scan
Solid引導自動化安全掃描、相依套件稽核與機密偵測。 Use when: 相依套件稽核、CVE 掃描、機密偵測、授權條款合規。 Not for: 人工的威脅建模與安全設計審查——請用 /security;一般的程式碼整潔度——請用 /sweep。 Keywords: scan, audit, CVE, dependency, secret, SBOM, vulnerability, 掃描, 稽核, 相依套件, 機密偵測.
Code & Development 71 stars
13 forks Updated today NOASSERTION
Install
Quality Score: 79/100
Stars 20%
Recency 20%
Frontmatter 20%
Documentation 15%
Issue Health 10%
License 10%
Description 5%
Skill Content
# 安全掃描助手
> **語言**: [English](../../../../skills/security-scan-assistant/SKILL.md) | 繁體中文
自動化相依套件、機密資訊和授權合規的安全掃描。
## 掃描類型
| 類型 | 工具範例 | 用途 |
|------|----------|------|
| **相依套件審計** | npm audit, pip-audit, Snyk | 檢測已知 CVE |
| **機密偵測** | gitleaks, trufflehog | 偵測洩漏的憑證 |
| **授權合規** | license-checker, SPDX | 驗證開源授權相容性 |
| **SAST** | Semgrep, CodeQL | 靜態分析程式碼模式 |
## 工具整合
| 工具 | 指令 | 範圍 |
|------|------|------|
| npm audit | `npm audit --json` | Node.js 相依套件 |
| Snyk | `npx snyk test` | 多語言相依套件 |
| Trivy | `trivy fs .` | 檔案系統與容器 |
| gitleaks | `gitleaks detect` | Git 歷史機密 |
| SPDX | `npx spdx-tool` | 授權 SBOM 產出 |
## 嚴重程度分類與 SLA
| 嚴重程度 | SLA | 標準 |
|----------|-----|------|
| **Critical** | 24 小時 | 遠端執行、認證繞過、資料外洩 |
| **High** | 72 小時 | 權限提升、SQL 注入 |
| **Medium** | 2 週 | XSS、CSRF、資訊洩漏 |
| **Low** | 下個 Sprint | 缺少 Header、冗長錯誤訊息 |
## 工作流程
```
SCAN ──► TRIAGE ──► PRIORITIZE ──► FIX ──► VERIFY
```
## 使用方式
- `/scan` - 完整掃描(相依套件 + 機密 + 授權)
- `/scan --deps` - 僅相依套件審計
- `/scan --secrets` - 僅機密偵測
- `/scan --license` - 授權合規檢查
## 下一步引導
`/scan` 完成後,AI 助手應建議:
> **掃描完成。建議下一步:**
> - 執行 `/security` 深入安全審查
> - 執行 `/checkin` 確認修復符合提交規範
> - 執行 `/commit` 提交安全修復
> - 更新相依套件 → `npm update` 或 `pip install --upgrade`
## 參考
- 核心規範:[security-standards.md](../../../../core/security-standards.md)
Details
- Author
- AsiaOstrich
- Repository
- AsiaOstrich/universal-dev-standards
- Created
- 8 months ago
- Last Updated
- today
- Language
- JavaScript
- License
- NOASSERTION
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
Code & Development Solid
security
引導安全審查與弱點評估,遵循 OWASP 標準。 Use when: 安全稽核、弱點檢查、安全程式碼審查、威脅建模。 Not for: 自動化的相依套件、CVE 與機密掃描——請用 /scan;處理正在發生的資安事件——請用 /incident。 Keywords: security, OWASP, vulnerability, authentication, authorization, 資訊安全, 弱點, 認證, 授權, 威脅建模.
71 Updated today
AsiaOstrich AI & Automation Listed
security-scan
对���码变更进行安全扫描,覆盖依赖漏洞、危险 API 使用、供应链风险和常见安全反模式。由 code-reviewer 在 /code-review 和 /ship 流程中自动调用。
1 Updated today
Kucell AI & Automation Listed
code-safety-audit
扫描代码安全漏洞,检测依赖漏洞、密钥泄露和OWASP安全模式。当用户提到安全扫描、漏洞检测、依赖审计、密钥泄露、API key、OWASP、npm audit、pip-audit或SQL注入/XSS等关键词时触发。
5 Updated 1 months ago
serejaris