Agentic GitHub Actions Auditor
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告)
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC security-automation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-automation .claude/skills/security-automation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-automation" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/security-automation into .claude/skills/security-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-automation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/security-automationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC security-automation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-automation .agents/skills/security-automation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-automation" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/security-automation into .agents/skills/security-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-automation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC security-automation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-automation .cursor/skills/security-automation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-automation" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/security-automation into .cursor/skills/security-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-automation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/langbyyi/CyberStrikeAI-SRC.git --path skills/security-automation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC security-automation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-automation .gemini/skills/security-automation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-automation" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/security-automation into .gemini/skills/security-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-automation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install langbyyi/CyberStrikeAI-SRC security-automationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-automation .github/skills/security-automation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-automation" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/security-automation into .github/skills/security-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-automation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC security-automation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-automation .opencode/skills/security-automation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-automation" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/security-automation into .opencode/skills/security-automation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-automation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-automation安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告)
Security Automation is an agent skill from langbyyi/CyberStrikeAI-SRC. 安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告)
Its SKILL.md is about 6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Static analysis and SAST and CI/CD. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 166ee1c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
trivycurlgitleaksjqdockergitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Automation loads about 6k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 998 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from langbyyi/CyberStrikeAI-SRC at commit 166ee1c, republished under its Apache-2.0 licence (© langbyyi). 998 words, ~5,967 tokens.
.claude/skills/security-automation/SKILL.md (or your agent's skills folder).AI LOAD INSTRUCTION: DevSecOps 与安全自动化专家方法论。聚焦流水线卡点选型→扫描工具链→策略即代码→漏洞生命周期→SOAR/Agentic 编排→误报治理。自动化结论保留原始证据,门槛对齐 pentest-verification。
安全自动化是将安全能力嵌入 DevOps 与安全运营流程的核心实践。本技能系统化覆盖代码提交→构建→测试→部署→运行全生命周期安全自动化,同时站在资深攻防专家双视角:红队视角关注"自动化打点—攻击链验证—漏洞利用",蓝队视角关注"自动检测—降噪—编排响应"。v3.0.0 在 v2.0.0 基础上新增 SOAR 深度编排、Agentic AI 安全自动化、大模型安全运营(LLM 告警分析与降噪)、AI 辅助剧本生成、攻防双视角自动化、误报治理与质量保障、合规自动化(证据收集/报告) 等高级维度,并给出与 Eino 技能系统的联动方式。
Plan阶段: 威胁建模(STRIDE) → 安全需求 → 安全设计评审 → 攻击面分析
Code阶段: IDE安全插件 → Pre-commit Hook(密钥/格式) → 代码审计(SAST)
Build阶段: SAST → SCA → 依赖漏洞 → 许可证合规 → 构建产物签名
Test阶段: DAST → IAST → 渗透测试 → Fuzzing → API安全测试
Deploy阶段: 容器扫描 → IaC审计 → 配置合规 → 供应链校验(SBOM)
Run阶段: RASP → WAF → 运行时监控(Falco) → 漏洞管理 → 自动化应急响应stages:
- security-scan
sast:
stage: security-scan
image: semgrep/semgrep
script:
- semgrep --config=auto --json -o sast-results.json .
artifacts:
reports:
sast: sast-results.json
dependency-scan:
stage: security-scan
image: aquasec/trivy
script:
- trivy fs --format json -o deps-results.json .
container-scan:
stage: security-scan
image: aquasec/trivy
script:
- trivy image --format json -o container-results.json $CI_REGISTRY_IMAGE
secret-scan:
stage: security-scan
image: zricethezav/gitleaks
script:
- gitleaks detect --source . --report-format json --report-path secrets.json
iac-scan:
stage: security-scan
image: bridgecrew/checkov
script:
- checkov -d terraform/ -o json > iac-results.json# 门禁原则:扫描发现 X 级漏洞 → 阻断发布;Y 级漏洞 → 放行+缺陷登记+限时修复
# 示例:Semgrep 阻断严重级
if grep -q '"severity": "ERROR"' sast-results.json; then
echo "检测到严重级SAST漏洞,阻断流水线"
exit 1
fi
# 示例:Trivy 高危漏洞阈值阻断(支持 --exit-code --severity 直接内嵌)
trivy image --exit-code 1 --severity CRITICAL,HIGH --ignore-unfixed $IMAGEsecurity-config 仓库管理,扫描器只读配置,避免各团队自行放水| 指标 | 含义 | 建议目标 |
|---|---|---|
| 漏洞密度 | 每千行代码漏洞数 | 持续下降趋势 |
| MTTR | 平均修复时间(漏洞/告警) | 按 SLA 分级 |
| 修复率 | 周期内修复/新增 | ≥90% |
| 门禁拦截率 | 流水线被安全阻断比例 | 反映左移生效度 |
| 误报率 | 确认误报/总告警 | <30% 持续优化 |
| 覆盖率 | 扫描资产/全量资产 | ≥95% |
| 工具 | 语言 | 特点 |
|---|---|---|
| Semgrep | 多语言 | 规则灵活,自定义强,OSS 规则社区 |
| CodeQL | 多语言 | GitHub 集成,数据流/污点分析 |
| SonarQube | 多语言 | 代码质量+安全,质量门禁 |
| Bandit | Python | Python 专用 |
| Brakeman | Ruby | Rails 专用 |
| Gosec | Go | Go 专用 |
| ESLint Security / eslint-plugin-security | JS/TS | Node.js 安全 |
| Snyk Code / Fortify / Checkmarx | 商业 | 企业级,IDE/CI 全覆盖 |
实战要点:SAST 按团队细分规则集(新项目严/存量项目宽),结果按文件变更行(diff)过滤,只上报"本次改动引入"的问题,避免存量噪声淹没新问题。
| 工具 | 类型 | 特点 |
|---|---|---|
| OWASP ZAP | 开源 | CI/CD 集成,API 扫描,主动/被动模式 |
| Burp Suite CI | 商业 | 专业级,REST API 驱动 |
| Nuclei | 开源 | 模板驱动,YAML 模板生态丰富,扫描极快 |
| Nikto | 开源 | Web 服务器扫描 |
| Arachni | 开源 | 高覆盖 Web 扫描 |
| 工具 | 范围 | 特点 |
|---|---|---|
| Trivy | 全面 | 依赖/容器/IaC/密钥四合一 |
| Grype | 依赖/镜像 | 与 Syft SBOM 生成配套 |
| Snyk | 依赖 | 修复建议,PR 集成 |
| Dependabot / Renovate | 依赖 | 自动升级 PR |
| OWASP Dependency-Check | 依赖 | NVD 数据库 |
| OSV-Scanner | 依赖 | Google OSV 数据库 |
| 工具 | 目标 | 特点 |
|---|---|---|
| Trivy | 镜像/依赖 | 多用途扫描,支持 SBOM 生成 |
| Hadolint | Dockerfile | Dockerfile Lint |
| Checkov | Terraform/K8s/云 | IaC 安全策略 1000+ |
| tfsec | Terraform | Terraform 安全 |
| kube-hunter | K8s | K8s 渗透测试 |
| OPA/Gatekeeper | K8s | 策略即代码(准入控制) |
| Kyverno | K8s | K8s 原生策略,无需 Rego |
| kube-bench | K8s | CIS Benchmark |
# gitleaks pre-commit hook(提交即拦截)
#!/bin/sh
gitleaks protect --staged
if [ $? -ne 0 ]; then
echo "检测到密钥泄露,提交被拒绝"
exit 1
fi# CI 全量扫描(含 Git 历史)
secret-scan:
script:
- gitleaks detect --source . --log-opts="--all"
# 扫描所有 Git 历史,阻断合并请求补充:定期(每周)对 Git 历史做深度回扫,防止已合入的密钥遗漏;检测到历史泄露时优先轮换密钥而非仅删提交。
# 生成 SBOM(CycloneDX 格式)
syft dir:. -o cyclonedx-json > sbom.json
# 或 trivy
trivy fs --format cyclonedx -o sbom.json .
# 校验 SBOM 与镜像签名
cosign verify $IMAGE --certificate-identity $IDENTITY --certificate-oidc-issuer $ISSUER
# 依赖投毒防护:锁定版本 + hash 校验(npm/pip 等)
# package-lock.json / poetry.lock 强制提交,CI 校验 lock 文件未篡改供应链自动化还包括:镜像来源白名单、依赖策略(禁用已 EOL 版本)、内网镜像代理(阻断对上游的不可控拉取)。
# K8s Pod 安全策略
package kubernetes.admission
deny[msg] {
input.request.kind.kind == "Pod"
container := input.request.object.spec.containers[_]
container.securityContext.privileged == true
msg := sprintf("容器 %v 不允许使用特权模式", [container.name])
}
deny[msg] {
input.request.kind.kind == "Pod"
container := input.request.object.spec.containers[_]
not container.securityContext.runAsNonRoot
msg := sprintf("容器 %v 必须以非root运行", [container.name])
}# Docker CIS Benchmark
docker-bench-security
# K8s CIS Benchmark
kube-bench
# AWS CIS Benchmark
prowler --checks cis
# 云安全态势(GCP/Azure)
# scoutsuite / pacu 组合| 引擎 | 语言 | 适用 |
|---|---|---|
| OPA/Gatekeeper | Rego | 云原生准入 + 通用策略 |
| Kyverno | YAML | K8s 原生,学习成本低 |
| Conftest | Rego | 通用配置测试(Dockerfile/Terraform/K8s 均可) |
| HashiCorp Sentinel | Sentinel | Terraform Enterprise 集成 |
# Conftest 测试任意配置
conftest test deployment.yaml -p policies/security-policies 仓库,走 MR 评审 + 单测(OPA 单元测试 opa test)1. 扫描发现 → 自动录入漏洞管理平台
2. 归一化 → 多扫描器结果统一格式(去重/去噪/合并同类)
3. 风险评估 → CVSS评分 × 资产权重 × 可利用性 = 优先级
4. 分配修复 → 按代码归属/资产负责人自动指派
5. 修复验证 → 自动复扫确认修复,闭环关闭
6. SLA跟踪 → 超时自动告警+升级
7. 定期报告 → 自动生成安全态势报告(周/月)# 导入 Trivy 扫描结果
curl -X POST http://defectdojo/api/v2/import-scan/ \
-H "Authorization: Token $TOKEN" \
-F "scan_type=Trivy Scan" \
-F "file=@trivy-results.json"
# 导入 Semgrep 结果
curl -X POST http://defectdojo/api/v2/import-scan/ \
-H "Authorization: Token $TOKEN" \
-F "scan_type=Semgrep JSON Report" \
-F "file=@sast-results.json"# 示例:基于日期的 SLA 升级脚本(伪代码)
for vuln in open_vulnerabilities:
if vuln.severity == "critical" and vuln.age_days > 7:
escalate(vuln, to="安全负责人", notify="IM/邮件")
elif vuln.severity == "high" and vuln.age_days > 14:
escalate(vuln, to="部门负责人")CI流水线/调度器
├─ Semgrep(SAST) ──┐
├─ Trivy(SCA/镜像) ─┤→ 结果归一化 → DefectDojo/ThreadFix → 指派修复 → 复扫验证
├─ Nuclei(DAST) ───┤
└─ Checkov(IaC) ───┘ ↑
回归/去重/加噪# 单资产扫描
nuclei -u https://target.com -severity high,critical -jsonl -o nuclei.jsonl
# 资产列表批量扫描(并发控制,遵守授权)
nuclei -l targets.txt -c 20 -stats -jsonl -o nuclei.jsonl
# 指定模板分类
nuclei -u https://target.com -t cves/ -t exposures/ -t misconfiguration/
# 与漏洞平台联动:nuclei -jsonl 输出 → jq 提取 → 导入 DefectDojo
jq -c '{scan_type:"Nuclei Scan", ...}' nuclei.jsonl# 将 nuclei JSONL → DefectDojo 期望字段(示意)
import json, sys
out = []
for line in sys.stdin:
d = json.loads(line)
out.append({
"title": d.get("info", {}).get("name", d.get("template-id")),
"severity": d.get("info", {}).get("severity", "info"),
"cwe": (d.get("info", {}).get("classification") or {}).get("cwe-id", []),
"description": d.get("info", {}).get("description", ""),
"matched_at": d.get("matched-at"),
"tags": d.get("info", {}).get("tags", []),
})
print(json.dumps(out, ensure_ascii=False, indent=2))# ZAP 全量扫描并出报告
docker run -t ghcr.io/zaproxy/zaproxy zap-baseline.py \
-t https://target.com -r zap-report.html -J zap-report.json
# 结合 -x 导出 XML 供 DefectDojo "ZAP Scan" 类型导入资产收集(子域/端口/指纹)
→ 攻击面分析(ASM: 公网暴露/影子资产)
→ 自动化漏洞探测(nuclei/自动化工具)
→ 漏洞验证(exploit-validated: 起 PoC 确认可利用性)
→ 打点成功 → 建立据点 → 横向扩展# 打点自动化示例(仅授权环境)
# 1) 子域枚举
subfinder -d target.com -all -silent | sort -u > subs.txt
# 2) 存活探测
httpx -l subs.txt -silent -title -status-code -tech-detect -o alive.txt
# 3) 指纹/资产测绘(httpx 探测技术栈,nuclei -tech-detect 亦可)
httpx -l alive.txt -tech-detect -silent | tee -a tech.txt
# 4) 定向漏洞验证
nuclei -l alive.txt -t cves/ -t exposures/ -severity critical,high
# 5) 结果入库 + 人工/LLM 研判 → 确认可利用目标检测(SIEM/EDR/NDR 规则+行为分析)
→ 告警聚合/降噪(去重/关联/LLM triage)
→ 自动化调查(资产上下文/威胁情报/TTP映射)
→ 自动化响应(隔离/封禁/撤销会话 —— 高危动作 HITL)
→ 复盘与检测工程(规则调优/新规则生成)# 示例:EDR/SIEM 告警 → 自动化处置脚本(示意)
# 1) 提取 IOC
# 2) 威胁情报查询(VirusTotal/AbuseIPDB/MISP)
# 3) 命中规则 → 隔离主机 / 封禁 IP / 撤销 Token
# 4) 全自动动作需白名单+审批闸门# Atomic Red Team(红蓝共用检测验证)
git clone https://github.com/redcanaryco/atomic-red-team
# 执行单一 ATT&CK 技术(模拟 T1059.001 PowerShell)
powershell -ExecutionPolicy Bypass -File ./atomics/T1059.001/T1059.001.yaml # 或对应执行脚本
# MITRE CALDERA(自主对抗模拟平台)
# 部署 server + agent,按操作计划自动化演练
# 商业替代:SafeBreach / AttackIQ / Picus —— 持续验证检测覆盖率红队自动化发现 → 证据包(复现步骤+PoC) → 漏洞平台登记
↓
蓝队检测规则(以红队 TTP 为样本生成) → 攻击模拟验证 → 上线
↓
复测闭环:下轮红队验证新规则是否拦截 → 覆盖率持续提升编排层(Orchestration): API 连接 SIEM/EDR/身份/邮件/防火墙/威胁情报
自动化层(Automation): 剧本执行引擎(全自动/半自动/手动)
响应层(Response): 案件管理、告警队列、处置动作、审计留痕2025-2026 演进:SOAR 不再是独立孤岛,已内嵌进 SIEM/XDR(如 Splunk SOAR 与 ES 8.0 统一负载、Microsoft Sentinel 集成、Palo Alto Cortex AgentiX);新增自然语言剧本创建与提示驱动自动化(Prompt-driven automation:直接向外部团队/工单系统推送处置请求)。
剧本要素:触发器(SIEM 告警/定时/Webhook)→ 条件分支 → 动作(查询/封禁/通知)→ 人工审批节点 → 超时与失败处理。
# 暴力破解调查剧本(示意,YAML 化描述)
name: brute-force-investigation
trigger: SIEM 告警 "Multiple Failed Logins"
steps:
- action: 查询来源IP威胁情报(AbuseIPDB/MISP)
- action: 查询账号最近登录记录
- action: 查询资产关键性(CMDB)
- if: IP信誉=恶意 AND 账号=特权
then: [隔离主机(HITL审批), 封禁IP, 禁用账号, 通知安全负责人]
- else: [打标"预期行为", 关闭案件]
- action: 生成案件报告与证据快照静态剧本的局限:对未知攻击形态无法响应。2026 趋势是运行时生成剧本:LLM 基于实时证据动态决策下一步(查什么、问什么、封什么),但必须在规则边界+动作白名单+审批闸门内执行,详见第八章。
| 类型 | 谁决定下一步 | 代表 |
|---|---|---|
| SOAR 自动化 | 人类预先编写剧本 | Splunk SOAR、XSOAR |
| Copilot 副驾 | 人类运行时决策,AI 辅助 | Microsoft Security Copilot |
| Agentic | 系统基于实时证据自主推理决策,在受控边界内行动 | D3 Morpheus、Cortex AgentiX、Torq HyperAgents |
用户指令(自然语言) → Agent规划(拆解任务) → 工具调用(nuclei/子域/指纹/查漏洞库)
→ 结果分析 → 下一步决策(扩大范围/验证/跳过) → 输出结构化报告# Agent 工具调用示意(LangChain/CrewAI 风格)
from langchain.tools import tool
@tool
def run_nuclei(target: str, severity: str = "high") -> str:
"""对目标执行 nuclei 扫描,返回 JSONL 结果"""
# 实际实现:subprocess 调用 nuclei,解析输出
...
@tool
def lookup_cve(cve_id: str) -> str:
"""查询 CVE 详情与 PoC 信息"""
...
# Agent 循环:plan → act → observe → re-plan告警进入 → Agent调查(查日志/查资产/查威胁情报) → 形成结论(严重度+置信度)
→ 分级响应:
低危/确定误报 → 自动关闭(附理由)
中危 → 转人工队列(附调查摘要)
高危 → 隔离/封禁(需HITL审批) + 生成报告成熟实践(2026 实证):Databricks 用 17 个源特定 Triage Agent(每个 Agent 只负责单一检测源)+ 共享威胁情报 Agent,低危告警全量自动 Triage,升级率 ~3.2%,30 天节省 6500+ 分析师小时。单一通用 Agent 处理全量告警会退化为另一种噪声(升级率 50%),源特定 Agent 才是有效形态。
| 等级 | 行为 | 适用 |
|---|---|---|
| AL1 建议 | Agent 仅给建议,人执行 | 初期/高风险动作 |
| AL2 审批 | Agent 执行到关键动作停下等人审批 | 半自动(HITL) |
| AL3 授权内自动 | 白名单动作内自动执行 | 低危、高频、确定动作 |
| AL4 自主 | 全流程自主 | 受限环境(靶场/隔离网段) |
红线:封禁生产、隔离核心资产、禁用特权账号、外发数据等动作默认 AL2,白名单之外的 AL3/AL4 必须经安全委员会审批。
Layer1 规则过滤: 确定性规则滤掉 90-95% 明确良性事件(健康检查/CI账号/计划任务)
Layer2 LLM Triage: 富化后的告警 → LLM 结构化判定(benign/suspicious/malicious + 置信度 + 理由)
Layer3 分级响应: 高危自动遏制 / 中危转人工 / 低危记录趋势# LLM Triage 结构化输出(示意)
from pydantic import BaseModel
from enum import Enum
class Disposition(str, Enum):
ESCALATE = "escalate"; MONITOR = "monitor"; CLOSE = "close"
class TriageResult(BaseModel):
severity: str # critical/high/medium/low/info
disposition: Disposition
confidence: float # 0-1,低于阈值不自动动作
reasoning: str # 一段结论性理由
recommended_actions: list[str]
false_positive_indicators: list[str] # 支撑"关闭"判定的证据富化是命脉:用户角色、资产关键性、IP 信誉、24h 关联告警、是否业务时间——"垃圾进垃圾出",LLM 需要上下文才能避免把 Tor 出口节点当普通外部 IP。
误报率=确认误报/总告警,规则或 Agent 调优后回测"帮我写一个:检测到异常登录后,查询威胁情报,若是恶意 IP 则禁用账号并通知" → LLM 生成结构化剧本 → 人工评审 → 沙箱回放(用历史告警回测)→ 灰度上线战略大脑(通用大模型): 威胁研判、攻击链推理、复杂决策
战术专家(安全微调模型): 日志语义解析、ATT&CK 技术识别、实时告警分类(毫秒级)| 来源 | 典型原因 | 治理手段 |
|---|---|---|
| 扫描器规则过宽 | 正则/模板命中正常功能 | 规则瘦身、降级 severity |
| 检测规则阈值不当 | 阈值过低触发风暴 | 基线化调参 |
| 环境上下文缺失 | 测试环境/灰度流量被当攻击 | 资产标记+流量标签 |
| 静态规则无法推理 | 规则看不到业务上下文 | 引入 LLM 富化判定 |
| 重复扫描 | 相同漏洞多轮上报 | 指纹去重+区间合并 |
# 指标
精确率(Precision)=真阳性/(真阳性+假阳性) 目标 >80%
召回率(Recall)=真阳性/(真阳性+假阴性) 目标 >90%(宁可误报不漏报的类别)
F1 = 2*P*R/(P+R)
误报率、升级率、MTTR、告警周转率起草 → 离线回放(历史数据) → 灰度(仅告警) → 强制 → 定期复盘(误报率/召回率) → 退役# 自动化证据包:扫描结果+配置快照+修复验证
# 1) 扫描结果(前文 DefectDojo 导入即可留存)
# 2) 配置基线快照
checkov -d . -o json > iac-baseline.json
# 3) 镜像签名与 SBOM 归档(审计可追溯)
cosign verify $IMAGE ... ; syft $IMAGE -o spdx-json > artifact.sbom
# 4) 合规状态导出(CIS/等保/NIST 控制项映射)
prowler -M csv -o prowler-report/ --checks cis证据链三要素:时间戳(不可篡改)、来源(哪个工具/哪个版本)、原始数据(原始输出存档,报告仅引用)。
| 框架 | 自动化支撑 |
|---|---|
| CIS Controls / CIS Benchmark | 扫描器 + 策略引擎(kube-bench/docker-bench/prowler) |
| NIST CSF / 800-53 | 控制项 → 证据 → 状态自动化映射 |
| ISO 27001 / SOC 2 | 证据收集 + 持续监控报告 |
| PCI DSS | 扫描报告 + 渗透测试证据 + 变更审计链 |
| 等保 2.0 | 自查项自动化核对 + 测评证据导出 |
本工作区采用 Eino(Agent Skills 兼容)技能包规范:SKILL.md 为清单+主说明,同目录可挂 scripts/、references/、assets/ 子目录;由 Eino 的 ListPackageFiles / resource_path 与多代理内 ADK skill 工具按包加载,FilesystemSkillsRetriever 支持包摘要与 ## 分块检索;平台同时提供 HTTP GET /api/skills/...、section=、resource_path= 访问机制。
security-automation 技能包主文档:多代理会话内用 skill 工具加载本包,即可获得 CI/CD 管道、扫描编排、SOAR、Agentic 自动化的可执行命令与模板scripts/:管道扫描脚本(如 5.3 归一化脚本)、门禁检查脚本references/:SBOM/CIS/合规证据收集清单、剧本模板assets/:报告模板、规则示例section=扫描工具链 等分块,节省 token;需要脚本原文用 resource_path=scripts/xxx.py协调代理(任务拆解/上下文传递)
├─ 扫描代理 → 加载 security-automation: nuclei/SAST/SCA 命令
├─ 利用代理 → 加载 fastjson-exploitation / log4shell 等利用技能(授权内)
├─ 响应代理 → 加载 incident-response: 处置动作/证据留痕
└─ 报告代理 → 加载本技能第十一章: 证据收集/报告生成技能间的上下文衔接:扫描代理输出(资产/漏洞清单 JSON)作为下游代理的输入,统一 schema 便于多代理传递。
skill 工具加载本技能后,即可调用其中被封装的扫描/门禁/报告命令,实现"Agent 用技能干活"version)支持 Agent 选择稳定版本,避免行为漂移# CI/CD 集成
GitLab CI / GitHub Actions / Jenkins # CI平台
Tekton / Argo CD # K8s原生CI/CD
Buildkite / CircleCI # 云原生CI
# 扫描编排
DefectDojo # 开源漏洞管理平台
ThreadFix # 漏洞聚合与修复管理
Faraday # 渗透测试管理
ArcherySec / VulnIQ # 漏洞管理替代
# 策略引擎
OPA/Gatekeeper # K8s策略
Kyverno # K8s原生策略
Conftest # 通用策略测试
Hashicorp Sentinel # Terraform Enterprise
# 供应链与容器
Syft / CycloneDX # SBOM生成
cosign / Sigstore # 镜像签名与验证
Trivy / Grype # 容器与依赖扫描
SLSA / in-toto # 供应链完整性
# 安全监控
Falco # K8s运行时安全
Wazuh # 主机安全/开源SIEM
Elastic Security # SIEM/XDR
Microsoft Sentinel # 云原生SIEM/SOAR
# SOAR
Splunk SOAR / Palo Alto XSOAR(→Cortex AgentiX) / Microsoft Sentinel SOAR
Shuffle / Tines # 轻量开源/低代码SOAR
TheHive / DFIR-IRIS # 开源案件管理
# 红队自动化
Subfinder/httpx/nuclei # 打点三件套
Metasploit / Cobalt Strike / Sliver # 利用与C2
BloodHound / PlumHound # AD域分析
CALDERA / Atomic Red Team # 攻击模拟
Nuclei / Xray / Yakit # 漏洞扫描与验证
# AI安全运营
LangChain / CrewAI / AutoGen # Agent编排框架
Cisco Foundation-sec / 安全微调模型 # 安全LLM
Microsoft Security Copilot / CrowdStrike Charlotte AI # 商业化副驾/Agent
Dropzone AI / Radiant Security # AI分析师
MISP / OpenCTI # 威胁情报(RAG知识源)自动化目标?
├── 建流水线 → 第一章 DevSecOps 阶段定位(SAST/DAST/SCA/IaC 卡点选择)
├── 扫描能力落地 → 第二章工具链按资产类型路由(源码/镜像/API/Infrastructure)
├── 策略与合规 → 第三章 OPA 策略即代码
├── 漏洞全生命周期 → 第四章(发现→去重→派单→复测→指标)
├── 告警编排与响应 → 第七章 SOAR 剧本
├── Agentic 编排 → 第八章 LLM Agent 驱动扫描/响应 → 第十二章与 Eino skill 系统联动
├── 误报率高 → 第十章误报治理门槛 → 对齐 pentest-verification
└── 报告生成 → 第十一章证据自动收集 → 格式对齐 pentest-output-standardsUse visible execute-python-script for 脚本化扫描编排与结果聚合、nuclei 仅以相关性模板运行。不假设 SOAR/SIEM/漏洞管理平台 API 可达;编排产出的每条结论保留原始证据引用。
© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/security-automation of langbyyi/CyberStrikeAI-SRC.
Open the folder on GitHubat commit 166ee1c
Security Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Automation this skilllangbyyi/CyberStrikeAI-SRC | 134 | — | ~6k | Automated safety check: Pass | Apache-2.0 | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Openclaw CI Limitsopenclaw/openclaw | 392k | — | ~13k | Automated safety check: Pass | MIT | |
| Hadolint Dockerfile Security LintingAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.4k | Automated safety check: Pass | Custom licence | |
| Building Devsecops Pipeline With GitLab CImukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Managing Vulnerabilitiesancoleman/ai-design-components | 526 | — | ~3.8k | Automated safety check: Pass | MIT |
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
openclaw/openclaw
Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…
AgentSecOps/SecOpsAgentKit
Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.
mukul975/Anthropic-Cybersecurity-Skills
Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…
ancoleman/ai-design-components
Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.
revfactory/harness-100
CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
langbyyi/CyberStrikeAI-SRC
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
langbyyi/CyberStrikeAI-SRC
Source control and artifact exposure (.git, .svn, .hg, backups, .env).
langbyyi/CyberStrikeAI-SRC
PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
Categories
安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告). Security Automation is an agent skill from langbyyi/CyberStrikeAI-SRC.
Security Automation fits situations like: tasks that involve Static analysis and SAST; tasks that involve CI/CD.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a claude-code`. Or copy the skill folder (skills/security-automation in langbyyi/CyberStrikeAI-SRC) into .claude/skills/security-automation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a codex`. Or copy the skill folder (skills/security-automation in langbyyi/CyberStrikeAI-SRC) into .agents/skills/security-automation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill security-automation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-automation, .gemini/skills/security-automation, .github/skills/security-automation and .opencode/skills/security-automation in your project.
Going by SKILL.md and its folder, Security Automation needs the command-line tools its instructions call (trivy, curl, gitleaks, jq, docker and git). Our summary lists: Python 3; Node.js; Docker.
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Automation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Automation: Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars), Openclaw CI Limits (openclaw/openclaw, 392k stars), Hadolint Dockerfile Security Linting (AgentSecOps/SecOpsAgentKit, 220 stars) and Building Devsecops Pipeline With GitLab CI (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 134 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 7, 2026.
Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.