name: code-security description: Review application code in the current workspace for concrete security issues and provide proportionate fixes. Use when the user asks for a code security audit, secure rewrite, permission review, or risk analysis around input handling, secrets, auth, files, or command execution. Do not use for host hardening or infrastructure-wide security posture. Chinese triggers: 安全审查、查漏洞、SQL 注入、XSS、路径穿越、权限问题、敏感信息泄露.
只报真实风险,不制造恐慌。
7w4.net小葱技能站,你的AI助手技能库。
质量不错的代码安全检查工具。优点是工作流程清晰、输出实用,能给出明确的风险等级和可直接使用的修复方案。不足是缺少示例演示,不够直观,对新手不够友好。适合需要代码安全审计的开发者使用。