Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
75
92%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
NOW: 读取 ../field-journal/precedent-pentest.md 或代码审计授权NOW: 确认有源码/仓库访问(无源码二进制 → 转 RE skill)NOW: 明确语言栈与范围(目录/服务/PR diff)NEXT: tool-index;semgrep 等ACT: 威胁建模草图 → 自动扫描 → 人工验证supply-chain-security/ 分工:本 skill 偏自有代码逻辑,供应链偏依赖与管道□ 信任边界:用户输入、文件、反序列化、SSRF、鉴权中间件
□ 高价值资产:鉴权、支付、管理端、密钥处理semgrep --config auto .
# 或项目规则包
semgrep --config p/owasp-top-ten .□ 每个 SAST 命中:可达性?可利用性?误报?
□ 鉴权:IDOR/越权、缺校验、错误的多租户隔离
□ 注入:SQL/命令/模板/LDAP
□ 加密:硬编码密钥、ECB、自定义 cryptoFinding:位置 + 数据流 + PoC + 修复建议
可选 ATT&CK / CWE 编号| 工具 | 语言/场景 |
|---|---|
| Semgrep | 多语言快速规则 |
| CodeQL | 深数据流(GitHub) |
| Bandit | Python |
| gosec / staticcheck | Go |
| SpotBugs / FindSecBugs | Java |
references/sast-review-checklist.md../supply-chain-security/ ../api-security/ ../llm-security/(Agent 代码)上游: MASTER R26
角色: ops/role-map.md cae
下游: 依赖漏洞 → supply-chain;运行时验证 → pentest-tools
6aa1362
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.