Security Audit

Security Audit

從原始碼與信任邊界整理安全疑點及證據。

Cloudflare · 官方來源 · 安全

來源狀態

可用來源

原始名稱: security-audit

資源類型

Skill

與類似 Skill 有什麼不同?

  • 安全最佳實務

    Security Audit 追查安全疑點、信任邊界與證據;Security Best Practices 偏向安全編碼建議。

來源描述的能力

這些是來源描述的可能操作,不代表 2lus 已授予權限或已測試。

尚未列出能力,請審查原始來源。

這個 Skill 是什麼?

在授權範圍內檢視 API、服務、CLI 與函式庫,區分待確認的疑點與有證據支持的漏洞。

可以做什麼?何時適合使用?

  • 檢查 API 是否跨越租戶邊界。
  • 追查輸入如何到達敏感操作。
  • 整理完整程式安全審查報告。

如何使用

  1. 提供授權範圍、原始碼及架構背景。
  2. 從入口追蹤資料與權限檢查,記錄邊界及受影響資源。
  3. 逐項列證據、未確認事項與最小修補;需要重現時先定義隔離條件。

使用前你需要準備

  • 授權原始碼
  • 架構背景與信任邊界

你可以替換:

請替換範例中的檔名與情境,提供範圍、限制及預期產物。

環境與相依需求

  • 授權原始碼
  • 架構背景與信任邊界

使用範例與 Prompt

以下是 2lus 撰寫的示範需求;請替換為你有權處理的檔案與專案,不代表已執行或保證結果。

入門

用 Security Audit 閱讀 download-handler.ts,列出檔案路徑與使用者權限的信任邊界;只讀分析,不執行請求。

實務

審查已授權的多租戶訂單 API 原始碼,追蹤 tenantId 到資料查詢;分開列出疑點、反證與缺少的驗證證據。

進階

規劃此 CLI 與 daemon 的防禦性完整安全審查:定義授權範圍、入口、資源邊界、隔離重現條件及修補優先順序;未重現者不得標為確認漏洞。

實用提醒

  • 報告附上檔案位置與可反駁的假設。

限制與注意事項

  • 靜態疑點不等於確認漏洞,也不能保證找出所有問題。

安全注意事項

  • 只處理有權使用的資料;先檢閱第三方指令與相依工具,移除密鑰及個資。2lus 不會執行 Skill。

使用與設定

此條目不提供已確認的通用安裝指令;請依官方文件與 Agent 版本操作。

支援平台

未確認特定 Agent 相容性

來源與授權

來源查核日期(非安全認證): 2026-09-30

請參考原始來源授權條款

原始來源 ↗ 官方文件 ↗

GitHub 關注趨勢

約 +4600 / 7d

快照日期(UTC): 2026-09-30

快照來源: weekly-agent-skills-ranking

歷史快照

需求提供的近似 Repository 成長快照,並非 GitHub 官方 Analytics;同 Repository 的 Skill 共用此訊號。

Star 成長代表近期 GitHub 關注度,不代表品質排名。

相關 Skills

使用第三方 Skill 前,請先檢查來源、權限與執行內容。安裝指令只供查看與複製,不會由 2lus 執行。

2lus AI Skills Library 提供 Skill 的整理與使用導覽。第三方 Skill 的內容、授權與可用性以原始來源為準。使用或安裝前,請自行確認其權限與執行內容。

Security Audit

Review security candidates against source evidence and trust boundaries.

Cloudflare · Official source · Security

Source status

Active source

Original name: security-audit

Resource type

Skill

How is this different from similar skills?

  • Security Best Practices

    Security Audit investigates candidates and boundary evidence; Security Best Practices focuses on secure coding guidance.

Documented capabilities

These are operations described upstream, not permissions granted or tested by 2lus.

Capabilities not declared here; review the original source.

What is this skill?

Investigate authorized codebases, APIs, services and command-line tools while separating hypotheses from substantiated vulnerabilities.

Use cases and when to use it

  • Inspect cross-tenant authorization.
  • Trace untrusted input to sensitive operations.
  • Prepare a scoped security review.

How to use it

  1. Provide authorized scope, source and architecture.
  2. Trace entry points, permission checks and affected resources.
  3. Report evidence, uncertainties and minimal fixes; define isolation before reproduction.

What you need

  • Authorized source code
  • Architecture context and trust boundaries

You can replace:

Replace example filenames and context; specify scope, constraints and the intended deliverable.

Environment and dependencies

  • Authorized source code
  • Architecture context and trust boundaries

Usage and prompt examples

These example requests were written by 2lus. Substitute files and projects you may use; examples are not executed results or guarantees.

Beginner

Use Security Audit on download-handler.ts to identify path and authorization boundaries. Read only; send no requests.

Practical

Review authorized multi-tenant order API code. Trace tenantId to queries and separate candidates, counterevidence and missing validation.

Advanced

Plan a defensive review of this CLI and daemon with scope, entry points, boundaries, isolated reproduction conditions and fix priorities. Do not confirm untested candidates.

Tips

  • Attach source locations and falsifiable hypotheses.

Limitations

  • Static candidates are not confirmed vulnerabilities; coverage is never guaranteed.

Security notes

  • Use authorized inputs; review third-party instructions and dependencies, remove secrets and personal data. 2lus does not execute skills.

Usage and setup

No verified universal installation command is provided for this entry. Follow the official documentation for your agent version.

Supported agents

Specific agent compatibility unknown

Sources and license

Source check date (not a safety certification): 2026-09-30

Refer to the original source license terms

Original source ↗ Documentation ↗

GitHub Momentum

Approx. +4600 / 7d

Snapshot date (UTC): 2026-09-30

Snapshot source: weekly-agent-skills-ranking

Historical snapshot

Approximate repository growth supplied by the selection brief, not official GitHub Analytics; skills in the same repository share this signal.

Star growth reflects recent GitHub attention, not a quality ranking.

Related skills

Before using a third-party skill, review its source, permissions and executable content. Commands are for viewing and copying only; 2lus does not execute them.

2lus AI Skills Library provides curated educational guides. Third-party content, licenses and availability are governed by their original sources. Review permissions and executable content before use or installation.