Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计通过

security安全

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

588

周安装

25

GitHub Stars

6

下载量

206
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:security(安全)
来源仓库:https://github.com/hyperb1iss/hyperskills
仓库路径:skills/security
安装命令:
npx skills add https://github.com/hyperb1iss/hyperskills --skill security
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/hyperb1iss/hyperskills --skill security

简介

security 用于辅助安全审计、权限检查和常见漏洞排查。

  • 适合梳理敏感配置、检查依赖风险或生成安全复核清单。
  • 通过 npx skills add 命令从 hyperb1iss/hyperskills 仓库安装。
  • 不能将工具输出直接作为最终结论,涉及密钥或生产系统时应确认最小权限。
  • 建议结合原始 README 了解具体检查项和脱敏要求。

SKILL.md

Security Operations

Frameworks and checklists for secure systems. This skill is a triage map: use it to find the right review lens, then pull the authoritative standard for implementation detail.

Zero Trust Principles

NIST SP 800-207 frames Zero Trust as removing implicit trust based on network location, asset ownership, or perimeter membership. Access decisions are resource-centered and continuously evaluated.

TenetReview Question
Resource-centric accessIs the protected thing a specific app, service, or data set?
Per-session authorizationIs access granted for this request/session, not forever?
Continuous evaluationDo identity, device posture, and behavior affect decisions?
Least privilegeAre permissions scoped to the minimum operation needed?
Assume breachCan one compromised account/device move laterally?

Do not equate Zero Trust with micro-segmentation. Segmentation can help, but the security boundary is identity, policy, and resource access.

SLSA 1.2 (Supply Chain)

As of Apr 26, 2026, SLSA 1.2 uses separate tracks. The old single SLSA 1-4 framing is retired; Build L4, hermetic builds, and reproducible builds are future-direction topics, not current requirements.

TrackLevelMeaningPrimary Protection
BuildL0No guaranteesNone
BuildL1Provenance existsMistakes, traceability
BuildL2Signed provenance from hosted platformTampering after build
BuildL3Hardened build platformTampering during build
SourceL1-L3Increasing trust in source revisionsSource integrity controls

For agent work, minimum practical target is Build L2 for releases: hosted CI, signed provenance, and consumer verification. Aim for Build L3 when release artifacts are high-trust dependencies.

Threat Modeling (STRIDE)

ThreatExampleMitigation
SpoofingFake identityStrong auth, MFA
TamperingModified dataIntegrity checks, signing
RepudiationDeny actionsAudit logs, non-repudiation
Information DisclosureData leakEncryption, access control
Denial of ServiceOverloadRate limiting, scaling
Elevation of PrivilegeUnauthorized accessLeast privilege, RBAC

OWASP Top 10:2025 Checklist

As of Apr 26, 2026, OWASP lists the 2025 release as current.

  • A01: Broken Access Control
  • A02: Security Misconfiguration
  • A03: Software Supply Chain Failures
  • A04: Cryptographic Failures
  • A05: Injection
  • A06: Insecure Design
  • A07: Authentication Failures
  • A08: Software or Data Integrity Failures
  • A09: Security Logging and Alerting Failures
  • A10: Mishandling of Exceptional Conditions

Secrets Management

Never commit secrets. Use environment-based injection (External Secrets Operator, Vault, cloud-native secret managers). Scan with gitleaks or trufflehog in CI.

Supply Chain Security

  • Generate SBOMs with Syft: syft packages dir:. -o spdx-json
  • Scan with Grype: grype sbom:sbom.spdx.json --fail-on high
  • Scan container images with Trivy: trivy image <image> --severity HIGH,CRITICAL
  • Use distroless/Chainguard base images

Incident Response

NIST SP 800-61 Rev. 3 maps incident response into the CSF 2.0 lifecycle instead of treating response as a linear cleanup checklist.

FunctionAgent Checklist
GovernOwners, severity policy, legal/comms paths are known
IdentifyAssets, dependencies, data classes, and blast radius
ProtectPreventive controls, backups, secrets rotation path
DetectAlerts, logs, indicators, timelines, correlation
RespondContainment, evidence preservation, eradication
RecoverRestore service, monitor recurrence, capture lessons

Compliance Frameworks

FrameworkFocus
SOC 2 Type IIService organization controls
ISO 27001Information security management
HIPAAProtected health information
GDPREU data protection
PCI DSSPayment card data

Use Vanta or Drata for continuous monitoring and automated evidence collection.

Anti-Patterns

Anti-PatternFix
Treating OWASP Top 10 as a full auditUse it as a baseline; add abuse cases and data-flow review
Claiming "Zero Trust compliant"Name concrete controls and the resource they protect
Calling SBOMs supply-chain securityPair SBOM with provenance, signing, and verification
Doing security review after mergeThreat-model before design freezes; scan continuously
Ignoring recovery pathsTest restore, key rotation, and evidence capture

What This Skill is NOT

  • Not legal or compliance advice.
  • Not a replacement for current OWASP, NIST, SLSA, or framework-specific docs.
  • Not a penetration testing methodology.
  • Not sufficient for regulated environments without organization-specific controls.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

33.54%
按下载量换算69

Claude

32.28%
按下载量换算66

Cursor

17.55%
按下载量换算36

Gemini CLI

8.31%
按下载量换算17

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills