一键导入
security-check
Quick security checklist for a PR or set of files (secrets, input, logging). Use proactively for security reviews.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Quick security checklist for a PR or set of files (secrets, input, logging). Use proactively for security reviews.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Create blog posts — from a topic (writes content) or with provided content (scaffolding). Use proactively when creating new blog posts or articles.
Pre-publication audit for blog posts — comprehensive final review of SEO, AEO, accessibility, images, content quality, i18n parity, and project conventions before publishing. Use proactively before publishing any blog post.
Pre-publication audit for blog series — validates series definition, post ordering, cross-post consistency, navigation, and runs individual post audits for all posts in the series. Use proactively before publishing any blog series.
Audit the blog tag taxonomy — frequency analysis, orphan detection, hierarchy validation, and proposals for new subtopic tags. Read-only — proposes, never modifies tags or posts. Use proactively before each release cycle or after a content drop of 5+ posts.
Optional DeepWorkPlan addon that connects an AI-first repo to the developer's Dailybot team — installing (with consent) the Dailybot agent skill (DailybotHQ/agent-skill) and/or the Dailybot CLI (DailybotHQ/cli), wiring the plan lifecycle into best-effort agent updates - kickoff when a plan starts, significant task completions, a blocked report when an unattended run halts, and a milestone on plan completion - with payloads derived from the plan's state layer, and optionally committing the Dailybot skill's deterministic hook enforcement (dailybot hook lifecycle hooks, CLI >= 1.12.0) so the agent harness itself reminds agents about unreported work. Opt-in, never required, never blocks the work, reconciles existing setups instead of clobbering them, and defers all auth to the Dailybot skill's own consent flow. Use when the developer or team already uses Dailybot and wants DWP progress visible to humans.
Optional DeepWorkPlan addon that safely upgrades a repo's dependencies — reasoning about the repo's ACTUAL package manager (npm/pnpm/yarn + ncu, pip/poetry/uv, cargo, go mod, bundler, composer, and more) rather than assuming npm — with a batched, validated, revertible workflow that detects the manager and manifests/lockfiles, classifies upgrades (patch/minor/major), upgrades in safe batches, runs the repo's real validation gate after each batch, reverts a failing batch, and summarizes. Opt-in, never required, reconciles with the repo's existing tooling. Use when the developer wants to bring dependencies up to date without breaking the build.
| name | security-check |
| description | Quick security checklist for a PR or set of files (secrets, input, logging). Use proactively for security reviews. |
| disable-model-invocation | false |
| allowed-tools | Read, Glob, Grep, Bash |
| model | haiku |
| tier | 1 |
| intent | review |
Run a quick, checklist-based security pass on changed files or a PR: no hardcoded secrets, proper input handling, no sensitive data in logs, no obvious OWASP issues. Lightweight; for deeper review escalate to security-auditor agent. Follow docs/SECURITY.md.
Tier: 1 - Light/Cheap
Reasoning: Checklist-based; read-only; pattern matching (secrets, sanitization). Escalate to security-auditor when issues found.
$TARGET: PR diff, or list of files to check (e.g., paths or "current PR")$FOCUS: Focus area (default: all) — e.g., "secrets", "input", "logging"Secrets & config:
.env)Input & sanitization:
Logging:
Static site considerations:
Obvious risks:
## ✅ Security Check Complete
### Scope
{Files or PR checked}
### Checklist
- Secrets: ✅
- Input/sanitization: ✅ / ⚠️ / ❌
- Logging: ✅ / ⚠️ / ❌
- Static site risks: ✅
### Findings
**Blocking:** {count} — {brief list}
**Suggestions:** {count} — {brief list}
### Recommendation
{Pass / Request changes / Escalate to security-auditor}
When sensitive data handling is involved and issues found:
## 🔄 Escalate to security-auditor
### Reason
{Why deeper review is needed}
### Findings so far
- {Finding 1}
- {Finding 2}
### Next step
Run security-auditor agent for full review (docs/SECURITY.md).
Escalate to security-auditor if:
For Astro static sites:
docs/ doesn't contain sensitive datasrc/pages/api/ endpoints for data exposurePUBLIC_* vars available on client