security-audit
Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.
DeepseekModel
官方收录技能
质量 优秀 · 90
v1.0.0
获取
https://deepseekmodel.com/api/download.php?id=ruvnet-ruflo-agents-skills-security-audit-skill-md&format=skill
下载 .skill
标准格式,含 system_prompt 与 model_config,导入任意 Agent 框架即可使用
.skill 文件中 system_prompt 字段的实际内容。
name security-audit description Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes. Security Audit Skill Purpose Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. When to Trigger authentication implementation authorization logic payment processing user data handling API endpoint creation file upload handling database queries external API integration When to Skip read-only operations on public data internal development tooling static documentation styling changes Commands Full Security Scan Run comprehensive security analysis on the codebase npx @claude-flow/cli security scan --depth full Example: npx @claude-flow/cli security scan --depth full --output security-report.json Input Validation Check Check for input validation issues npx @claude-flow/cli security scan --check input-validation Example: npx @claude-flow/cli security scan --check input-validation --path ./src/api Path Traversal Check Check for path traversal vulnerabilities npx @claude-flow/cli security scan --check path-traversal SQL Injection Check Check for SQL injection vulnerabilities npx @claude-flow/cli security scan --check sql-injection XSS Check Check for cross-site scripting vulnerabilities npx @claude-flow/cli security scan --check xss CVE Scan Scan dependencies for known CVEs npx @claude-flow/cli security cve --scan Example: npx @claude-flow/cli security cve --scan --severity high Security Audit Report Generate full security audit report npx @claude-flow/cli security audit --report Example: npx @claude-flow/cli security audit --report --format markdown --output SECURITY.md Threat Modeling Run threat modeling analysis npx @claude-flow/cli security threats --analyze Validate Secrets Check for hardcoded secrets npx @claude-flow/cli security validate --check secrets Scripts Script Path Description security-scan .agents/scripts/security-scan.sh Run full security scan pipeline cve-remediate .agents/scripts/cve-remediate.sh Auto-remediate known CVEs References Document Path Description Security Checklist docs/security-checklist.md Security review checklist OWASP Guide docs/owasp-top10.md OWASP Top 10 mitigation guide Best Practices Check memory for existing patterns before starting Use hierarchical topology for coordination Store successful patterns after completion Document any new learnings
Agent 识别该技能的关键词,点击任意一个即可复制。
该技能未提供触发词。
下载的 .skill 包内含以下字段。
| 字段 | 说明 |
|---|---|
| format | 格式标识(skill/v1) |
| skill_id | 技能唯一 ID |
| name | 技能名称 |
| version | 版本号 |
| description | 技能描述 |
| category | 所属分类(数组) |
| trigger_words | 触发词列表 |
| tags | 标签列表 |
| source | 来源标识 |
| source_url | 来源链接(本页地址) |
| exported_at | 导出时间(每次下载生成) |
| system_prompt | 系统提示词正文 |
| model_config | 模型参数:provider / model / temperature / max_tokens / top_p |
| examples | 示例 |
| install_guide | 各平台导入说明(Coze / Dify / Claude / 自定义框架) |