Skills Plugins MCP Prompt Model 博客 我的中心
Lifestyle & Tools #data #api #database #security

security-audit

Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.

DeepseekModel Curated skill Quality Excellent · 90 v1.0.0

Get

https://deepseekmodel.com/api/download.php?id=ruvnet-ruflo-agents-skills-security-audit-skill-md&format=skill
Download .skill Standard format with system_prompt and model_config, ready for any agent framework
The actual content of the system_prompt field in the .skill file.
name security-audit description Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes. Security Audit Skill Purpose Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. When to Trigger authentication implementation authorization logic payment processing user data handling API endpoint creation file upload handling database queries external API integration When to Skip read-only operations on public data internal development tooling static documentation styling changes Commands Full Security Scan Run comprehensive security analysis on the codebase npx @claude-flow/cli security scan --depth full Example: npx @claude-flow/cli security scan --depth full --output security-report.json Input Validation Check Check for input validation issues npx @claude-flow/cli security scan --check input-validation Example: npx @claude-flow/cli security scan --check input-validation --path ./src/api Path Traversal Check Check for path traversal vulnerabilities npx @claude-flow/cli security scan --check path-traversal SQL Injection Check Check for SQL injection vulnerabilities npx @claude-flow/cli security scan --check sql-injection XSS Check Check for cross-site scripting vulnerabilities npx @claude-flow/cli security scan --check xss CVE Scan Scan dependencies for known CVEs npx @claude-flow/cli security cve --scan Example: npx @claude-flow/cli security cve --scan --severity high Security Audit Report Generate full security audit report npx @claude-flow/cli security audit --report Example: npx @claude-flow/cli security audit --report --format markdown --output SECURITY.md Threat Modeling Run threat modeling analysis npx @claude-flow/cli security threats --analyze Validate Secrets Check for hardcoded secrets npx @claude-flow/cli security validate --check secrets Scripts Script Path Description security-scan .agents/scripts/security-scan.sh Run full security scan pipeline cve-remediate .agents/scripts/cve-remediate.sh Auto-remediate known CVEs References Document Path Description Security Checklist docs/security-checklist.md Security review checklist OWASP Guide docs/owasp-top10.md OWASP Top 10 mitigation guide Best Practices Check memory for existing patterns before starting Use hierarchical topology for coordination Store successful patterns after completion Document any new learnings
Keywords that activate this skill. Click one to copy it.

This skill does not provide trigger words.

The downloaded .skill package contains the following fields.
Field Description
formatFormat tag (skill/v1)
skill_idUnique skill ID
nameSkill name
versionVersion
descriptionDescription
categoryCategories (array)
trigger_wordsTrigger words
tagsTags
sourceSource
source_urlSource URL (this page)
exported_atExported at (set per download)
system_promptSystem prompt body
model_configModel config: provider / model / temperature / max_tokens / top_p
examplesExamples
install_guideImport guide for Coze / Dify / Claude / custom frameworks
The same skill can be exported in different platform formats.
.skill Standard format with system_prompt and model_config, ready for any agent framework Download
.skillpro Enhanced format with scripts, tools, dependencies and hooks Download
.json Plain JSON export with system_prompt and model parameters only Download
Coze Markdown with frontmatter, for Coze platform import Download
Dify Dify DSL, import directly after creating an app Download

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。