code-audit

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Source Code Security Audit

Source Code Security Audit

ACTION REQUIRED(读完后立刻执行)

ACTION REQUIRED (Execute Immediately After Reading)

  1. NOW
    : 读取
    ../field-journal/precedent-pentest.md
    或代码审计授权
  2. NOW
    : 确认有源码/仓库访问(无源码二进制 → 转 RE skill)
  3. NOW
    : 明确语言栈与范围(目录/服务/PR diff)
  4. NEXT
    : tool-index;semgrep 等
  5. ACT
    : 威胁建模草图 → 自动扫描 → 人工验证
  1. NOW
    : Read
    ../field-journal/precedent-pentest.md
    or code audit authorization document
  2. NOW
    : Confirm source code/repository access (If only binary without source code → switch to RE skill)
  3. NOW
    : Clarify tech stack and scope (directories/services/PR diff)
  4. NEXT
    : tool-index; semgrep, etc.
  5. ACT
    : Threat modeling sketch → automated scanning → manual verification

适用场景

Applicable Scenarios

  • 白盒审计、PR/差分安全审查
  • Semgrep / CodeQL / Bandit / gosec 等 SAST
  • 危险 API、注入点、鉴权缺失、加密误用
  • supply-chain-security/
    分工:本 skill 偏自有代码逻辑,供应链偏依赖与管道
  • White-box audit, PR/differential security review
  • SAST tools like Semgrep / CodeQL / Bandit / gosec
  • Dangerous APIs, injection points, missing authentication, improper encryption usage
  • Division of work with
    supply-chain-security/
    : This skill focuses on in-house code logic, while supply chain focuses on dependencies and pipelines

工作流

Workflow

1. 范围与威胁模型

1. Scope and Threat Modeling

text
□ 信任边界:用户输入、文件、反序列化、SSRF、鉴权中间件
□ 高价值资产:鉴权、支付、管理端、密钥处理
text
□ Trust boundaries: user input, files, deserialization, SSRF, authentication middleware
□ High-value assets: authentication, payment, admin panel, key handling

2. 自动扫描

2. Automated Scanning

bash
semgrep --config auto .
bash
semgrep --config auto .

或项目规则包

Or project rule package

semgrep --config p/owasp-top-ten .
undefined
semgrep --config p/owasp-top-ten .
undefined

3. 人工验证(MUST)

3. Manual Verification (MUST)

text
□ 每个 SAST 命中:可达性?可利用性?误报?
□ 鉴权:IDOR/越权、缺校验、错误的多租户隔离
□ 注入:SQL/命令/模板/LDAP
□ 加密:硬编码密钥、ECB、自定义 crypto
text
□ Each SAST hit: Reachability? Exploitability? False positive?
□ Authentication: IDOR/permission bypass, missing validation, incorrect multi-tenant isolation
□ Injection: SQL/command/template/LDAP
□ Encryption: hardcoded keys, ECB, custom crypto

4. 产出

4. Deliverables

text
Finding:位置 + 数据流 + PoC + 修复建议
可选 ATT&CK / CWE 编号
text
Finding: Location + Data Flow + PoC + Fix Recommendations
Optional ATT&CK / CWE IDs

工具链

Toolchain

工具语言/场景
Semgrep多语言快速规则
CodeQL深数据流(GitHub)
BanditPython
gosec / staticcheckGo
SpotBugs / FindSecBugsJava
ToolLanguage/Scenario
SemgrepMulti-language quick rules
CodeQLDeep data flow (GitHub)
BanditPython
gosec / staticcheckGo
SpotBugs / FindSecBugsJava

参考

References

  • references/sast-review-checklist.md
  • ../supply-chain-security/
    ../api-security/
    ../llm-security/
    (Agent 代码)
  • references/sast-review-checklist.md
  • ../supply-chain-security/
    ../api-security/
    ../llm-security/
    (Agent code)

路由上下文

Routing Context

上游: MASTER R26
角色:
ops/role-map.md
cae
下游: 依赖漏洞 → supply-chain;运行时验证 → pentest-tools
Upstream: MASTER R26
Role:
ops/role-map.md
cae
Downstream: Dependency vulnerabilities → supply-chain; Runtime verification → pentest-tools

任务完成自检

Task Completion Self-Check

  • 是否人工验证而非只贴扫描器输出?
  • 是否含修复建议?
  • 是否限定在授权仓库范围?
  • Checklist?
  • Is manual verification done instead of just pasting scanner outputs?
  • Are fix recommendations included?
  • Is it limited to the authorized repository scope?
  • Checklist completed?