一键导入
vet
Use when the user wants a security and trust-boundary review of the current design before implementation or release.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Use when the user wants a security and trust-boundary review of the current design before implementation or release.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | vet |
| description | Use when the user wants a security and trust-boundary review of the current design before implementation or release. |
Use this skill inside Codex to review security posture before the build lane. $vet remains the sole security gate even as Meta-Architect ships deeper native security playbooks.
Produce:
decision, status, evidence, blockers, next_allowed_triggers$vibereferences/security-playbooks.md when you need the native security playbook set for common trust-boundary reviews..agents/skills/security/llm-security/SKILL.md.Write, refine, run, and QA promptfoo evaluation suites for Premortem: promptfooconfig.yaml, providers, vars, tests, assertions, and CI gates. Use for canonical prompt regression in @premortem/evals. Do not use for adversarial redteam plugin setup (see security/llm-security).
Use when the user wants to decide whether implementation is ready, what remains blocked, and what the exact next build step should be.
Use when the user wants the singular Meta-Architect in-session autonomous manager: choose the best next workflow step, manage the fixed gated workflow, and route bounded helper handoffs inside Codex.
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".
Comprehensive Android mobile application penetration testing with rooted-device ADB and Frida-based MCP tooling. Covers OWASP MASTG full methodology: recon, static + dynamic analysis, SSL/root bypass, IPC fuzzing, data exfiltration, crypto audit, and reporting. Triggers on requests to pentest Android apps, analyze APKs, bypass mobile security controls, or run MASVS/MASTG assessments.