一键导入
security
Security review for BoxLang and web applications. Load this skill when asked to review code for vulnerabilities, injection risks, or insecure patterns.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Security review for BoxLang and web applications. Load this skill when asked to review code for vulnerabilities, injection risks, or insecure patterns.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Data science methodology — EDA, feature engineering, model selection, evaluation metrics, and production ML patterns.
Financial analysis expertise — ratio analysis, valuation, risk assessment, budgeting, forecasting, and investment evaluation frameworks.
Deep BoxLang language expertise. Inject this skill whenever the user asks about BoxLang syntax, modules, BIFs, or runtime behaviour.
BoxLang code review guidelines. Load this skill when asked to review, audit, or critique code for correctness, style, or best practices.
| name | security |
| description | Security review for BoxLang and web applications. Load this skill when asked to review code for vulnerabilities, injection risks, or insecure patterns. |
When performing a security review of BoxLang code or application design, check for the following threats:
.env, never hard-coded.logResponseToConsole: false)....Content-Security-Policy headers on any web endpoints.Structure every security review as:
**Risk Level**: Critical / High / Medium / Low / Info
**Findings** (numbered, most critical first):
1. [RISK] Description — Remediation
**Clean Bill of Health** (if no issues found):
No security issues detected.