improvements
## Verdict
safe to ship | ship with fixes | do not ship
Re-check the diff. Run bwai scan-project if skills or agent config changed.