Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问clear审计提醒

ln-621-security-auditorln 621 安全审核员

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

7,007

周安装

301

GitHub Stars

437

下载量

2,456
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:ln-621-security-auditor(ln 621 安全审核员)
来源仓库:https://github.com/levnikolaevich/claude-code-skills
仓库路径:skills/ln-621-security-auditor
安装命令:
npx skills add https://github.com/levnikolaevich/claude-code-skills --skill ln-621-security-auditor
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/levnikolaevich/claude-code-skills --skill ln-621-security-auditor

简介

用于安全审计、权限检查和常见漏洞排查,适合梳理敏感配置和鉴权逻辑。

  • 适用于需要分析凭据风险或生成安全复核清单的场景。
  • 使用时不能把工具输出直接当最终结论,需先确认最小权限和操作边界。
  • 涉及密钥、令牌或用户数据时应脱敏处理,避免影响生产系统。
  • 安装前建议确认权限范围和维护状态,确保不会触发不必要的网络或文件操作。

SKILL.md

Paths: File paths (shared/, references/, ../ln-*) are relative to skills repo root. If not found at CWD, locate this SKILL.md directory and go up one level for repo root. If shared/ is missing, fetch files via WebFetch from https://raw.githubusercontent.com/levnikolaevich/claude-code-skills/master/skills/{path}.

Security Auditor (L3 Worker)

Type: L3 Worker

Specialized worker auditing security vulnerabilities in codebase.

Purpose & Scope

  • Audit codebase for security vulnerabilities (Category 1: Critical Priority)
  • Scan for hardcoded secrets, SQL injection, XSS, insecure dependencies, missing input validation
  • Return structured findings to coordinator with severity, location, effort, recommendations
  • Calculate compliance score (X/10) for Security category

Inputs

MANDATORY READ: Load shared/references/audit_worker_core_contract.md. MANDATORY READ: Load shared/references/mcp_tool_preferences.md and shared/references/mcp_integration_patterns.md

Receives contextStore with: tech_stack, best_practices, principles, codebase_root, output_dir.

Use hex-graph first when dataflow or cross-file reference analysis materially improves confidence. Use hex-line first for local code reads when available. If MCP is unavailable, unsupported, or not indexed, continue with built-in Read/Grep/Glob/Bash and state the fallback in the report.

Workflow

MANDATORY READ: Load shared/references/two_layer_detection.md for detection methodology.

  1. Parse Context: Extract tech stack, best practices, codebase root, output_dir from contextStore
  2. Scan Codebase (Layer 1): Run security checks using Glob/Grep patterns (see Audit Rules below)
  3. Analyze Context (Layer 2): For each candidate, read surrounding code to classify:

- Secrets: test fixture / example / template -> FP. Production code -> confirmed - SQL injection: ORM parameterization nearby -> FP. Raw string concat with user input -> confirmed - XSS: framework auto-escapes (React JSX, Go templates) -> FP. Unsafe context (innerHTML, | safe) -> confirmed - Deps: vulnerable API not called in project -> downgrade. Exploitable path -> confirmed - Validation: internal service-to-service endpoint -> downgrade. Public API -> confirmed

  1. Collect Findings: Record confirmed violations with severity, location (file:line), effort estimate (S/M/L), recommendation
  2. Calculate Score: Count violations by severity, calculate compliance score (X/10)
  3. Write Report: Build full markdown report in memory per shared/templates/audit_worker_report_template.md, write to {output_dir}/ln-621--global.md in single Write call
  4. Return Summary: Return minimal summary to coordinator (see Output Format)

Audit Rules (Priority: CRITICAL)

1. Hardcoded Secrets

What: API keys, passwords, tokens, private keys in source code

Detection:

  • Search patterns: API_KEY = "...", password = "...", token = "...", SECRET = "..."
  • File extensions: .ts, .js, .py, .go, .java, .cs
  • Exclude: .env.example, README.md, test files with mock data

Severity:

  • CRITICAL: Production credentials (AWS keys, database passwords, API tokens)
  • HIGH: Development/staging credentials
  • MEDIUM: Test credentials in non-test files

Recommendation: Move to environment variables (.env), use secret management (Vault, AWS Secrets Manager)

Effort: S (replace hardcoded value with process.env.VAR_NAME)

2. SQL Injection Patterns

What: String concatenation in SQL queries instead of parameterized queries

Detection:

  • Patterns: query = "SELECT * FROM users WHERE id=" + userId, db.execute(f"SELECT * FROM {table}"), ` SELECT * FROM ${table} `
  • Languages: JavaScript, Python, PHP, Java

Severity:

  • CRITICAL: User input directly concatenated without sanitization
  • HIGH: Variable concatenation in production code
  • MEDIUM: Concatenation with internal variables only

Recommendation: Use parameterized queries (prepared statements), ORM query builders

Effort: M (refactor query to use placeholders)

3. XSS Vulnerabilities

What: Unsanitized user input rendered in HTML/templates

Detection:

  • Patterns: innerHTML = userInput, dangerouslySetInnerHTML={{__html: data}}, echo $userInput;
  • Template engines: Check for unescaped output ({{var | safe}}, <%- var %>)

Severity:

  • CRITICAL: User input directly inserted into DOM without sanitization
  • HIGH: User input with partial sanitization (insufficient escaping)
  • MEDIUM: Internal data with potential XSS if compromised

Recommendation: Use framework escaping (React auto-escapes, use textContent), sanitize with DOMPurify

Effort: S-M (replace innerHTML with textContent or sanitize)

4. Insecure Dependencies

What: Dependencies with known CVEs (Common Vulnerabilities and Exposures)

Detection:

  • Run npm audit (Node.js), pip-audit (Python), cargo audit (Rust), dotnet list package --vulnerable (.NET)
  • Check for outdated critical dependencies

Severity:

  • CRITICAL: CVE with exploitable vulnerability in production dependencies
  • HIGH: CVE in dev dependencies or lower severity production CVEs
  • MEDIUM: Outdated packages without known CVEs but security risk

Recommendation: Update to patched versions, replace unmaintained packages

Effort: S-M (update package.json, test), L (if breaking changes)

5. Missing Input Validation

What: Missing validation at system boundaries (API endpoints, user forms, file uploads)

Detection:

  • API routes without validation middleware
  • Form handlers without input sanitization
  • File uploads without type/size checks
  • Missing CORS configuration

Severity:

  • CRITICAL: File upload without validation, authentication bypass potential
  • HIGH: Missing validation on sensitive endpoints (payment, auth, user data)
  • MEDIUM: Missing validation on read-only or internal endpoints

Recommendation: Add validation middleware (Joi, Yup, express-validator), implement input sanitization

Effort: M (add validation schema and middleware)

Scoring Algorithm

MANDATORY READ: Load shared/references/audit_worker_core_contract.md and shared/references/audit_scoring.md.

Output Format

MANDATORY READ: Load shared/references/audit_worker_core_contract.md and shared/templates/audit_worker_report_template.md.

Write JSON summary per shared/references/audit_summary_contract.md. In managed mode the caller passes both runId and summaryArtifactPath; in standalone mode the worker generates its own run-scoped artifact path per shared contract.

Write report to {output_dir}/ln-621--global.md with category: "Security" and checks: hardcoded_secrets, sql_injection, xss_vulnerabilities, insecure_dependencies, missing_input_validation.

Return summary per shared/references/audit_summary_contract.md.

Standalone mode still writes the same JSON summary to a worker-owned run-scoped artifact path per shared contract.

Critical Rules

MANDATORY READ: Load shared/references/audit_worker_core_contract.md.

  • Do not auto-fix: Report violations only; coordinator creates task for user to fix
  • Tech stack aware: Use contextStore to apply framework-specific patterns (e.g., React XSS vs PHP XSS)
  • False positive reduction: Exclude test files, example configs, documentation
  • Effort realism: S = <1 hour, M = 1-4 hours, L = >4 hours
  • Location precision: Always include file:line for programmatic navigation

Definition of Done

MANDATORY READ: Load shared/references/audit_worker_core_contract.md.

  • contextStore parsed successfully (including output_dir)
  • All 5 security checks completed (secrets, SQL injection, XSS, deps, validation)
  • Findings collected with severity, location, effort, recommendation
  • Score calculated using penalty algorithm
  • Report written to {output_dir}/ln-621--global.md (atomic single Write call)
  • Summary written per contract

Reference Files


Version: 3.0.0 Last Updated: 2025-12-23

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

26.93%
按下载量换算661

Gemini CLI

23.55%
按下载量换算578

Codex

17.59%
按下载量换算432

OpenCode

12.34%
按下载量换算303

Cursor

8.88%
按下载量换算218

Antigravity

3.25%
按下载量换算80

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。

来源信息

继续浏览同类 Skills