Skip to main content
在 Manus 中运行任何 Skill
一键导入

web-security-baseline

星标6
分支1
更新时间2026年6月8日 19:57

OWASP Top 10 (web, not agentic) baseline review for any web application code change — auth, sessions, headers, CSRF, XSS, SQL injection, CORS, rate limits, secret handling, file upload, SSRF. Use this skill on any PR or diff that touches HTTP handlers, auth flows, session/cookie logic, file uploads, redirect/URL parsing, database queries with user input, or proxying/fetching external URLs. Catches the bug classes that ship to production and become public CVEs. Distinct from the security-auditor agent (which is invoked explicitly); this skill auto-triggers when relevant code is in scope.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly