一键导入
security-audit
Deep security audit for code changes or areas: auth/authz, data exposure, injection, secrets, dependency risk, and OWASP-style issues.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Deep security audit for code changes or areas: auth/authz, data exposure, injection, secrets, dependency risk, and OWASP-style issues.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
| name | security-audit |
| description | Deep security audit for code changes or areas: auth/authz, data exposure, injection, secrets, dependency risk, and OWASP-style issues. |
Review for concrete exploitable or data-exposure risk.
Read ~/.claude/rules/review-finding-format.md, ~/.claude/rules/pr-mode-readonly.md, and ~/.claude/rules/model-escalation.md when available. Use ~/.agents/rules/ under Codex. For full checklist, read references/protocol-index.md.
Findings must include affected asset/data, attacker or misuse path, evidence, impact, and concrete mitigation.
Address pending PR review feedback through verified triage, small fix phases, implementation, validation, and evidence-backed replies. Manual invocation only.
Autonomous iteration loop for a measurable goal: review, ideate, modify, verify, keep or rollback, repeat until interrupted or capped.
Monitor a PR's CircleCI pipeline, diagnose failures, apply scoped fixes, push when requested, and continue until green or blocked.
Stage and commit changes in logical groups using the project's git message style, without mixing unrelated user changes.
Create or update a GitHub PR with concise description, review guidance, triggered specialty reviews, and focus areas.
Build a daily work brief from yesterday/off-hours activity plus today's Linear, Calendar, Gmail, and Notion context; update Notion and produce standup/checklist.