Agent skill

Cm Security

by kingxiaozhe in kingxiaozhe/cm-workflow

用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。

MITAuto-check passedDevelopment

Install Cm Security

skills CLI
$ npx skills add kingxiaozhe/cm-workflow --skill cm-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kingxiaozhe/cm-workflow cm-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cm-security .claude/skills/cm-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cm-security
GitHub stars
104
Used in
1 other repo
Token cost
~744 tokens
SKILL.md length
127 words
Files
2 (incl. references)
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。

  • Works in 9 steps: 省略项目时解析当前 Git 仓库根。显式路径也定位到该仓库根;无… → 先确认地图在 Git index… → 从当前 Skill 位置解析… → …
  • Development work in your project
  • SKILL.md covers 用法, 执行 and 报告
  • Calls node

What it does

Cm Security is an agent skill from kingxiaozhe/cm-workflow. 用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。

Its SKILL.md is about 740 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/scan-contract.md`).

It sits in Development. It works with Git. The repository describes itself as: Codex-native, spec-driven AI Agent workflow with Claude Code compatibility, independent review, QA, fixes, and refactors. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/cm-security”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. 省略项目时解析当前 Git 仓库根。显式路径也定位到该仓库根;无 Git/HEAD、主分支缺失或有歧义时停止并说明,不猜基准,不自动 fetch。--all 不要求主分支,但仍要求 Git/HEAD。
  2. 先确认地图在 Git index 中为普通已跟踪文件,再加载业务地图,只读核对受影响的入口、调用方、权限与数据流。地图缺失、陈旧或失真时,从相关代码补足本次分析,标明缺口;不自动全仓重建或更新地图。
  3. 从当前 Skill 位置解析 {CM_WORKFLOW_ROOT},逐项传参数,禁止拼接用户文本为 shell 命令
  4. 将扫描 JSON 原样保存在项目外本次私有目录的普通文件中,保留范围、digest、工具状态、遗漏和 findings。退出码 1 表示发现候选问题,3 表示检查仍不完整,均需继续上下文复核;2 表示阻断,只汇报阻断原因。0 可能是 NO_CHANGES,不是安全认证。
  5. 对 selected 中每个路径做轻量 AI 复核。先看改动及调用链,再看扫描候选;只加载相关代码,禁止默认加载整套外部审计 Skill。命中或触及鉴权、支付、跨租户、命令/文件/网络边界时,沿该路径深入。
  6. 逐项核验输入是否可控、现有防护是否有效、受影响业务及复现条件。分别检查工作区与不同的暂存版本;删除或改名必须结合基准版本和调用方,不能只看剩余文件。引用 revision + 文件:行号。
  7. 对越权、注入、路径穿越、SSRF、敏感信息暴露、依赖漏洞给出有证据的判断。工具输出只算候选;没有测试或一般最佳实践不足以认定漏洞。无需主动执行 PoC、项目脚本、安装依赖或访问业务服务。
  8. 按复核 JSON 合同生成逐路径复核结果,写入项目外普通文件;不得传入 result、coverage 或 aiReview。必须调用以下命令;它内部重跑 inventory 核对复核窗口漂移,保留扫描窗口证据,机械核对漏报与覆盖率
  9. 以 --finalize 返回的 result、coverage、gaps 与 reportPath 输出简短结论,模型不再自行决定结论词。读取私有报告的 checkSummary,逐项展示已完成、已尝试但失败、未运行及原因,再列 nextSteps;OSV…

What it can do on your machine

Read from SKILL.md and the folder at commit 82d43f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cm Security loads about 744 tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 41 tokens; SKILL.md has 127 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~744
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kingxiaozhe/cm-workflow at commit 82d43f0, republished under its MIT licence (© kingxiaozhe). 127 words, ~744 tokens.

Download SKILL.mdSave it as .claude/skills/cm-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
cm-security
description
用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。

cm-security — 代码安全扫描与业务复核

先读 ../../runtime/project-context.md、../../runtime/logging.md 和 执行合同。 本 Skill 是独立只读安全入口;不改变 cm-test、任务完成门禁或发布授权。 Codex 用 $cm-security,Claude Code 用 /cm-security;macOS/Linux 兼容 /cm:security。

用法

text
$cm-security
$cm-security {项目路径}
$cm-security {项目路径} --all
$cm-security {项目路径} --semgrep-rules {已审查的外部本地规则文件}
$cm-security {项目路径} --osv-db {外部离线数据库缓存目录}

执行

  1. 省略项目时解析当前 Git 仓库根。显式路径也定位到该仓库根;无 Git/HEAD、主分支缺失或有歧义时停止并说明,不猜基准,不自动 fetch。--all 不要求主分支,但仍要求 Git/HEAD。
  2. 先确认地图在 Git index 中为普通已跟踪文件,再加载业务地图,只读核对受影响的入口、调用方、权限与数据流。地图缺失、陈旧或失真时,从相关代码补足本次分析,标明缺口;不自动全仓重建或更新地图。
  3. 从当前 Skill 位置解析 {CM_WORKFLOW_ROOT},逐项传参数,禁止拼接用户文本为 shell 命令:
bash
node "{CM_WORKFLOW_ROOT}/scripts/cm-security.mjs" --project "{项目根}" {已解析的可选参数}
  1. 将扫描 JSON 原样保存在项目外本次私有目录的普通文件中,保留范围、digest、工具状态、遗漏和 findings。退出码 1 表示发现候选问题,3 表示检查仍不完整,均需继续上下文复核;2 表示阻断,只汇报阻断原因。0 可能是 NO_CHANGES,不是安全认证。
  2. 对 selected 中每个路径做轻量 AI 复核。先看改动及调用链,再看扫描候选;只加载相关代码,禁止默认加载整套外部审计 Skill。命中或触及鉴权、支付、跨租户、命令/文件/网络边界时,沿该路径深入。
  3. 逐项核验输入是否可控、现有防护是否有效、受影响业务及复现条件。分别检查工作区与不同的暂存版本;删除或改名必须结合基准版本和调用方,不能只看剩余文件。引用 revision + 文件:行号。
  4. 对越权、注入、路径穿越、SSRF、敏感信息暴露、依赖漏洞给出有证据的判断。工具输出只算候选;没有测试或一般最佳实践不足以认定漏洞。无需主动执行 PoC、项目脚本、安装依赖或访问业务服务。
  5. 按复核 JSON 合同生成逐路径复核结果,写入项目外普通文件;不得传入 result、coverage 或 aiReview。必须调用以下命令;它内部重跑 inventory 核对复核窗口漂移,保留扫描窗口证据,机械核对漏报与覆盖率:
bash
node "{CM_WORKFLOW_ROOT}/scripts/cm-security.mjs" --project "{项目根}" --finalize --scan "{外部扫描报告.json}" --review "{外部复核结果.json}"
  1. 以 --finalize 返回的 result、coverage、gaps 与 reportPath 输出简短结论,模型不再自行决定结论词。读取私有报告的 checkSummary,逐项展示已完成、已尝试但失败、未运行及原因,再列 nextSteps;OSV 数据库新旧未知或生态未核验必须保留,不能把工具执行成功写成数据已更新。宿主在项目外创建私有报告目录;BLOCKED 时报告证据过期或输入错误,不替用户回滚。最终 JSON 原样保留校验通过的分析结论及未复核 reason,按路径列出未复核项;stdout 仅含六个摘要字段,不含自由描述。脱敏针对工具原始 stdout/stderr、密钥原文与源码片段;模型不得把这些内容粘进复核字段,JS 无法验证这项语义义务。默认扫描不自动修复、不安装、不提交、不上传给额外服务;需要修复时将证据交给用户决定。

范围、业务地图与安全边界确认后按 runtime/logging.md 写 run_start;--finalize 返回终态后写 run_done,只记录扫描范围、结论词、发现数量、覆盖率与报告路径。本 Skill 通常在没有 specs 目录的项目上独立运行,保存首次写入器返回的 run_id 并在后续事件显式传回。工具原始 stdout/stderr、密钥原文、源码片段与 findings 正文不进日志;BLOCKED 同样写 run_done,detail 只写阻断原因。写日志不改变本 Skill 的只读边界。

报告

text
安全检查:FINDINGS / REVIEWED_PARTIAL / NO_CHANGES / BLOCKED
范围:基准 → 当前分支 + 已跟踪暂存/工作区,或全部已跟踪文件
业务地图:已核验 / 部分核验 / 缺失 / 陈旧
发现:严重程度、文件:行号、受影响业务、证据与修复建议
已完成或尝试:工具、检查内容、版本、完成/失败及已有缺口
未运行:工具、原因(如未指定 Semgrep 规则、未提供 OSV 离线数据库)
需要补齐 / 下一步:逐项列规则、工具、离线数据或人工核验要求
AI 复核:completed、已复核路径、未复核路径及原因、分析结论与修复建议
源码一致性:扫描窗口、复核窗口分别列出;综合一致 / 变化
报告:绝对路径

存在候选问题时使用 FINDINGS,并分清已确认与待验证;源码漂移或范围不可信优先 BLOCKED。 无发现且有选中路径时一律使用 REVIEWED_PARTIAL,包括 coverage 为 FULL 的情况。 即使所选检查全完成,也只能说明本轮未发现问题,不能输出“没有漏洞”或替代独立 Review。 未跟踪文件只报告数量,不读取;需要包含时由用户明确选择并另行确认范围,不自动 git add。

© kingxiaozhe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/cm-security of kingxiaozhe/cm-workflow.

  • SKILL.md
  • references/scan-contract.md

Open the folder on GitHubat commit 82d43f0

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in kingxiaozhe/cm-workflow, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cm Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cm Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cm Security this skillkingxiaozhe/cm-workflow1041 repos~744Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Codebase Knowledge Graph Q&AEgonex-AI/Understand-Anything86k1 repos~1.2kAutomated safety check: PassMIT
Code Design Rationale Investigatorcursor/plugins10k9 repos~2.6kAutomated safety check: PassNone
Understand Diff AnalysisEgonex-AI/Understand-Anything86k1 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Codebase Knowledge Graph Q&A

    Egonex-AI/Understand-Anything

    Answers questions about a codebase by searching a prebuilt knowledge graph of its files, functions, classes and dependencies, not by rereading every source file.

    86k GitHub starsUsed in 1 repo~1.2k tokens
    DevelopmentAuto-check passed
  • Official

    Digs into why code is shaped the way it is by checking git history, pull requests and connected tools in parallel, then reporting a cited read on the tradeoffs.

    10k GitHub starsUsed in 9 repos~2.6k tokens
    DevelopmentAuto-check passed
  • Understand Diff Analysis

    Egonex-AI/Understand-Anything

    Reads your git changes or a pull request against a prebuilt knowledge graph of the project to explain what changed, which components are affected and what is risky.

    86k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Understand Explain

    Egonex-AI/Understand-Anything

    Gives an in-depth explanation of one file, function or module by reading the project's knowledge graph and checking that the graph is still fresh.

    86k GitHub starsUsed in 1 repo~1.3k tokens
    DevelopmentAuto-check passed

More from kingxiaozhe/cm-workflow

All 23 skills in this repo
  • Cm Fix

    kingxiaozhe/cm-workflow

    用户说“修复这个可复现 bug”或要求根据失败报告修代码时使用。执行红灯测试、根因定位、最小修复、独立审查和回归;尚未确认的问题先用 cm-test,新功能和架构重设计转交 cm-prd。

    104 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Cm Idea

    kingxiaozhe/cm-workflow

    用户说“我有个点子”“帮我梳理产品”或需要先聊清目标时使用。通过逐题访谈整理为可交给 cm-prd 的 PRD;已有明确需求文档时改用 cm-prd,不写代码、不拆开发任务。

    104 GitHub starsUsed in 1 repo~419 tokens
    Auto-check passed
  • Cm Refactor

    kingxiaozhe/cm-workflow

    用户明确要求“只整理结构,不改变行为”时使用。执行边界分流、行为判官、分批重构和独立审查;缺陷修复转交 cm-fix,新增或变化的业务行为转交 cm-prd。

    104 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Cm AI

    kingxiaozhe/cm-workflow

    用户明确说“规格已确认,开始实现”或要求按已审批 CM specs 开发时使用。新任务默认由 JS workflow 驱动 N1-N8,完成开发、独立审查、QA 与文档同步;模糊点子、未审规格和单独一句“继续”不能触发编码批准。

    104 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Cm Check

    kingxiaozhe/cm-workflow

    用户说“检查工作流是否安装正确”“为什么找不到 cm 命令”时使用。默认查询 npm 稳定版,有新版自动升级已管理的 CM 安装,再检查插件、核心 Skills、兼容包装与模板引用;不测试或修改业务代码。

    104 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Cm Init

    kingxiaozhe/cm-workflow

    用户说“第一次接管这个项目”“分析仓库并生成项目规则”时使用。分析已有代码并生成 Codex AGENTS.md 与 CM/Claude 兼容规则;仅适用于非空存量项目,不创建脚手架、不承接普通代码修改。

    104 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Cm Security

What does Cm Security do?

用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。. Cm Security is an agent skill from kingxiaozhe/cm-workflow.

When should I use Cm Security?

Cm Security fits situations like: development work in your project.

How do I install Cm Security in Claude Code?

Run `npx skills add kingxiaozhe/cm-workflow --skill cm-security -a claude-code`. Or copy the skill folder (skills/cm-security in kingxiaozhe/cm-workflow) into .claude/skills/cm-security in your project. Claude Code loads it when a task matches its description.

How do I install Cm Security in Codex?

Run `npx skills add kingxiaozhe/cm-workflow --skill cm-security -a codex`. Or copy the skill folder (skills/cm-security in kingxiaozhe/cm-workflow) into .agents/skills/cm-security in your project. Codex loads it when a task matches its description.

Can I use Cm Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kingxiaozhe/cm-workflow --skill cm-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cm-security, .gemini/skills/cm-security, .github/skills/cm-security and .opencode/skills/cm-security in your project.

What does Cm Security need to run?

Going by SKILL.md and its folder, Cm Security needs the command-line tools its instructions call (node).

Does Cm Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cm Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cm Security use?

Cm Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cm Security use?

About 744 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Cm Security?

Skills that share tags, products or a category with Cm Security: Finishing a Development Branch (obra/superpowers, 296k stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Codebase Knowledge Graph Q&A (Egonex-AI/Understand-Anything, 86k stars) and Code Design Rationale Investigator (cursor/plugins, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cm Security?

kingxiaozhe (a GitHub user) maintains it in kingxiaozhe/cm-workflow, which has 104 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 8, 2026.

Source: kingxiaozhe/cm-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.