Secknowledge Skill
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
基于 OWASP Top 10 (2021) 标准提供代码安全审查,逐项检查 SQL 注入、XSS、SSRF、访问控制、加密失败等常见漏洞,并给出具体的漏洞代码示例与修复方案。当用户需要代码安全审查、安全加固、渗透测试辅助,或提及 OWASP、安全检查、SQL 注入、XSS、代码审计、安全清单等关键词时触发此技能。
$ npx skills add rongxinzy/RongxinAI --skill web-security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rongxinzy/RongxinAI web-security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/SKILLs/web-security-audit .claude/skills/web-security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "web-security-audit" agent skill from https://github.com/rongxinzy/RongxinAI/tree/main/SKILLs/web-security-audit into .claude/skills/web-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rongxinzy/RongxinAI/tree/main/SKILLs/web-security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rongxinzy/RongxinAI --skill web-security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rongxinzy/RongxinAI web-security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .agents/skills && cp -r skills-src/SKILLs/web-security-audit .agents/skills/web-security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "web-security-audit" agent skill from https://github.com/rongxinzy/RongxinAI/tree/main/SKILLs/web-security-audit into .agents/skills/web-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rongxinzy/RongxinAI --skill web-security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rongxinzy/RongxinAI web-security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/SKILLs/web-security-audit .cursor/skills/web-security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "web-security-audit" agent skill from https://github.com/rongxinzy/RongxinAI/tree/main/SKILLs/web-security-audit into .cursor/skills/web-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rongxinzy/RongxinAI.git --path SKILLs/web-security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rongxinzy/RongxinAI --skill web-security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rongxinzy/RongxinAI web-security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/SKILLs/web-security-audit .gemini/skills/web-security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "web-security-audit" agent skill from https://github.com/rongxinzy/RongxinAI/tree/main/SKILLs/web-security-audit into .gemini/skills/web-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rongxinzy/RongxinAI web-security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rongxinzy/RongxinAI --skill web-security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .github/skills && cp -r skills-src/SKILLs/web-security-audit .github/skills/web-security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "web-security-audit" agent skill from https://github.com/rongxinzy/RongxinAI/tree/main/SKILLs/web-security-audit into .github/skills/web-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rongxinzy/RongxinAI --skill web-security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rongxinzy/RongxinAI web-security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rongxinzy/RongxinAI.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/SKILLs/web-security-audit .opencode/skills/web-security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "web-security-audit" agent skill from https://github.com/rongxinzy/RongxinAI/tree/main/SKILLs/web-security-audit into .opencode/skills/web-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "web-security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
web-security-audit基于 OWASP Top 10 (2021) 标准提供代码安全审查,逐项检查 SQL 注入、XSS、SSRF、访问控制、加密失败等常见漏洞,并给出具体的漏洞代码示例与修复方案。当用户需要代码安全审查、安全加固、渗透测试辅助,或提及 OWASP、安全检查、SQL 注入、XSS、代码审计、安全清单等关键词时触发此技能。
Web Security Audit is an agent skill from rongxinzy/RongxinAI. 基于 OWASP Top 10 (2021) 标准提供代码安全审查,逐项检查 SQL 注入、XSS、SSRF、访问控制、加密失败等常见漏洞,并给出具体的漏洞代码示例与修复方案。当用户需要代码安全审查、安全加固、渗透测试辅助,或提及 OWASP、安全检查、SQL 注入、XSS、代码审计、安全清单等关键词时触发此技能。
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `zhiyuan/metadata.yaml`).
It sits in Security, covering Web application vulnerabilities. It works with SQL. The repository describes itself as: An all-in-one local AI Agent workspace with a fully self-developed stack. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 9c64865. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYJWT_SECRETFLASK_SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Web Security Audit loads about 3k tokens when it runs. Until then it costs about 44 tokens; SKILL.md has 388 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rongxinzy/RongxinAI at commit 9c64865, republished under its MIT licence (© rongxinzy). 388 words, ~3,034 tokens.
.claude/skills/web-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.基于 OWASP Top 10 (2021) 标准,对代码进行逐项安全审查。每一项包含:漏洞说明、典型漏洞代码、检查要点、修复示例。适用于 Web 应用的安全 Code Review 场景。
将待审查的代码文件或代码片段提供给 Claude,指定需要检查的 OWASP 项目(或全部检查),即可获得逐项审查报告。
示例提问:
| 编号 | 类别 | 一句话检查重点 |
|---|---|---|
| A01 | 失效的访问控制 | 每个端点是否校验当前用户身份?能否通过改 ID 越权? |
| A02 | 加密失败 | 密码是否用 bcrypt/argon2?密钥是否硬编码? |
| A03 | 注入 | SQL 拼接?shell=True?模板未转义? |
| A04 | 不安全的设计 | 有无频率限制?关键操作能否被跳步? |
| A05 | 安全配置错误 | DEBUG 开着?错误页泄露堆栈?默认密码? |
| A06 | 过时的组件 | pip audit / npm audit 有 CVE 吗? |
| A07 | 认证失败 | JWT 验签名了吗?Token 能失效吗?有 MFA 吗? |
| A08 | 完整性失败 | 有 pickle.loads 反序列化不可信数据吗? |
| A09 | 日志监控失败 | 日志里有明文密码吗?登录失败有记录吗? |
| A10 | SSRF | 用户可控 URL 的请求过滤了内网 IP 吗? |
关键原则:宁可多报 false positive,不可漏报 true positive。
文件:行号风险说明: 用户能够越权访问其他用户的数据或执行未授权的操作。
检查要点:
# ❌ 漏洞:无权限校验,任何用户可通过修改 user_id 查看他人订单
@app.route("/api/orders/<user_id>")
def get_orders(user_id):
orders = db.query(f"SELECT * FROM orders WHERE user_id = {user_id}")
return jsonify(orders)# ✅ 修复:验证当前登录用户只能访问自己的数据
@app.route("/api/orders")
@login_required
def get_orders():
current_user_id = get_current_user().id
orders = db.query("SELECT * FROM orders WHERE user_id = %s", (current_user_id,))
return jsonify(orders)风险说明: 敏感数据(密码、信用卡号、个人信息)未加密或使用弱加密算法。
检查要点:
# ❌ 漏洞:使用 MD5 存储密码,且密钥硬编码
import hashlib
SECRET_KEY = "my-secret-key-123"
def save_password(password):
hashed = hashlib.md5(password.encode()).hexdigest()
db.save(hashed)# ✅ 修复:使用 bcrypt 进行密码哈希,密钥从环境变量读取
import bcrypt
import os
SECRET_KEY = os.environ["SECRET_KEY"]
def save_password(password):
salt = bcrypt.gensalt()
hashed = bcrypt.hashpw(password.encode(), salt)
db.save(hashed)风险说明: 用户输入未经过滤直接拼接到 SQL、命令、LDAP 等查询中,导致攻击者可执行任意查询或命令。
检查要点:
os.system()、subprocess.call(shell=True) 等直接拼接用户输入的命令执行# ❌ 漏洞:字符串拼接 SQL,攻击者可输入 ' OR 1=1 --
@app.route("/api/user")
def get_user():
username = request.args.get("username")
query = f"SELECT * FROM users WHERE username = '{username}'"
result = db.execute(query)
return jsonify(result)# ✅ 修复:使用参数化查询
@app.route("/api/user")
def get_user():
username = request.args.get("username")
result = db.execute(
"SELECT * FROM users WHERE username = %s",
(username,)
)
return jsonify(result)# ❌ 漏洞:用户输入直接拼接到 shell 命令
import os
def ping_host(host):
os.system(f"ping -c 4 {host}")# ✅ 修复:使用 subprocess 列表参数,禁用 shell
import subprocess
import re
def ping_host(host):
if not re.match(r'^[a-zA-Z0-9.\-]+$', host):
raise ValueError("Invalid hostname")
subprocess.run(["ping", "-c", "4", host], check=True)风险说明: 业务逻辑层面的设计缺陷,无法通过完美的实现来修复。
检查要点:
# ❌ 漏洞:验证码无尝试次数限制,可暴力破解
@app.route("/api/verify-code", methods=["POST"])
def verify_code():
code = request.json["code"]
stored_code = session.get("verification_code")
if code == stored_code:
return jsonify({"status": "verified"})
return jsonify({"status": "invalid"}), 400# ✅ 修复:添加尝试次数限制和过期时间
@app.route("/api/verify-code", methods=["POST"])
def verify_code():
attempts = session.get("verify_attempts", 0)
if attempts >= 5:
return jsonify({"error": "尝试次数过多,请重新获取验证码"}), 429
code = request.json["code"]
stored = session.get("verification_code")
expire_at = session.get("code_expire_at", 0)
if time.time() > expire_at:
return jsonify({"error": "验证码已过期"}), 400
session["verify_attempts"] = attempts + 1
if code == stored:
session.pop("verify_attempts", None)
return jsonify({"status": "verified"})
return jsonify({"status": "invalid"}), 400风险说明: 应用或服务器使用默认配置、开启了不必要的功能、错误消息暴露敏感信息。
检查要点:
# ❌ 漏洞:生产环境开启 DEBUG,泄露敏感信息
app = Flask(__name__)
app.config["DEBUG"] = True
app.config["SECRET_KEY"] = "default-secret"
@app.errorhandler(500)
def error_handler(e):
return jsonify({"error": str(e), "traceback": traceback.format_exc()}), 500# ✅ 修复:从环境变量读取配置,生产环境关闭 DEBUG
import os
app = Flask(__name__)
app.config["DEBUG"] = os.environ.get("FLASK_DEBUG", "false").lower() == "true"
app.config["SECRET_KEY"] = os.environ["FLASK_SECRET_KEY"]
@app.errorhandler(500)
def error_handler(e):
app.logger.error(f"Internal error: {e}")
return jsonify({"error": "服务器内部错误,请稍后重试"}), 500风险说明: 使用了存在已知漏洞的第三方库或框架版本。
检查要点:
pip audit、npm audit、snyk 等扫描)# Python 项目
pip audit
# Node.js 项目
npm audit
# 通用扫描
# 使用开源工具 trivy 或 grype 扫描容器/项目依赖# 更新有漏洞的包
pip install --upgrade package_name
# 自动修复 npm 漏洞
npm audit fix
# 锁定依赖版本,避免隐式升级引入风险
pip freeze > requirements.txt风险说明: 认证机制存在缺陷,允许暴力破解、凭据填充、会话劫持等攻击。
检查要点:
# ❌ 漏洞:JWT 未验证签名,接受 alg=none
import jwt
def verify_token(token):
payload = jwt.decode(token, options={"verify_signature": False})
return payload# ✅ 修复:强制验证签名和过期时间,指定算法
import jwt
import os
JWT_SECRET = os.environ["JWT_SECRET"]
def verify_token(token):
try:
payload = jwt.decode(
token,
JWT_SECRET,
algorithms=["HS256"],
options={"require": ["exp", "iat", "sub"]}
)
return payload
except jwt.ExpiredSignatureError:
raise AuthError("Token 已过期")
except jwt.InvalidTokenError:
raise AuthError("无效的 Token")风险说明: 未验证软件更新、关键数据、CI/CD 流水线的完整性,导致供应链攻击或数据篡改。
检查要点:
pickle.loads 处理不可信数据)# ❌ 漏洞:反序列化不可信数据,可导致远程代码执行
import pickle
@app.route("/api/import", methods=["POST"])
def import_data():
data = pickle.loads(request.data)
process(data)
return "OK"# ✅ 修复:使用安全的数据格式(JSON),拒绝反序列化任意对象
import json
@app.route("/api/import", methods=["POST"])
def import_data():
try:
data = json.loads(request.data)
except json.JSONDecodeError:
return jsonify({"error": "无效的 JSON 格式"}), 400
process(data)
return "OK"风险说明: 缺乏安全事件的日志记录和监控,导致攻击无法被及时发现和响应。
检查要点:
# ❌ 漏洞:登录失败无日志,且日志中记录了明文密码
def login(username, password):
user = db.get_user(username)
if not user or not check_password(password, user.password_hash):
print(f"Login failed for {username} with password {password}")
return None
return create_session(user)# ✅ 修复:记录安全事件但不记录敏感数据
import logging
security_logger = logging.getLogger("security")
def login(username, password):
user = db.get_user(username)
if not user or not check_password(password, user.password_hash):
security_logger.warning(
"登录失败",
extra={"username": username, "ip": request.remote_addr}
)
return None
security_logger.info(
"登录成功",
extra={"username": username, "ip": request.remote_addr}
)
return create_session(user)风险说明: 应用接受用户提供的 URL 并在服务端发起请求,攻击者可利用此访问内网资源或云元数据。
检查要点:
# ❌ 漏洞:直接请求用户提供的 URL,可访问内网和云元数据
import requests
@app.route("/api/fetch-url")
def fetch_url():
url = request.args.get("url")
response = requests.get(url)
return response.text# ✅ 修复:校验 URL 协议和目标地址,阻止内网访问
import requests
import ipaddress
from urllib.parse import urlparse
import socket
BLOCKED_NETWORKS = [
ipaddress.ip_network("127.0.0.0/8"),
ipaddress.ip_network("10.0.0.0/8"),
ipaddress.ip_network("172.16.0.0/12"),
ipaddress.ip_network("192.168.0.0/16"),
ipaddress.ip_network("169.254.0.0/16"),
]
def is_safe_url(url):
parsed = urlparse(url)
if parsed.scheme not in ("http", "https"):
return False
try:
ip = ipaddress.ip_address(socket.gethostbyname(parsed.hostname))
for network in BLOCKED_NETWORKS:
if ip in network:
return False
except (socket.gaierror, ValueError):
return False
return True
@app.route("/api/fetch-url")
def fetch_url():
url = request.args.get("url")
if not is_safe_url(url):
return jsonify({"error": "不允许访问该地址"}), 403
response = requests.get(url, timeout=10, allow_redirects=False)
return response.text完成检查后,输出如下格式的报告。所有 10 项都必须出现,无发现的标 ✅:
# OWASP Top 10 安全审查报告
## 审查概览
- 审查范围:[文件/模块列表]
- 审查时间:[日期]
- 风险统计:🔴 高危 X 个 | 🟡 中危 X 个 | 🟢 低危 X 个 | ✅ 无发现 X 项
## 发现详情(按风险等级降序)
### [风险等级] [OWASP 编号] — [问题标题]
- **位置:** [文件:行号]
- **描述:** [问题描述]
- **影响:** [可能造成的危害]
- **修复代码:**(直接可用的代码,非描述)
### ✅ A0X — [类别名] — 未发现问题
## 修复优先级
1. [最紧急修复项 — 理由]
2. [次优先项 — 理由]
3. ...| 工具 | 语言 | 用途 |
|---|---|---|
bandit | Python | Python 代码安全扫描 |
semgrep | 多语言 | 基于规则的代码扫描 |
eslint-plugin-security | JavaScript | JS 安全规则 |
npm audit / pip audit | JS / Python | 依赖漏洞扫描 |
trivy | 多语言 | 容器和依赖扫描 |
sqlmap | — | SQL 注入检测 |
OWASP ZAP | — | Web 应用动态扫描 |
注意: 本清单为辅助审查工具,不能替代专业渗透测试。对于高安全要求的系统,建议结合自动化扫描 + 人工审计 + 渗透测试。
© rongxinzy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files in SKILLs/web-security-audit of rongxinzy/RongxinAI.
Open the folder on GitHubat commit 9c64865
Web Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Web Security Audit this skillrongxinzy/RongxinAI | 154 | — | ~3k | Automated safety check: Pass | MIT | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 425 | — | ~2.7k | Automated safety check: Pass | None | |
| SecskillsArenbai/SecSkills | 253 | — | ~1.8k | Automated safety check: Notes | MIT | |
| Code Security AuditProgrammerAnthony/Expert-Coding-Harness | 235 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~477 | Automated safety check: Pass | None | |
| Security ReviewerAratKruglik/claude-laravel | 155 | 1 repos | ~1.1k | Automated safety check: Notes | None |
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
Arenbai/SecSkills
渗透测试实战技能 v1.3.0。覆盖信息收集、全类漏洞发现(注入全家桶/SSRF/文件类/反序列化/SSTI/越权逻辑/CSRF)、漏洞利用、后渗透、免杀全流程。
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
0xShe/PHP-Code-Audit-Skill
CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
liuyanghejerry/Clausura
TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.
rongxinzy/RongxinAI
SaaS financial health advisor. An agent skill from rongxinzy/RongxinAI.
rongxinzy/RongxinAI
Reduce voluntary and involuntary churn through cancel flow design, save offers, exit surveys, and dunning sequences.
rongxinzy/RongxinAI
The only skill for creating a new PowerPoint deck. An agent skill from rongxinzy/RongxinAI.
rongxinzy/RongxinAI
ZhiYuan Agent expert package lifecycle manager for the pi engine.
rongxinzy/RongxinAI
Professional Ziwei Doushu consultation skill with an offline calculation engine.
rongxinzy/RongxinAI
飞书邮箱:Use when user mentions 起草邮件、写邮件、草稿、发送/回复/转发邮件、查阅邮件、看邮件、搜索邮件、邮件文件夹、邮件标签、邮件联系人、监听新邮件、邮件收信规则等;use for mail/email intent only.
Works with
Categories
基于 OWASP Top 10 (2021) 标准提供代码安全审查,逐项检查 SQL 注入、XSS、SSRF、访问控制、加密失败等常见漏洞,并给出具体的漏洞代码示例与修复方案。当用户需要代码安全审查、安全加固、渗透测试辅助,或提及 OWASP、安全检查、SQL 注入、XSS、代码审计、安全清单等关键词时触发此技能。. Web Security Audit is an agent skill from rongxinzy/RongxinAI.
Web Security Audit fits situations like: tasks that involve Web application vulnerabilities.
Run `npx skills add rongxinzy/RongxinAI --skill web-security-audit -a claude-code`. Or copy the skill folder (SKILLs/web-security-audit in rongxinzy/RongxinAI) into .claude/skills/web-security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rongxinzy/RongxinAI --skill web-security-audit -a codex`. Or copy the skill folder (SKILLs/web-security-audit in rongxinzy/RongxinAI) into .agents/skills/web-security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rongxinzy/RongxinAI --skill web-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/web-security-audit, .gemini/skills/web-security-audit, .github/skills/web-security-audit and .opencode/skills/web-security-audit in your project.
Going by SKILL.md and its folder, Web Security Audit needs the command-line tools its instructions call (pip and npm) and credentials named SECRET_KEY, JWT_SECRET and FLASK_SECRET_KEY. Our summary lists: Python 3; Node.js; A credential in SECRET_KEY; A credential in FLASK_SECRET_KEY.
SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Web Security Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Web Security Audit: Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars), Secskills (Arenbai/SecSkills, 253 stars), Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars) and Php Codeigniter Audit (0xShe/PHP-Code-Audit-Skill, 402 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rongxinzy (a GitHub organization) maintains it in rongxinzy/RongxinAI, which has 154 GitHub stars. The repository holds 94 skills in this directory. The repository was last updated on October 10, 2026.
Source: rongxinzy/RongxinAI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.