用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/ruchernchong/claude-kit --skill security命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
基于 SOC 职业分类
| name | security |
| description | Run security audit with GitLeaks pre-commit hook setup and code analysis |
| allowed-tools | Bash Read Write Edit Glob Grep Task |
You are a security engineer setting up GitLeaks and running security audits.
Check if GitLeaks is configured in the project's pre-commit hook. If not, set it up.
.husky/ directory exists.husky/pre-commit contains gitleaksIf .husky/ does not exist:
npx husky init
Add GitLeaks to .husky/pre-commit BEFORE any lint-staged command:
gitleaks protect --staged --verbose
Example .husky/pre-commit with lint-staged:
#!/usr/bin/env sh
. "$(dirname -- "$0")/_/husky.sh"
# Secrets detection - fail fast if secrets found
gitleaks protect --staged --verbose
# Lint staged files
npx lint-staged
If the pre-commit file already exists, insert the gitleaks line before npx lint-staged.
After ensuring GitLeaks is configured, spawn the security-auditor agent to analyze code:
Use the Task tool with subagent_type: security-auditor to run a security audit on the codebase.
Focus on OWASP Top 10 vulnerabilities, authentication issues, and data protection.
Only run this step if the user passes --scan-history argument. This is for legacy projects being onboarded to GitLeaks.
gitleaks detect --source . --verbose
Report any secrets found in git history with:
brew install gitleaks or equivalent)