Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计异常

security-review安全审查

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

1,067

周安装

44

GitHub Stars

642

下载量

348
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:security-review(安全审查)
来源仓库:https://github.com/getsentry/sentry-skills
仓库路径:skills/security-review
安装命令:
npx skills add https://github.com/getsentry/sentry-skills --skill security-review
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/getsentry/sentry-skills --skill security-review

简介

用于辅助安全审计和权限检查,支持梳理敏感配置和分析鉴权逻辑。

  • 可生成安全复核清单,但不应将工具输出直接当作最终结论。
  • 涉及密钥或令牌时,应先确认最小权限和操作边界。
  • 使用时应脱敏处理用户数据和生产系统信息。
  • security-review 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Security Review Skill

Identify exploitable security vulnerabilities in code. Report only HIGH CONFIDENCE findings—clear vulnerable patterns with attacker-controlled input.

Scope: Research vs. Reporting

CRITICAL DISTINCTION:

  • Report on: Only the specific file, diff, or code provided by the user
  • Research: The ENTIRE codebase to build confidence before reporting

Before flagging any issue, you MUST research the codebase to understand:

  • Where does this input actually come from? (Trace data flow)
  • Is there validation/sanitization elsewhere?
  • How is this configured? (Check settings, config files, middleware)
  • What framework protections exist?

Do NOT report issues based solely on pattern matching. Investigate first, then report only what you're confident is exploitable.

Confidence Levels

LevelCriteriaAction
HIGHVulnerable pattern + attacker-controlled input confirmedReport with severity
MEDIUMVulnerable pattern, input source unclearNote as "Needs verification"
LOWTheoretical, best practice, defense-in-depthDo not report

Do Not Flag

General Rules

  • Test files (unless explicitly reviewing test security)
  • Dead code, commented code, documentation strings
  • Patterns using constants or server-controlled configuration
  • Code paths that require prior authentication to reach (note the auth requirement instead)

Server-Controlled Values (NOT Attacker-Controlled)

These are configured by operators, not controlled by attackers:

SourceExampleWhy It's Safe
Django settingssettings.API_URL, settings.ALLOWED_HOSTSSet via config/env at deployment
Environment variablesos.environ.get('DATABASE_URL')Deployment configuration
Config filesconfig.yaml, app.config['KEY']Server-side files
Framework constantsdjango.conf.settings.*Not user-modifiable
Hardcoded valuesBASE_URL = "https://api.internal"Compile-time constants

SSRF Example - NOT a vulnerability:

# SAFE: URL comes from Django settings (server-controlled)
response = requests.get(f"{settings.SEER_AUTOFIX_URL}{path}")

SSRF Example - IS a vulnerability:

# VULNERABLE: URL comes from request (attacker-controlled)
response = requests.get(request.GET.get('url'))

Framework-Mitigated Patterns

Check language guides before flagging. Common false positives:

PatternWhy It's Usually Safe
Django {{variable}}Auto-escaped by default
React {variable}Auto-escaped by default
Vue {{variable}}Auto-escaped by default
User.objects.filter(id=input)ORM parameterizes queries
cursor.execute("...%s", (input,))Parameterized query
innerHTML = "<b>Loading...</b>"Constant string, no user input

Only flag these when:

  • Django: {{var|safe}}, {% autoescape off %}, mark_safe(user_input)
  • React: dangerouslySetInnerHTML={{__html: userInput}}
  • Vue: v-html="userInput"
  • ORM: .raw(), .extra(), RawSQL() with string interpolation

Review Process

1. Detect Context

What type of code am I reviewing?

Code TypeLoad These References
API endpoints, routesauthorization.md, authentication.md, injection.md
Frontend, templatesxss.md, csrf.md
File handling, uploadsfile-security.md
Crypto, secrets, tokenscryptography.md, data-protection.md
Data serializationdeserialization.md
External requestsssrf.md
Business workflowsbusiness-logic.md
GraphQL, REST designapi-security.md
Config, headers, CORSmisconfiguration.md
CI/CD, dependenciessupply-chain.md
Error handlingerror-handling.md
Audit, logginglogging.md

2. Load Language Guide

Based on file extension or imports:

IndicatorsGuide
.py, django, flask, fastapilanguages/python.md
.js, .ts, express, react, vue, nextlanguages/javascript.md
.go, go.modlanguages/go.md
.rs, Cargo.tomllanguages/rust.md
.java, spring, @Controllerlanguages/java.md

3. Load Infrastructure Guide (if applicable)

File TypeGuide
Dockerfile, .dockerignoreinfrastructure/docker.md
K8s manifests, Helm chartsinfrastructure/kubernetes.md
.tf, Terraforminfrastructure/terraform.md
GitHub Actions, .gitlab-ci.ymlinfrastructure/ci-cd.md
AWS/GCP/Azure configs, IAMinfrastructure/cloud.md

4. Research Before Flagging

For each potential issue, research the codebase to build confidence:

  • Where does this value actually come from? Trace the data flow.
  • Is it configured at deployment (settings, env vars) or from user input?
  • Is there validation, sanitization, or allowlisting elsewhere?
  • What framework protections apply?

Only report issues where you have HIGH confidence after understanding the broader context.

5. Verify Exploitability

For each potential finding, confirm:

Is the input attacker-controlled?

Attacker-Controlled (Investigate)Server-Controlled (Usually Safe)
request.GET, request.POST, request.argssettings.X, app.config['X']
request.json, request.data, request.bodyos.environ.get('X')
request.headers (most headers)Hardcoded constants
request.cookies (unsigned)Internal service URLs from config
URL path segments: /users/<id>/Database content from admin/system
File uploads (content and names)Signed session data
Database content from other usersFramework settings
WebSocket messages

Does the framework mitigate this?

  • Check language guide for auto-escaping, parameterization
  • Check for middleware/decorators that sanitize

Is there validation upstream?

  • Input validation before this code
  • Sanitization libraries (DOMPurify, bleach, etc.)

6. Report HIGH Confidence Only

Skip theoretical issues. Report only what you've confirmed is exploitable after research.


Severity Classification

SeverityImpactExamples
CriticalDirect exploit, severe impact, no auth requiredRCE, SQL injection to data, auth bypass, hardcoded secrets
HighExploitable with conditions, significant impactStored XSS, SSRF to metadata, IDOR to sensitive data
MediumSpecific conditions required, moderate impactReflected XSS, CSRF on state-changing actions, path traversal
LowDefense-in-depth, minimal direct impactMissing headers, verbose errors, weak algorithms in non-critical context

Quick Patterns Reference

Always Flag (Critical)

eval(user_input)           # Any language
exec(user_input)           # Any language
pickle.loads(user_data)    # Python
yaml.load(user_data)       # Python (not safe_load)
unserialize($user_data)    # PHP
deserialize(user_data)     # Java ObjectInputStream
shell=True + user_input    # Python subprocess
child_process.exec(user)   # Node.js

Always Flag (High)

innerHTML = userInput              # DOM XSS
dangerouslySetInnerHTML={user}     # React XSS
v-html="userInput"                 # Vue XSS
f"SELECT * FROM x WHERE {user}"    # SQL injection
`SELECT * FROM x WHERE ${user}`    # SQL injection
os.system(f"cmd {user_input}")     # Command injection

Always Flag (Secrets)

password = "hardcoded"
api_key = "sk-..."
AWS_SECRET_ACCESS_KEY = "..."
private_key = "-----BEGIN"

Check Context First (MUST Investigate Before Flagging)

# SSRF - ONLY if URL is from user input, NOT from settings/config
requests.get(request.GET['url'])     # FLAG: User-controlled URL
requests.get(settings.API_URL)       # SAFE: Server-controlled config
requests.get(f"{settings.BASE}/{x}") # CHECK: Is 'x' user input?

# Path traversal - ONLY if path is from user input
open(request.GET['file'])            # FLAG: User-controlled path
open(settings.LOG_PATH)              # SAFE: Server-controlled config
open(f"{BASE_DIR}/{filename}")       # CHECK: Is 'filename' user input?

# Open redirect - ONLY if URL is from user input
redirect(request.GET['next'])        # FLAG: User-controlled redirect
redirect(settings.LOGIN_URL)         # SAFE: Server-controlled config

# Weak crypto - ONLY if used for security purposes
hashlib.md5(file_content)            # SAFE: File checksums, caching
hashlib.md5(password)                # FLAG: Password hashing
random.random()                      # SAFE: Non-security uses (UI, sampling)
random.random() for token            # FLAG: Security tokens need secrets module

Output Format

## Security Review: [File/Component Name]

### Summary
- **Findings**: X (Y Critical, Z High, ...)
- **Risk Level**: Critical/High/Medium/Low
- **Confidence**: High/Mixed

### Findings

#### [VULN-001] [Vulnerability Type] (Severity)
- **Location**: `file.py:123`
- **Confidence**: High
- **Issue**: [What the vulnerability is]
- **Impact**: [What an attacker could do]
- **Evidence**:

[Vulnerable code snippet]


- **Fix**: [How to remediate]

### Needs Verification

#### [VERIFY-001] [Potential Issue]

- **Location**: `file.py:456`
- **Question**: [What needs to be verified]

If no vulnerabilities found, state: "No high-confidence vulnerabilities identified."


Reference Files

Core Vulnerabilities (references/)

FileCovers
injection.mdSQL, NoSQL, OS command, LDAP, template injection
xss.mdReflected, stored, DOM-based XSS
authorization.mdAuthorization, IDOR, privilege escalation
authentication.mdSessions, credentials, password storage
cryptography.mdAlgorithms, key management, randomness
deserialization.mdPickle, YAML, Java, PHP deserialization
file-security.mdPath traversal, uploads, XXE
ssrf.mdServer-side request forgery
csrf.mdCross-site request forgery
data-protection.mdSecrets exposure, PII, logging
api-security.mdREST, GraphQL, mass assignment
business-logic.mdRace conditions, workflow bypass
modern-threats.mdPrototype pollution, LLM injection, WebSocket
misconfiguration.mdHeaders, CORS, debug mode, defaults
error-handling.mdFail-open, information disclosure
supply-chain.mdDependencies, build security
logging.mdAudit failures, log injection

Language Guides (languages/)

  • python.md - Django, Flask, FastAPI patterns
  • javascript.md - Node, Express, React, Vue, Next.js
  • go.md - Go-specific security patterns
  • rust.md - Rust unsafe blocks, FFI security
  • java.md - Spring, Java EE patterns

Infrastructure (infrastructure/)

  • docker.md - Container security
  • kubernetes.md - K8s RBAC, secrets, policies
  • terraform.md - IaC security
  • ci-cd.md - Pipeline security
  • cloud.md - AWS/GCP/Azure security

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.89%
按下载量换算118

Claude

30.69%
按下载量换算107

Cursor

18.15%
按下载量换算63

Gemini CLI

8.27%
按下载量换算29

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

未通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills