Token导航 LogoToken导航TokenDH.com
研究检索external-servicegithub未标认证来源可访问clear审计提醒

ln-620-codebase-auditorln 620 代码库审核员

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

7,836

周安装

317

GitHub Stars

437

下载量

2,460
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:ln-620-codebase-auditor(ln 620 代码库审核员)
来源仓库:https://github.com/levnikolaevich/claude-code-skills
仓库路径:skills/ln-620-codebase-auditor
安装命令:
npx skills add https://github.com/levnikolaevich/claude-code-skills --skill ln-620-codebase-auditor
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/levnikolaevich/claude-code-skills --skill ln-620-codebase-auditor

简介

用于安全审计、权限检查和常见漏洞排查,适合梳理敏感配置和鉴权逻辑。

  • 适用于需要分析凭据风险或生成安全复核清单的场景。
  • 使用时不能把工具输出直接当最终结论,需先确认最小权限和操作边界。
  • 涉及密钥、令牌或用户数据时应脱敏处理,避免影响生产系统。
  • 安装前建议确认权限范围和维护状态,确保不会触发不必要的网络或文件操作。

SKILL.md

Paths: File paths (shared/, references/, ../ln-*) are relative to skills repo root.

Type: L2 Coordinator Category: 6XX Audit

Codebase Auditor

Mandatory Read

MANDATORY READ: Load shared/references/evaluation_coordinator_runtime_contract.md, shared/references/evaluation_summary_contract.md, shared/references/evaluation_research_contract.md MANDATORY READ: Load shared/references/research_tool_fallback.md

Purpose

  • audit security, build health, code quality, dependencies, observability, concurrency, lifecycle, and structure
  • coordinate ln-621 through ln-629
  • require stack-aware research before scoring

Runtime Contract

Runtime family:

  • evaluation-runtime

Identifier:

  • codebase-audit

Phase order:

  1. PHASE_0_CONFIG
  2. PHASE_1_DISCOVERY
  3. PHASE_2_RESEARCH
  4. PHASE_3_DELEGATE
  5. PHASE_4_AGGREGATE
  6. PHASE_5_REPORT
  7. PHASE_6_SELF_CHECK

Worker Set

  • ln-621-security-auditor
  • ln-622-build-auditor
  • ln-623-code-principles-auditor
  • ln-624-code-quality-auditor
  • ln-625-dependencies-auditor
  • ln-626-dead-code-auditor
  • ln-627-observability-auditor
  • ln-628-concurrency-auditor
  • ln-629-lifecycle-auditor

Worker Invocation (MANDATORY)

Use the Skill tool for delegated workers. Do not inline worker logic inside the coordinator.

TodoWrite format (mandatory):

  • Resolve audit scope and build manifest
  • Load codebase structure and stack
  • Run best-practice research
  • Delegate to domain audit workers
  • Aggregate worker findings
  • Generate audit report
  • Verify cleanup and self-check

Representative invocations:

Skill(skill: "ln-621-security-auditor", args: "{scope}")
Skill(skill: "ln-622-build-auditor", args: "{scope}")
Skill(skill: "ln-623-code-principles-auditor", args: "{scope}")
Skill(skill: "ln-624-code-quality-auditor", args: "{scope}")
Skill(skill: "ln-625-dependencies-auditor", args: "{scope}")
Skill(skill: "ln-626-dead-code-auditor", args: "{scope}")
Skill(skill: "ln-627-observability-auditor", args: "{scope}")
Skill(skill: "ln-628-concurrency-auditor", args: "{scope}")
Skill(skill: "ln-629-lifecycle-auditor", args: "{scope}")

Workflow

Phase 0: Config

Start evaluation-runtime with required_research=true.

Phase 1: Discovery

Detect project type, stack, and applicability of audit workers.

Phase 2: Research

Mandatory research sources:

  1. official docs or standards
  2. MCP Ref
  3. Context7 when framework docs matter
  4. current web best-practice research

Phase 3: Delegate

Delegate applicable audit workers. Child workers must use evaluation-worker-runtime and emit evaluation-compatible summaries.

Phase 4: Aggregate

Merge security, correctness, architecture, and maintainability findings.

Phase 5: Report

Write final codebase audit output and coordinator summary.

Phase 6: Self-Check

Required checks:

  • research completed
  • all applicable worker summaries recorded
  • aggregation completed
  • cleanup verified
  • coordinator summary recorded

Summary Contract

Write summary_kind=evaluation-coordinator.

Definition of Done

  • Evaluation runtime started
  • Applicable workers selected
  • Research completed
  • All applicable worker summaries recorded
  • Final report written
  • evaluation-coordinator summary written
  • Runtime completed

Meta-Analysis

MANDATORY READ: Load shared/references/meta_analysis_protocol.md

After the coordinator run, analyze the session per protocol section 7 and include the protocol-formatted output with the final codebase audit result.

References

  • Workers: ../ln-621-security-auditor/SKILL.md, ../ln-622-build-auditor/SKILL.md, ../ln-623-code-principles-auditor/SKILL.md, ../ln-624-code-quality-auditor/SKILL.md, ../ln-625-dependencies-auditor/SKILL.md, ../ln-626-dead-code-auditor/SKILL.md, ../ln-627-observability-auditor/SKILL.md, ../ln-628-concurrency-auditor/SKILL.md, ../ln-629-lifecycle-auditor/SKILL.md

Version: 5.0.0 Last Updated: 2025-12-23

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

29.62%
按下载量换算729

Gemini CLI

23.98%
按下载量换算590

Codex

17.55%
按下载量换算432

OpenCode

13.15%
按下载量换算323

Antigravity

7.11%
按下载量换算175

windsurf

3.28%
按下载量换算81

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。

来源信息

继续浏览同类 Skills