Token导航 LogoToken导航TokenDH.com
研究检索敏感数据github未标认证来源可访问许可证需确认审计提醒

security安全

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

5,016

周安装

209

GitHub Stars

4

下载量

1,672
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:security(安全)
来源仓库:https://github.com/cognitedata/dune-skills
仓库路径:skills/security
安装命令:
npx skills add https://github.com/cognitedata/dune-skills --skill security
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/cognitedata/dune-skills --skill security

简介

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。

  • 适合梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。
  • 不能将工具输出直接当作最终结论,涉及密钥或生产系统时应先确认最小权限。
  • 安装命令:npx skills add https://github.com/cognitedata/dune-skills --skill security。
  • 建议脱敏处理用户数据,并明确操作边界。

SKILL.md

Security Fix

Find and fix security issues in $ARGUMENTS (or the whole app if no argument is given). Work through every step below in order. Every step that finds an issue must also fix it.


Step 1 — Map the attack surface

Read these files before checking anything:

  • src/main.tsx / src/App.tsx — entry point, routing, auth gating
  • vite.config.ts — dev server proxy, CORS, headers
  • package.json — list of third-party dependencies
  • Any file matching **/auth*, **/login*, **/token*, **/credential*

Identify:

  • All pages/routes and whether each is behind an auth guard
  • All places where external data enters the app (CDF SDK calls, fetch, user form input)
  • All places where data is written back (CDF upsert, fetch POST/PUT/DELETE)

Step 2 — Migrate all CDF access to the Cognite SDK

All traffic to Cognite Data Fusion (CDF) must go through the official Cognite SDK. Find any HTTP, WebSocket, or other network call to CDF-like hosts or APIs that bypasses the SDK and rewrite it to use the SDK.

Search for raw HTTP calls

# Find fetch, axios, XMLHttpRequest, and other HTTP client usage
grep -rn --include="*.ts" --include="*.tsx" --include="*.js" \
  -E "(fetch\(|axios\.|axios\(|XMLHttpRequest|\.ajax\(|http\.get\(|http\.post\(|request\()" src/

# Find raw URL construction that looks like CDF endpoints
grep -rn --include="*.ts" --include="*.tsx" \
  -E "(cognitedata\.com|cognite\.ai|/api/v1/projects|cdf\.|\.cognite\.)" src/

# Find custom Authorization or api-key headers
grep -rn --include="*.ts" --include="*.tsx" \
  -E "(Authorization|api-key|apikey|x-api-key)" src/ | grep -v "node_modules"

How to fix

For each raw CDF call found, read the surrounding code to understand what CDF resource and operation it targets, then rewrite it using the appropriate SDK method. Remove the raw HTTP client import if it's no longer used.

PatternAction
fetch() or axios call to a CDF URL (*.cognitedata.com, /api/v1/projects/*)Rewrite to use the Cognite SDK (cognite.files.getDownloadUrls(...), cognite.timeseries.retrieve(...), client.instances.search(...), etc.)
Custom Authorization header with a CDF tokenRemove — the SDK handles auth automatically
WebSocket connection to CDF endpointsRewrite to use SDK streaming methods
Proxy endpoint that forwards to CDF internallyRewrite the proxy to use the SDK internally
fetch() to a non-CDF URL (static assets, documented third-party API)Leave — but add a comment documenting why it's needed

After rewriting all CDF calls, remove any axios or fetch-related imports that are no longer used.

What is acceptable

  • All CDF reads/writes through sdk.files.*, sdk.timeseries.*, client.instances.*, etc.
  • Non-CDF network calls that are:

- To known static asset hosts (CDNs, image services) - To documented third-party APIs required by the product - Explicitly noted in the app's README or architecture docs


Step 3 — Find and fix credential & secret hygiene

Search for hard-coded credentials and sensitive values:

# Look for anything that smells like a secret in source files
grep -rn --include="*.ts" --include="*.tsx" --include="*.js" \
  -E "(password|secret|apikey|api_key|token|bearer|private_key)\s*=\s*['\"]" src/

For each hardcoded secret, replace it with an environment variable. Create or update .env.example with a placeholder. Add .env to .gitignore if missing.

How to fix

  1. Replace each hardcoded secret with an import.meta.env.VITE_* reference. For example:

- const apiKey = "sk-abc123"const apiKey = import.meta.env.VITE_API_KEY - const token = "eyJhbG..."const token = import.meta.env.VITE_AUTH_TOKEN

  1. Add the variable to .env.example with a placeholder value (e.g., VITE_API_KEY=your-api-key-here). Create .env.example if it doesn't exist.
  2. Ensure .env and .env.local are in .gitignore — add them if missing.
  3. Remove any console.log, console.error, or similar calls that print a CDF token, user object, or API key.

Step 4 — Find and fix dangerous DOM APIs

Search for patterns that allow arbitrary script execution or HTML injection:

grep -rn --include="*.tsx" --include="*.ts" \
  -E "dangerouslySetInnerHTML|innerHTML\s*=|eval\(|new Function\(|setTimeout\(['\"]|setInterval\(['\"]" src/

For each dangerous DOM pattern, apply the fix directly. Install DOMPurify with pnpm add dompurify and pnpm add -D @types/dompurify if needed.

How to fix

  • dangerouslySetInnerHTML: Wrap the value with DOMPurify.sanitize(). Add import DOMPurify from 'dompurify' to the file. Example: // Before <div dangerouslySetInnerHTML={{__html: userContent}} /> // After import DOMPurify from 'dompurify'; <div dangerouslySetInnerHTML={{__html: DOMPurify.sanitize(userContent)}} />
  • eval() / new Function(): Rewrite using a data-driven approach. Use JSON.parse() for data parsing, or a lookup table / switch statement for dynamic logic dispatch. Never pass user-controlled strings to code evaluation.
  • setTimeout/setInterval with a string argument: Convert to a function reference: // Before setTimeout("doSomething()", 1000) // After setTimeout(() => doSomething(), 1000)

Step 5 — Find and fix authentication & authorization gaps

Read the auth setup (likely src/contexts/, src/hooks/, or setup-dune-auth output):

  • Every route that shows CDF data must be behind the Dune auth guard (useCogniteClient returns a non-null sdk before rendering).
  • The CDF client must be initialized with short-lived OIDC tokens, not a static API key.
  • User role/capability checks must happen server-side (CDF ACLs) — do not rely solely on hiding UI elements.

Check the useAtlasChat / Atlas agent integration:

  • The agentExternalId must not be constructed from user-supplied input.
  • Tool execute functions must not trust args blindly — validate or guard before using values in CDF queries.

How to fix

For each unguarded route that shows CDF data, wrap it with the auth guard component. For example, ensure the route element is wrapped in a component that checks useCogniteClient and renders a loading/login state when the SDK is not ready.

For Atlas tool execute functions, add argument validation at the top of each function. Validate that each args field is the expected type and within expected bounds before using it in any CDF query.


Step 6 — Find and fix input validation gaps

Every value that comes from a form, URL param, or query string before it reaches a CDF call or is rendered to the DOM must be validated:

# Find useSearchParams, URLSearchParams, and form onChange handlers
grep -rn --include="*.tsx" --include="*.ts" \
  -E "useSearchParams|URLSearchParams|searchParams\.get|e\.target\.value" src/

For each unvalidated external input, add runtime validation. Install Zod if not present (pnpm add zod). Create a schema that matches the expected shape and use .safeParse() instead of type casts.

How to fix

  1. Add Zod schemas for URL params and form inputs. Example: import {z} from 'zod'; const paramSchema = z.object({id: z.string().min(1), page: z.coerce.number().int().positive().default(1),}); const result = paramSchema.safeParse({id: searchParams.get('id'), page: searchParams.get('page')}); if (!result.success) {/* handle error */}
  2. Replace as MyType casts on external data with Zod .safeParse() — never trust data from URL params, form inputs, or API responses without validation.
  3. Add nullish fallbacks for searchParams.get() — always handle the case where the param is missing or empty.

Step 7 — Find and fix Vite / server configuration

Read vite.config.ts and any server.ts / express.ts files.

How to fix

Add any missing security headers to the vite.config.ts server.headers section. If the section doesn't exist, create it. The minimum required headers are:

server: {
  headers: {
    'Content-Security-Policy': "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self' https://*.cognitedata.com",
    'X-Frame-Options': 'DENY',
    'X-Content-Type-Options': 'nosniff',
  },
}

Adjust the Content-Security-Policy to match the app's actual needs (e.g., adding specific CDN hosts for fonts or images).

Also:

  • Remove any define entries in vite.config.ts that embed raw secrets into the bundle. Use import.meta.env instead.
  • Confirm the dev proxy (server.proxy) does not expose internal endpoints in production builds.

Step 8 — Find and fix dependency vulnerabilities

pnpm audit --audit-level=high

How to fix

  1. Run pnpm audit fix first to auto-fix what's possible.
  2. For any remaining high/critical CVEs, manually update the package version in package.json and run pnpm install.
  3. If a vulnerable package has no fix available, document it as a known risk and check if there's an alternative package.

Step 9 — Report remaining findings

Report only issues that could not be auto-fixed (e.g., architectural decisions that need human judgment, packages with no available fix, or patterns that require significant refactoring).

Summarize what was fixed in each step:

StepWhat was fixedRemaining issues
2 — CDF SDKMigrated N raw calls to SDK(any that couldn't be migrated)
3 — CredentialsReplaced N hardcoded secrets with env vars(any that need human decision)
4 — DOMSanitized N dangerous patterns(any that need refactoring)
5 — AuthWrapped N unguarded routes(any architectural gaps)
6 — ValidationAdded Zod schemas to N inputs(any that need custom logic)
7 — Vite configAdded N security headers(any CSP tuning needed)
8 — DependenciesFixed N vulnerable packages(any with no available fix)

If any remaining issues require immediate action before deployment, list them explicitly.


Done

State what was fixed and confirm the app is more secure. List any remaining items that require human judgment before the next deployment.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

36.82%
按下载量换算616

Claude

28.09%
按下载量换算470

Cursor

20.25%
按下载量换算339

Gemini CLI

10.31%
按下载量换算172

安全审计

Gen Agent Trust Hub

可疑

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills