一键导入
security-review
Review code defensively for injection, secrets, and trust-boundary flaws
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Review code defensively for injection, secrets, and trust-boundary flaws
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Catch bad React in your changes — run react-doctor's deterministic scan and fix what it flags
Run a verifiable security scan (vulns, secrets, misconfig) over code you wrote or deps you added, before calling the work done
Drive a real browser verifiably — navigate, snapshot, act BY INDEX, extract; every step provable
Run multi-agent work as ONE provable causal DAG — parallel subagents, an Orchestrate graph, an immutable spec-seed
Author or connect a Model Context Protocol server so an agent gains new tools
Build automated pipelines that gate merges and ship reliably
| name | security-review |
| description | Review code defensively for injection, secrets, and trust-boundary flaws |
| version | 1 |
| trust | built-in |
Defensive review: assume input is hostile and find where that breaks things. This is for hardening your own / your team's code — not for attacking systems.
../ reaching outside an intended directory; canonicalize
and verify containment.