安全最佳實務

安全最佳實務

依語言與框架檢視 Python、JavaScript/TypeScript、Go 的安全設計。

OpenAI · 官方來源 · 安全

舊來源已停止維護;請同時參考新版官方文件。

來源狀態

已棄用

官方目前建議來源

官方 README 建議改看 Plugins catalog;不表示此 Skill 已一對一搬遷。

資源類型

Skill

與類似 Skill 有什麼不同?

  • 受限安全瀏覽器

    Safe Browser 聚焦瀏覽時的信任邊界與敏感操作;Security Best Practices 檢視程式與框架的安全實作。

來源描述的能力

這些是來源描述的可能操作,不代表 2lus 已授予權限或已測試。

  • 讀取檔案
  • 寫入檔案
原始來源 ↗

這個 Skill 是什麼?

整理具體資料流、威脅前提與修補優先度,協助 secure-by-default 開發;不把泛用安全建議假稱為所有語言的官方支援。

可以做什麼?何時適合使用?

  • 檢閱 TypeScript API 的輸入與輸出。
  • 分析 Python 服務的安全設定。
  • 為 Go 的授權流程建立修補清單。

如何使用

  1. 先確認語言與框架是否在來源的參考文件中。
  2. 要求以程式位置、攻擊前提及影響整理報告。
  3. 區分確定問題與待查假設;僅在獲准後做最小修補。

使用前你需要準備

  • 待審查來源與權限
  • 威脅假設及不能操作的範圍

你可以替換:

[scope]、[permissions]

環境與相依需求

  • 可閱讀的程式碼與對應框架參考;來源主要涵蓋 Python、JS/TS、Go。

使用範例與 Prompt

以下是 2lus 撰寫的示範需求;請替換為你有權處理的檔案與專案,不代表已執行或保證結果。

入門

檢閱這個 TypeScript API 的輸入驗證與輸出編碼,只列有程式證據的風險。

實務

對這份 Python API 做安全報告,依嚴重度列程式位置、攻擊前提與最小修補;先不要改檔。

進階

分析 Go 授權中介層跨租戶資料流,列出證據與待確認假設,提出 regression cases;不得發送正式 API 請求。

實用提醒

  • 要求每個高優先問題附資料流證據,避免堆積通用建議。

限制與注意事項

  • 未宣稱完整支援 Java/Spring Boot;來源 repository 已 Deprecated。

安全注意事項

  • 去識別化安全報告,不貼憑證或可直接攻擊正式環境的秘密;沒有授權不得探測服務。

使用與設定

此條目不提供已確認的通用安裝指令;請依官方文件與 Agent 版本操作。

支援平台

Codex — 文件記載,未做實機相容性測試 官方文件 ↗

來源與授權

來源查核日期(非安全認證): 2026-09-29

Apache-2.0

原始來源 ↗ 授權條款 ↗ 官方文件 ↗

相關 Skills

使用第三方 Skill 前,請先檢查來源、權限與執行內容。安裝指令只供查看與複製,不會由 2lus 執行。

2lus AI Skills Library 提供 Skill 的整理與使用導覽。第三方 Skill 的內容、授權與可用性以原始來源為準。使用或安裝前,請自行確認其權限與執行內容。

Security Best Practices

Review security design in supported Python, JavaScript/TypeScript and Go projects.

OpenAI · Official source · Security

The legacy repository is deprecated; also consult the current official documentation.

Source status

Deprecated

Current official reference

The official README recommends the Plugins catalog; this does not establish a one-to-one relocation of this skill.

Resource type

Skill

How is this different from similar skills?

  • Safe Browser

    Safe Browser focuses on browsing trust boundaries and sensitive actions; Security Best Practices reviews code and framework security.

Documented capabilities

These are operations described upstream, not permissions granted or tested by 2lus.

  • Read files
  • Write files
Original source ↗

What is this skill?

Connect code evidence to threat assumptions and prioritized remedies for secure-by-default development, without presenting generic advice as official support for every language.

Use cases and when to use it

  • Inspect TypeScript API input/output paths.
  • Review Python service security settings.
  • Plan fixes for Go authorization logic.

How to use it

  1. Check whether the language and framework have upstream references.
  2. Request code locations, attack prerequisites and impact for each finding.
  3. Separate confirmed issues from hypotheses; make minimal fixes only when authorized.

What you need

  • Source and permissions to review
  • Threat assumptions and prohibited actions

You can replace:

[scope], [permissions]

Environment and dependencies

  • Readable code and matching framework guidance; primary coverage is Python, JS/TS and Go.

Usage and prompt examples

These example requests were written by 2lus. Substitute files and projects you may use; examples are not executed results or guarantees.

Beginner

Review input validation and output encoding in this TypeScript API. Report only risks with code evidence.

Practical

Prepare a prioritized Python API security report with locations, attack prerequisites and minimal remedies. Do not edit files yet.

Advanced

Trace cross-tenant access in this Go authorization middleware. Separate evidence from hypotheses and propose regression cases without contacting production APIs.

Tips

  • Require data-flow evidence for high-priority findings.

Limitations

  • No claim of complete Java/Spring Boot coverage; the source repository is deprecated.

Security notes

  • Redact reports and credentials; do not probe services without authorization.

Usage and setup

No verified universal installation command is provided for this entry. Follow the official documentation for your agent version.

Supported agents

Codex — Documented; not runtime-tested Documentation ↗

Sources and license

Source check date (not a safety certification): 2026-09-29

Apache-2.0

Original source ↗ License terms ↗ Documentation ↗

Related skills

Before using a third-party skill, review its source, permissions and executable content. Commands are for viewing and copying only; 2lus does not execute them.

2lus AI Skills Library provides curated educational guides. Third-party content, licenses and availability are governed by their original sources. Review permissions and executable content before use or installation.