一键导入
fix-security
Fetch GitHub security alerts (Dependabot, code scanning, secret scanning) and fix them. Use when user wants to resolve security issues.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Fetch GitHub security alerts (Dependabot, code scanning, secret scanning) and fix them. Use when user wants to resolve security issues.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Run analyzer + tests sequentially via make check. Full pre-commit validation.
Create a git commit following project conventions. Checks docs. Pre-commit hook handles analyzer + tests. Use when user says "commit" or "commit and push".
Check test coverage via SonarCloud API. Shows overall, new code, and per-file coverage.
Look up a section of docs/ARCHITECTURE.md without reading the whole file. Given a task description OR a § identifier (numeric like "3.6", "§11" or header fragment like "Security", "Tags", "Transfer Queue"), returns the relevant ARCHITECTURE.md section(s) verbatim. Executes Grep + Read itself in a single invocation — does not ask the user to run anything. Trigger phrases: "/doc <anything>", "docs on X", "architecture of X", "find the ARCHITECTURE § about X". Use when you need to consult docs/ARCHITECTURE.md for a specific topic instead of reading the full 3000-line file.
Map the blast radius of changing a Dart file — find importers (call sites) and the paired test file. Use when user says "what uses X", "who imports X", "impact of X", "find callers of X", or invokes /find-impact with a path.
Fetch SonarCloud issues and fix them. Use when user wants to fix code smells, bugs, or vulnerabilities reported by SonarCloud.
| name | fix-security |
| description | Fetch GitHub security alerts (Dependabot, code scanning, secret scanning) and fix them. Use when user wants to resolve security issues. |
Run these in parallel to get the full picture:
Dependabot alerts:
gh api repos/Llloooggg/LetsFLUTssh/dependabot/alerts --jq '.[] | select(.state=="open") | "\(.severity) \(.dependency.package.name) \(.dependency.package.ecosystem) — \(.security_advisory.summary)"'
Code scanning alerts (CodeQL + Semgrep):
gh api repos/Llloooggg/LetsFLUTssh/code-scanning/alerts --jq '.[] | select(.state=="open") | "\(.rule.severity) \(.tool.name) \(.most_recent_instance.location.path):\(.most_recent_instance.location.start_line) — \(.rule.description)"'
Secret scanning alerts:
gh api repos/Llloooggg/LetsFLUTssh/secret-scanning/alerts --jq '.[] | select(.state=="open") | "\(.secret_type) — \(.secret_type_display_name)"' 2>/dev/null || echo "No secret scanning alerts or insufficient permissions"
If $ARGUMENTS contains "dependabot", "codescan", or "secrets" — fetch only that category.
Present a summary table:
| Source | Severity | Issue | Location |
|---|
Prioritize: critical/high first, then medium, then low.
Dependabot (dependency vulnerabilities):
pubspec.yaml to the fixed versionflutter pub get to update pubspec.lockmake check to verify nothing breaksCode scanning (CodeQL/Semgrep):
// ignore: or inline commentsSecret scanning:
.gitignore if it's a filemake check must pass