Skip to main content

security-analysis

Security assessment using STRIDE threat modeling, OWASP Top 10, and CVSS scoring. Use for security reviews, threat modeling, and secure coding guidance.

跳到安装

来源信息

仓库
kimasplund/clawdbot-skills-pack
最近来源活动
2026年1月26日 09:44
检测到的 SKILL.md 语言
英语
星标
0
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
security-analysis
description
Security assessment using STRIDE threat modeling, OWASP Top 10, and CVSS scoring. Use for security reviews, threat modeling, and secure coding guidance.
metadata
{"clawdbot":{"requires":{"env":"[Truncated]"}}}
user-invocable
true
# Security Analysis Comprehensive security assessment framework. ## Frameworks Included ### STRIDE Threat Modeling Categorize threats by type: | Threat | Description | Example | |--------|-------------|---------| | **S**poofing | Impersonating something/someone | Fake login page | | **T**ampering | Modifying data/code | SQL injection | | **R**epudiation | Denying actions | Missing audit logs | | **I**nformation Disclosure | Exposing data | Error message leaks | | **D**enial of Service | Disrupting availability | Resource exhaustion | | **E**levation of Privilege | Gaining unauthorized access | Broken access control | ### OWASP Top 10 (2021) Check for common vulnerabilities: 1. **A01: Broken Access Control** 2. **A02: Cryptographic Failures** 3. **A03: Injection** 4. **A04: Insecure Design** 5. **A05: Security Misconfiguration** 6. **A06: Vulnerable Components** 7. **A07: Auth Failures** 8. **A08: Integrity Failures** 9. **A09: Logging Failures** 10. **A10: SSRF** ### CVSS Scoring Rate vulnerability severity: | Score | Severity | Action | |-------|----------|--------| | 9.0-10.0 | Critical | Fix immediately | | 7.0-8.9 | High | Fix within days | | 4.0-6.9 | Medium | Fix within weeks | | 0.1-3.9 | Low | Fix when convenient | ## Security Review Process ### Phase 1: Attack Surface Mapping Identify all entry points: - API endpoints - User inputs - File uploads - External integrations - Authentication flows ### Phase 2: STRIDE Analysis For each entry point, check all STRIDE categories. ### Phase 3: OWASP Checklist Verify protection against Top 10. ### Phase 4: Risk Scoring Apply CVSS to findings. ### Phase 5: Remediation Plan Prioritize fixes by severity. ## Output Template ```markdown ## Security Analysis: [Component/Feature] ### Attack Surface | Entry Point | Type | Trust Level | |-------------|------|-------------| | [endpoint] | API | Untrusted | | [input] | User | Untrusted | ### STRIDE Assessment #### Spoofing - Risk: [description] - Mitigation: [control] - Status: [Mitigated/Open] #### Tampering ... ### OWASP Top 10 Check | Category | Status | Notes | |----------|--------|-------| | A01 Broken Access Control | ✓/✗ | | | A02 Crypto Failures | ✓/✗ | | | A03 Injection | ✓/✗ | | ... ### Vulnerabilities Found | ID | Description | CVSS | Severity | |----|-------------|------|----------| | V1 | [description] | X.X | High | | V2 | [description] | X.X | Medium | ### Remediation Plan 1. **[V1]**: [fix] - Priority: Immediate 2. **[V2]**: [fix] - Priority: This sprint ### Security Posture **Overall Risk: [Low/Medium/High/Critical]** ``` ## Quick Security Checklist For rapid review: - [ ] Input validation on all user data - [ ] Output encoding to prevent XSS - [ ] Parameterized queries (no SQL concatenation) - [ ] Authentication on sensitive endpoints - [ ] Authorization checks (not just auth) - [ ] HTTPS everywhere - [ ] Secrets not in code - [ ] Error messages don't leak info - [ ] Logging without sensitive data - [ ] Dependencies updated ## Secure Coding Patterns ### Input Validation ```python # Always validate and sanitize def process_input(user_input): if not isinstance(user_input, str): raise ValueError("Invalid input type") if len(user_input) > MAX_LENGTH: raise ValueError("Input too long") sanitized = escape_html(user_input) return sanitized ``` ### SQL Injection Prevention ```python # NEVER concatenate cursor.execute(f"SELECT * FROM users WHERE id = {user_id}") # BAD # ALWAYS parameterize cursor.execute("SELECT * FROM users WHERE id = ?", (user_id,)) # GOOD ```
在 GitHub 查看