Skip to main content
在 Manus 中运行任何 Skill
一键导入

agent-security-review

星标6
分支2
更新时间2026年6月1日 04:19

Scan AI-agent, LLM, MCP-server, or tool-calling code for security vulnerabilities using the raxIT agent-security-review pack (ast-grep), then triage the findings with a concrete fix for each. Use this whenever the user wants to security-review, audit, harden, or "check before shipping" any agentic code — for example "review my agent for security issues", "is my MCP server safe", "audit my LangChain / OpenAI Agents / CrewAI / LlamaIndex tool code", "scan my agent for prompt injection", or "find vulnerabilities in my tool definitions". It catches hardcoded credentials, prompt-injection sinks, unbounded loops / denial-of-wallet, ungated tool dispatch, MCP tool poisoning and SSRF, memory poisoning and data exfiltration, lethal-trifecta skill permissions, and missing gateway auth. The pack is agent-specific — if the target turns out NOT to be agentic code, this skill says so plainly and scopes out instead of inventing issues. Rules are pulled live from GitHub so the checks stay current. Reach for this even when th

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
46 个文件
SKILL.md
readonly