基于 SOC 职业分类
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/ww-w-ai/marketplace --skill scan-security命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
Plan and execute multi-feature roadmaps as sequential, concurrent, or mixed sprint clusters. Trigger on sprint planning, run sprints, plan then build, /cowork-sprint, or requests to break an initiative into sprints. Do not use for trivial edits, one-shot fixes, or one feature (use pdca-wf).
USE for ANY single-feature build request. Trigger when the user asks to implement, build, add, or rework one feature end-to-end, supplies a feature Plan or Design for execution, explicitly requests PDCA, or asks to verify implementation completeness. Runs the shared Research, Brief, Plan review, Design review, Do, targeted Check/Act, and Report lifecycle. Also runs execution-only when cowork-sprint supplies reviewed planning artifacts. Do not use for multi-feature initiatives (use cowork-sprint), trivial edits under about 30 minutes, or pure research with no build.
Max plan hit the wall? Report your 5h window data — we're mapping the rate limit formula Anthropic won't publish
| name | scan-security |
| description | Detects security vulnerabilities via static pattern matching based on OWASP Top 10 |
| triggers | ["scan security","security scan","check security"] |
| user-invocable | true |
| allowed-tools | ["Read","Write","Glob","Grep","Bash"] |
Corresponding rule: security.md
Detect security vulnerabilities in code via static pattern matching based on OWASP Top 10. Does not auto-fix; reports only suspected items.
Resolve target directories in this order:
**/*.{ts,tsx,js,jsx,py,java,go,rs}) -- use the top-level directory containing matched filesDefault exclusions: node_modules/, .git/, dist/, build/, coverage/
Skill-specific exclusions: *.test.*, *.spec.*, test_*, *_test.* (security test code excluded)
Output the following before proceeding with validation. Do not advance until resolution is complete.
| Step | Result |
|---|---|
| CLAUDE.md check | Found/Not found |
| Resolved directories | {list or "none"} |
| Source file count | {count} |
| Resolution method | CLAUDE.md / Glob fallback / SHALLOW |
Detect passwords, API keys, and tokens embedded directly in code.
Search patterns:
API_KEY\s*=\s*["']password\s*=\s*["']secret\s*=\s*["']token\s*=\s*["']PRIVATE_KEY\s*=\s*["']aws_access_key_id\s*=\s*["']aws_secret_access_key\s*=\s*["']Severity: CRITICAL
Detect patterns that build SQL queries via string interpolation.
Search patterns:
f"SELECTf"INSERTf"UPDATEf"DELETEf"DROP`SELECT.*\$\{` (SQL in template literals)"SELECT.*" \+ (SQL via string concatenation)Severity: CRITICAL
Detect patterns that inject user input into HTML without escaping.
Search patterns:
innerHTML\s*=dangerouslySetInnerHTMLv-html=\{!!.*!!\} (Blade unescaped output)\|safe (Django/Jinja safe filter)Severity: HIGH
Detect patterns that pass external input directly to shell commands.
Search patterns:
os.system(f"subprocess.*shell=Trueexec( (dynamic code execution)eval( (dynamic code execution)child_process.exec(`.* (Node.js)Severity: CRITICAL
Detect patterns that include internal system information in user responses.
Search patterns:
traceback.format_exc() -- near return/responsestr(e) -- included directly in the response objectstack.*trace -- included in the responseexc_info=True -- inside a user-response functionSeverity: MEDIUM
Verify that secret files are included in .gitignore.
Required patterns (must exist in .gitignore):
.env related: .env, .env.*, .env.localcredentials, credentials.**.pem, *.key, *.p12, *.pfxsecrets/, .secrets/Severity: HIGH when missing
Glob to collect target source files (excluding test files)Grep each category's patterns across all source filesRead the .gitignore file and check for required patternsOutput the matrix below before generating the final report. Do not proceed until every category has been scanned.
| Category | Status | Items Checked | Findings | Severity | Evidence |
|---|---|---|---|---|---|
| Hardcoded Secrets | ? | ? | ? | CRITICAL | {tool, files, pattern} |
| SQL Injection | ? | ? | ? | CRITICAL | {tool, files, pattern} |
| XSS | ? | ? | ? | HIGH | {tool, files, pattern} |
| Command Injection | ? | ? | ? | CRITICAL | {tool, files, pattern} |
| Error Information Exposure | ? | ? | ? | MEDIUM | {tool, files, pattern} |
| .gitignore | ? | ? | ? | HIGH | {tool, files, pattern} |
Status values: PASS (verification complete, no issues), NOT_APPLICABLE (no source files), SKIPPED (plugin issue), SHALLOW (target resolution failed)
Check every item before writing the report. If any item is unchecked, go back and complete it.
Before writing to .ww-w-ai/devtools/scan-security/, verify the JSON output:
Generate the scan report in the user's conversation language.
Output detection results as a Markdown table in this format:
===== Security Scan Report =====
| File:Line | Type | Severity | Pattern |
|-----------|------|----------|---------|
| `src/config/db.ts:15` | Hardcoded Secret | CRITICAL | `password = "admin123"` |
| `src/api/users.ts:42` | SQL Injection | CRITICAL | `f"SELECT * FROM users WHERE id = {id}"` |
| `src/components/Post.tsx:18` | XSS | HIGH | `dangerouslySetInnerHTML` |
| `.gitignore` | Unprotected Secret | HIGH | `.env` pattern missing |
| `src/handlers/error.ts:30` | Error Information Exposure | MEDIUM | `str(e)` returned directly |
Total suspected items: {N}
CRITICAL: {C}
HIGH: {H}
MEDIUM: {M}
==============================
When there are no suspected items:
===== Security Scan Report =====
No suspected items.
==============================
After generating the security scan report, save results to .ww-w-ai/devtools/scan-security/:
.ww-w-ai/devtools/scan-security/ if missinglatest.json -- structured result following templates/schema.jsonlatest.md -- human-readable report following templates/report.template.mdhistory/ -- copy latest.json to .ww-w-ai/devtools/scan-security/history/{timestamp}.jsonlatest.md is generated in the user's conversation language. JSON field names stay in English regardless of language.
The JSON output enables machine-parseable history tracking and cross-run comparison.
The history/ directory preserves previous executions for trend analysis.
mkdir -p .ww-w-ai/devtools/scan-security/history). The scan itself is read-only and does not modify project files.os.environ["API_KEY"]) are not hardcoding and are excluded from detection.SECURITY prefix comment) is treated as intentionally vulnerable per security.md exceptions.For detailed validation criteria, evidence tables, and examples:
../../docs/specs/security.md