← スキル一覧に戻る

security-audit
by xingxerx
⭐ 0🍴 0📅 2026年1月21日
SKILL.md
name: security-audit description: Includes sub-skills for OWASP Top 10 checks and ethical hacking heuristics.
Security Audit Skill
This skill allows the agent to perform basic security auditing and vulnerability scanning on the codebase.
OWASP Top 10 Checklist
When auditing, check for:
- Injection: SQLi, NoSQLi, Command Injection. (Look for concatenated strings in queries).
- Broken Auth: Weak passwords, missing tokens, exposed session IDs.
- Sensitive Data Exposure: Keys in code, PII logging, weak crypto.
- XXE: XML External Entities.
- Broken Access Control: IDOR, missing role checks.
Heuristics
- "Never trust user input."
- "Sanitize early, escape late."
- "Least Privilege principle."
Action
- If you find a vulnerability, flag it with
[SECURITY CRITICAL]. - Suggest a remediation (e.g., "Use parameterized queries").
スコア
総合スコア
60/100
リポジトリの品質指標に基づく評価
✓SKILL.md
SKILL.mdファイルが含まれている
+20
✓LICENSE
ライセンスが設定されている
+10
○説明文
100文字以上の説明がある
0/10
○人気
GitHub Stars 100以上
0/15
○最近の活動
3ヶ月以内に更新がある
0/10
○フォーク
10回以上フォークされている
0/5
✓Issue管理
オープンIssueが50未満
+5
✓言語
プログラミング言語が設定されている
+5
○タグ
1つ以上のタグが設定されている
0/5
レビュー
💬
レビュー機能は近日公開予定です