Token导航 LogoToken导航TokenDH.com
研究检索需要联网github未标认证来源可访问许可证需确认审计通过

audit-context-building审计环境构建

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

1,297

周安装

53

GitHub Stars

131

下载量

416
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:audit-context-building(审计环境构建)
来源仓库:https://github.com/workersio/spec
仓库路径:skills/audit-context-building
安装命令:
npx skills add https://github.com/workersio/spec --skill audit-context-building
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/workersio/spec --skill audit-context-building

简介

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。

  • 适合梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。
  • 使用时不能把工具输出直接当最终结论,需先确认最小权限、脱敏方式和操作边界。
  • 涉及密钥、令牌、用户数据或生产系统时,应格外谨慎并遵循安全规范。
  • audit-context-building 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Deep Context Builder Skill

1. Purpose

This skill governs how Claude thinks during the context-building phase of an audit.

When active, Claude will:

  • Perform line-by-line / block-by-block code analysis by default.
  • Apply First Principles, 5 Whys, and 5 Hows at micro scale.
  • Continuously link insights -> functions -> modules -> entire system.
  • Maintain a stable, explicit mental model that evolves with new evidence.
  • Identify invariants, assumptions, flows, and reasoning hazards.

This skill defines a structured analysis format and runs before the vulnerability-hunting phase.


2. When to Use This Skill

Use when:

  • Deep comprehension is needed before bug or vulnerability discovery.
  • You want bottom-up understanding instead of high-level guessing.
  • Reducing hallucinations, contradictions, and context loss is critical.
  • Preparing for security auditing, architecture review, or threat modeling.

Do not use for:

  • Vulnerability findings
  • Fix recommendations
  • Exploit reasoning
  • Severity/impact rating

3. How This Skill Behaves

When active, Claude will:

  • Default to ultra-granular analysis of each block and line.
  • Apply micro-level First Principles, 5 Whys, and 5 Hows.
  • Build and refine a persistent global mental model.
  • Update earlier assumptions when contradicted ("Earlier I thought X; now Y.").
  • Periodically anchor summaries to maintain stable context.
  • Avoid speculation; express uncertainty explicitly when needed.

Goal: deep, accurate understanding, not conclusions.


Rationalizations (Do Not Skip)

RationalizationWhy It's WrongRequired Action
"I get the gist"Gist-level understanding misses edge casesLine-by-line analysis required
"This function is simple"Simple functions compose into complex bugsApply 5 Whys anyway
"I'll remember this invariant"You won't. Context degrades.Write it down explicitly
"External call is probably fine"External = adversarial until proven otherwiseJump into code or model as hostile
"I can skip this helper"Helpers contain assumptions that propagateTrace the full call chain
"This is taking too long"Rushed context = hallucinated vulnerabilities laterSlow is fast

4. Phase 1 -- Initial Orientation (Bottom-Up Scan)

Before deep analysis, perform a minimal mapping:

  1. Detect the tech stack -- identify languages, frameworks, databases, auth providers, package managers.
  2. Identify major modules/files/contracts.
  3. Note obvious public/external entrypoints (HTTP routes, RPC handlers, CLI commands, webhooks).
  4. Identify likely actors (users, admins, services, external integrations).
  5. Identify important storage (database tables, state structs, config, env vars).
  6. Build a preliminary structure without assuming behavior.

This establishes anchors for detailed analysis.


5. Phase 2 -- Ultra-Granular Function Analysis (Default Mode)

Every non-trivial function receives full micro analysis.

5.1 Per-Function Microstructure Checklist

For each function:

  1. Purpose

- Why the function exists and its role in the system.

  1. Inputs & Assumptions

- Parameters and implicit inputs (state, sender, env). - Preconditions and constraints.

  1. Outputs & Effects

- Return values. - State/storage writes. - Events/messages. - External interactions.

  1. Block-by-Block / Line-by-Line Analysis For each logical block: Apply per-block:

- What it does. - Why it appears here (ordering logic). - What assumptions it relies on. - What invariants it establishes or maintains. - What later logic depends on it. - First Principles - 5 Whys - 5 Hows


5.2 Cross-Function & External Flow Analysis

When encountering calls, continue the same micro-first analysis across boundaries.

Internal Calls

  • Jump into the callee immediately.
  • Perform block-by-block analysis of relevant code.
  • Track flow of data, assumptions, and invariants: caller -> callee -> return -> caller.
  • Note if callee logic behaves differently in this specific call context.

External Calls -- Two Cases

Case A -- External Call to Code That Exists in the Codebase Treat as an internal call:

  • Jump into the target function.
  • Continue block-by-block micro-analysis.
  • Propagate invariants and assumptions seamlessly.
  • Consider edge cases based on the *actual* code, not a black-box guess.

Case B -- External Call Without Available Code (True External / Black Box) Analyze as adversarial:

  • Describe payload/parameters sent.
  • Identify assumptions about the target.
  • Consider all outcomes: failure, incorrect return values, unexpected state changes, misbehavior.

Continuity Rule

Treat the entire call chain as one continuous execution flow. Never reset context. All invariants, assumptions, and data dependencies must propagate across calls.


5.3 Complete Analysis Example

See FUNCTION_MICRO_ANALYSIS_EXAMPLE.md for a complete walkthrough.


5.4 Output Requirements

Structure output following OUTPUT_REQUIREMENTS.md.

Quality thresholds:

  • Minimum 3 invariants per function
  • Minimum 5 assumptions documented
  • Minimum 3 risk considerations for external interactions
  • At least 1 First Principles application
  • At least 3 combined 5 Whys/5 Hows applications

5.5 Completeness Checklist

Verify against COMPLETENESS_CHECKLIST.md before concluding.


6. Phase 3 -- Global System Understanding

After sufficient micro-analysis:

  1. State & Invariant Reconstruction -- Map reads/writes of each state variable. Derive multi-function invariants.
  2. Workflow Reconstruction -- Identify end-to-end flows. Track state transforms. Record persistent assumptions.
  3. Trust Boundary Mapping -- Actor -> entrypoint -> behavior. Identify untrusted input paths.
  4. Complexity & Fragility Clustering -- Functions with many assumptions, high branching, coupled state changes.

7. Stability & Consistency Rules

  • Never reshape evidence to fit earlier assumptions. Update the model and state corrections explicitly.
  • Periodically anchor key facts. Summarize invariants, state relationships, actor roles, workflows.
  • Avoid vague guesses. Use "Unclear; need to inspect X." instead of "It probably..."
  • Cross-reference constantly. Connect new insights to previous state, flows, and invariants.

8. Subagent Usage

Use the function-analyzer agent for per-function deep analysis of dense or complex functions, long data-flow chains, cryptographic logic, or state machines.


9. Non-Goals

While active, Claude should NOT: identify vulnerabilities, propose fixes, generate PoCs, model exploits, or assign severity.

This is pure context building only.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.15%
按下载量换算150

Claude

27.19%
按下载量换算113

Cursor

20.09%
按下载量换算84

Gemini CLI

8.52%
按下载量换算35

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills