安全最佳實務
安全最佳實務
依語言與框架檢視 Python、JavaScript/TypeScript、Go 的安全設計。
OpenAI · 官方來源 · 安全
舊來源已停止維護;請同時參考新版官方文件。
來源狀態
已棄用
官方目前建議來源官方 README 建議改看 Plugins catalog;不表示此 Skill 已一對一搬遷。
資源類型
Skill
與類似 Skill 有什麼不同?
- 受限安全瀏覽器
Safe Browser 聚焦瀏覽時的信任邊界與敏感操作;Security Best Practices 檢視程式與框架的安全實作。
來源描述的能力
這些是來源描述的可能操作,不代表 2lus 已授予權限或已測試。
- 讀取檔案
- 寫入檔案
這個 Skill 是什麼?
整理具體資料流、威脅前提與修補優先度,協助 secure-by-default 開發;不把泛用安全建議假稱為所有語言的官方支援。
可以做什麼?何時適合使用?
- 檢閱 TypeScript API 的輸入與輸出。
- 分析 Python 服務的安全設定。
- 為 Go 的授權流程建立修補清單。
如何使用
- 先確認語言與框架是否在來源的參考文件中。
- 要求以程式位置、攻擊前提及影響整理報告。
- 區分確定問題與待查假設;僅在獲准後做最小修補。
使用前你需要準備
- 待審查來源與權限
- 威脅假設及不能操作的範圍
你可以替換:
[scope]、[permissions]
環境與相依需求
- 可閱讀的程式碼與對應框架參考;來源主要涵蓋 Python、JS/TS、Go。
使用範例與 Prompt
以下是 2lus 撰寫的示範需求;請替換為你有權處理的檔案與專案,不代表已執行或保證結果。
入門
檢閱這個 TypeScript API 的輸入驗證與輸出編碼,只列有程式證據的風險。
實務
對這份 Python API 做安全報告,依嚴重度列程式位置、攻擊前提與最小修補;先不要改檔。
進階
分析 Go 授權中介層跨租戶資料流,列出證據與待確認假設,提出 regression cases;不得發送正式 API 請求。
實用提醒
- 要求每個高優先問題附資料流證據,避免堆積通用建議。
限制與注意事項
- 未宣稱完整支援 Java/Spring Boot;來源 repository 已 Deprecated。
安全注意事項
- 去識別化安全報告,不貼憑證或可直接攻擊正式環境的秘密;沒有授權不得探測服務。
使用與設定
此條目不提供已確認的通用安裝指令;請依官方文件與 Agent 版本操作。
支援平台
Codex — 文件記載,未做實機相容性測試 官方文件 ↗
來源與授權
來源查核日期(非安全認證): 2026-09-29
Apache-2.0
原始來源 ↗ 授權條款 ↗ 官方文件 ↗相關 Skills
使用第三方 Skill 前,請先檢查來源、權限與執行內容。安裝指令只供查看與複製,不會由 2lus 執行。
2lus AI Skills Library 提供 Skill 的整理與使用導覽。第三方 Skill 的內容、授權與可用性以原始來源為準。使用或安裝前,請自行確認其權限與執行內容。
Security Best Practices
Review security design in supported Python, JavaScript/TypeScript and Go projects.
OpenAI · Official source · Security
The legacy repository is deprecated; also consult the current official documentation.
Source status
Deprecated
Current official referenceThe official README recommends the Plugins catalog; this does not establish a one-to-one relocation of this skill.
Resource type
Skill
How is this different from similar skills?
- Safe Browser
Safe Browser focuses on browsing trust boundaries and sensitive actions; Security Best Practices reviews code and framework security.
Documented capabilities
These are operations described upstream, not permissions granted or tested by 2lus.
- Read files
- Write files
What is this skill?
Connect code evidence to threat assumptions and prioritized remedies for secure-by-default development, without presenting generic advice as official support for every language.
Use cases and when to use it
- Inspect TypeScript API input/output paths.
- Review Python service security settings.
- Plan fixes for Go authorization logic.
How to use it
- Check whether the language and framework have upstream references.
- Request code locations, attack prerequisites and impact for each finding.
- Separate confirmed issues from hypotheses; make minimal fixes only when authorized.
What you need
- Source and permissions to review
- Threat assumptions and prohibited actions
You can replace:
[scope], [permissions]
Environment and dependencies
- Readable code and matching framework guidance; primary coverage is Python, JS/TS and Go.
Usage and prompt examples
These example requests were written by 2lus. Substitute files and projects you may use; examples are not executed results or guarantees.
Beginner
Review input validation and output encoding in this TypeScript API. Report only risks with code evidence.
Practical
Prepare a prioritized Python API security report with locations, attack prerequisites and minimal remedies. Do not edit files yet.
Advanced
Trace cross-tenant access in this Go authorization middleware. Separate evidence from hypotheses and propose regression cases without contacting production APIs.
Tips
- Require data-flow evidence for high-priority findings.
Limitations
- No claim of complete Java/Spring Boot coverage; the source repository is deprecated.
Security notes
- Redact reports and credentials; do not probe services without authorization.
Usage and setup
No verified universal installation command is provided for this entry. Follow the official documentation for your agent version.
Supported agents
Codex — Documented; not runtime-tested Documentation ↗
Sources and license
Source check date (not a safety certification): 2026-09-29
Apache-2.0
Original source ↗ License terms ↗ Documentation ↗Related skills
Before using a third-party skill, review its source, permissions and executable content. Commands are for viewing and copying only; 2lus does not execute them.
2lus AI Skills Library provides curated educational guides. Third-party content, licenses and availability are governed by their original sources. Review permissions and executable content before use or installation.