Skip to main content
在 Manus 中运行任何 Skill
一键导入

slo-sast

星标5
分支0
更新时间2026年6月21日 22:48

Use this skill to wire threat-model-driven SAST scanning into a target product repo. Reads docs/slo/design/<slug>-threat-model.md for CWE references, picks tuned Semgrep rule packs for the detected stack, emits a safe GitHub Actions workflow plus a baselined config plus an audit-defense manifest, and re-derives the ruleset on threat-model edit. Pure Markdown skill; no Rust binary dependency. Pair with /slo-rulegen for project-specific rules.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
15 个文件
SKILL.md
readonly