Loading...
Loading...
Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
npx skill4agent add zhaoxuya520/reverse-skill code-auditNOW../field-journal/precedent-pentest.mdNOWNOWNEXTACTsupply-chain-security/□ Trust boundaries: user input, files, deserialization, SSRF, authentication middleware
□ High-value assets: authentication, payment, admin panel, key handlingsemgrep --config auto .
# Or project rule package
semgrep --config p/owasp-top-ten .□ Each SAST hit: Reachability? Exploitability? False positive?
□ Authentication: IDOR/permission bypass, missing validation, incorrect multi-tenant isolation
□ Injection: SQL/command/template/LDAP
□ Encryption: hardcoded keys, ECB, custom cryptoFinding: Location + Data Flow + PoC + Fix Recommendations
Optional ATT&CK / CWE IDs| Tool | Language/Scenario |
|---|---|
| Semgrep | Multi-language quick rules |
| CodeQL | Deep data flow (GitHub) |
| Bandit | Python |
| gosec / staticcheck | Go |
| SpotBugs / FindSecBugs | Java |
references/sast-review-checklist.md../supply-chain-security/../api-security/../llm-security/ops/role-map.md