code-audit

仓库创建 2026年7月8日最近提交 3 天前SkillHot 收录 3 小时前
▸ 精选理由

结合大量实战样例,适合深度安全评估与渗透准备。

这个 Skill 做什么

覆盖55+漏洞类型的专业代码安全审计与检测流程。

做专业的代码安全审计,覆盖 55+ 漏洞类型和 143 项检测要点,支持 Java、Python、Go、PHP、JavaScript/Node、C/C++、.NET、Ruby、Rust 等语言。适合在代码评审、漏洞扫描、渗透测试准备或安全合规检查时调用。特色是结合大量真实漏洞案例,能查 SQL 注入、XSS、RCE、反序列化、SSRF 等传统与现代安全问题。

▸ 展开 SKILL.md 英文原文

Professional code security audit skill covering 55+ vulnerability types. Enhanced with WooYun 88,636 real-world vulnerability cases (2010-2016). This skill should be used when performing security audits, vulnerability scanning, penetration testing preparation, or code review for security issues. Supports 9 languages: Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C#, Ruby, Rust. Includes 143 mandatory detection items across all languages with language-specific checklists. Covers SQL injection, XSS, RCE, deserialization, SSRF, JNDI injection, JDBC protocol injection, authentication bypass, business logic flaws, race conditions, and modern security domains (LLM, Serverless, Android). WooYun integration adds: statistical-driven parameter priority, bypass techniques library, logic vulnerability patterns, and real-case references. v1.0: Initial public release with Docker deployment verification framework.

开发编程代码审计漏洞检测安全流程通用
243
Stars
13
Forks
40
仓库内 Skill
积累中
7 日增星
安装 / 使用
给你的 Agent 一句话(通用)
帮我安装这个 skill:https://raw.githubusercontent.com/OpenAisec/Miko/main/data/skills/code-audit/SKILL.md
或 curl 直取 SKILL.md
curl -fsSL "https://raw.githubusercontent.com/OpenAisec/Miko/main/data/skills/code-audit/SKILL.md"
SKILL.MD 节选查看完整文件 ↗
# Code Audit Skill

> 专业代码安全审计技能 | Professional Code Security Audit
> 支持模式: quick / standard / deep

## When to Use This Skill

This skill should be used when:

- User requests **code audit**, **security audit**, or **vulnerability scanning**
- User asks to **check code security** or **find security issues**
- User mentions **/audit** or **/code-audit**
- User wants to **review code for vulnerabilities** before deployment
- User needs **penetration testing preparation** or **security assessment**

**Trigger phrases:**
- "审计这个项目" / "Audit this project"
- "检查代码安全" / "Check code security"
- "找出安全漏洞" / "Find security vulnerabilities"
- "/audit", "/code-audit"

---

## Quick Reference

### Scan M
via SKILL·HOT · 数据来自 GitHub 公开信息 · 原文版权归作者所有