Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问clear审计通过

security-testing-patterns安全测试模式

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

2,138

周安装

90

GitHub Stars

15

下载量

749
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:security-testing-patterns(安全测试模式)
来源仓库:https://github.com/nickcrew/claude-ctx-plugin
仓库路径:skills/security-testing-patterns
安装命令:
npx skills add https://github.com/nickcrew/claude-ctx-plugin --skill security-testing-patterns
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/nickcrew/claude-ctx-plugin --skill security-testing-patterns

简介

用于辅助安全审计、权限检查和常见漏洞排查。

  • 适合梳理敏感配置、检查依赖风险或分析鉴权逻辑。
  • 可生成安全复核清单,但不能直接作为最终结论。
  • 涉及密钥或生产系统时需确认最小权限和操作边界。
  • 建议结合人工复核和脱敏处理敏感信息。security-testing-patterns 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Security Testing Patterns

Expert guidance for implementing comprehensive security testing strategies including static analysis, dynamic testing, penetration testing, and vulnerability assessment.

When to Use This Skill

  • Implementing security testing pipelines in CI/CD
  • Conducting security audits and vulnerability assessments
  • Validating application security controls and defenses
  • Performing penetration testing and security reviews
  • Configuring SAST/DAST tools and interpreting results
  • Testing authentication and authorization mechanisms
  • Evaluating API security and compliance with OWASP standards
  • Integrating security scanning into development workflows
  • Responding to security findings and prioritizing remediation
  • Training teams on security testing methodologies

Core Concepts

Security Testing Pyramid (Layered Approach)

  1. Unit Security Tests - Test security functions (encryption, validation)
  2. SAST - Static analysis during development
  3. SCA - Dependency and component vulnerability scanning
  4. DAST - Dynamic testing in running applications
  5. IAST - Interactive analysis combining SAST and DAST
  6. Penetration Testing - Manual security testing by experts
  7. Red Team Exercises - Adversarial simulation testing

Testing Categories

Static Testing (SAST)

  • Analyzes source code without execution
  • Early detection in development lifecycle
  • Complete code coverage
  • High false positive rates

Dynamic Testing (DAST)

  • Tests running applications
  • Detects runtime and configuration issues
  • Language agnostic
  • Requires deployed environment

Composition Analysis (SCA)

  • Scans dependencies for vulnerabilities
  • Tracks license compliance
  • Automated remediation options

Manual Testing

  • Penetration testing
  • Business logic validation
  • Complex attack scenarios

Quick Reference

TaskLoad reference
Static Application Security Testing (SAST)skills/security-testing-patterns/references/sast.md
Dynamic Application Security Testing (DAST)skills/security-testing-patterns/references/dast.md
Software Composition Analysis (SCA)skills/security-testing-patterns/references/sca.md
Penetration Testing Techniquesskills/security-testing-patterns/references/penetration-testing.md
API Security Testing (OWASP Top 10)skills/security-testing-patterns/references/api-security.md
Fuzzing and Property-Based Testingskills/security-testing-patterns/references/fuzzing.md
Security Automation Pipelineskills/security-testing-patterns/references/automation-pipeline.md

Security Testing Workflow

Phase 1: Planning

  1. Define security requirements and threat model
  2. Select appropriate testing tools and techniques
  3. Establish baseline security posture
  4. Set severity thresholds and acceptance criteria

Phase 2: Automated Testing

  1. SAST - Integrate into IDE and CI/CD pipeline
  2. SCA - Configure dependency scanning (npm audit, Snyk, Dependabot)
  3. DAST - Schedule scans against deployed environments
  4. Container Scanning - Scan Docker images (Trivy, Aqua)

Phase 3: Manual Testing

  1. Authentication and authorization testing
  2. Business logic vulnerability assessment
  3. API security testing (OWASP API Top 10)
  4. Penetration testing and exploitation

Phase 4: Analysis and Remediation

  1. Triage findings by severity and exploitability
  2. Eliminate false positives
  3. Prioritize remediation based on risk
  4. Track vulnerabilities to resolution
  5. Verify fixes with regression testing

Phase 5: Continuous Monitoring

  1. Monitor for new vulnerabilities in dependencies
  2. Re-scan after code changes
  3. Conduct periodic penetration tests
  4. Update security baselines and policies

Common Mistakes

Tool Selection

  • Wrong: Using only SAST or only DAST
  • Right: Layered approach combining multiple testing types

False Positive Management

  • Wrong: Ignoring or suppressing findings without review
  • Right: Systematic triage process with security team validation

Integration Timing

  • Wrong: Security testing only before release
  • Right: Continuous security testing throughout development

Scope Definition

  • Wrong: Testing only main application code
  • Right: Include dependencies, APIs, infrastructure, and third-party integrations

Remediation Priority

  • Wrong: Fixing all findings equally
  • Right: Risk-based prioritization (severity × exploitability × business impact)

Authentication in Testing

  • Wrong: DAST scans without authentication
  • Right: Configure authenticated scanning to test protected features

Best Practices

  1. Shift Left: Integrate security testing early in development
  2. Continuous Testing: Automate security scans in CI/CD pipelines
  3. Layered Approach: Combine SAST, DAST, SCA, and manual testing
  4. Risk-Based Testing: Prioritize testing based on threat model
  5. False Positive Management: Establish process for triaging findings
  6. Remediation Tracking: Use SIEM/SOAR for vulnerability management
  7. Regular Updates: Keep security tools and signatures current
  8. Security Champions: Train developers in security testing
  9. Metrics and KPIs: Track security posture over time
  10. Compliance Validation: Map tests to regulatory requirements

Resources

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Gemini CLI

30.93%
按下载量换算232

Antigravity

25.77%
按下载量换算193

Claude Code

16.54%
按下载量换算124

OpenCode

11.38%
按下载量换算85

Codex

7.54%
按下载量换算56

windsurf

3.48%
按下载量换算26

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills