Security Review
affaan-m/ECC
在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/ja-JP/skills/security-review .claude/skills/security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-review" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-review into .claude/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .agents/skills && cp -r skills-src/docs/ja-JP/skills/security-review .agents/skills/security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-review" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-review into .agents/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/docs/ja-JP/skills/security-review .cursor/skills/security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-review" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-review into .cursor/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/xu-xiang/everything-claude-code-zh.git --path docs/ja-JP/skills/security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/docs/ja-JP/skills/security-review .gemini/skills/security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-review into .gemini/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install xu-xiang/everything-claude-code-zh security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .github/skills && cp -r skills-src/docs/ja-JP/skills/security-review .github/skills/security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-review into .github/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/docs/ja-JP/skills/security-review .opencode/skills/security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-review" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-review into .opencode/skills/security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-review在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
Security Review is an agent skill from xu-xiang/everything-claude-code-zh. 在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `cloud-infrastructure-security.md`).
It sits in Security, covering Security review and Web application vulnerabilities. It works with SQL and Supabase. The repository describes itself as: everything-claude-code 中文翻译项目:完整的 Claude Code 配置集合(agents, skills, hooks, commands, rules, MCPs)。源自 Anthropic 黑客松获胜者的实战配置,助力中文工程师高效理解与使用 Claude Code。 The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit dfbf946. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmgitFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
owasp.orgnextjs.orgsupabase.comportswigger.netFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OPENAI_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Review loads about 2.4k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 249 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- [ ] 将 `.env.local` 添加到 .gitignoreAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from xu-xiang/everything-claude-code-zh at commit dfbf946, republished under its MIT licence (© xu-xiang). 249 words, ~2,410 tokens.
.claude/skills/security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.此技能旨在确保所有代码遵循安全最佳实践,并识别潜在漏洞。
const apiKey = "sk-proj-xxxxx" // 硬编码的机密信息
const dbPassword = "password123" // 存在于源码中const apiKey = process.env.OPENAI_API_KEY
const dbUrl = process.env.DATABASE_URL
// 确保机密信息存在
if (!apiKey) {
throw new Error('OPENAI_API_KEY not configured')
}.env.local 添加到 .gitignoreimport { z } from 'zod'
// 定义验证 Schema
const CreateUserSchema = z.object({
email: z.string().email(),
name: z.string().min(1).max(100),
age: z.number().int().min(0).max(150)
})
// 处理前验证
export async function createUser(input: unknown) {
try {
const validated = CreateUserSchema.parse(input)
return await db.users.create(validated)
} catch (error) {
if (error instanceof z.ZodError) {
return { success: false, errors: error.errors }
}
throw error
}
}function validateFileUpload(file: File) {
// 检查大小(最大 5MB)
const maxSize = 5 * 1024 * 1024
if (file.size > maxSize) {
throw new Error('File too large (max 5MB)')
}
// 检查类型
const allowedTypes = ['image/jpeg', 'image/png', 'image/gif']
if (!allowedTypes.includes(file.type)) {
throw new Error('Invalid file type')
}
// 检查扩展名
const allowedExtensions = ['.jpg', '.jpeg', '.png', '.gif']
const extension = file.name.toLowerCase().match(/\.[^.]+$/)?.[0]
if (!extension || !allowedExtensions.includes(extension)) {
throw new Error('Invalid file extension')
}
return true
}// 危险 - 存在 SQL 注入漏洞
const query = `SELECT * FROM users WHERE email = '${userEmail}'`
await db.query(query)// 安全 - 使用参数化查询
const { data } = await supabase
.from('users')
.select('*')
.eq('email', userEmail)
// 或在原生 SQL 中使用
await db.query(
'SELECT * FROM users WHERE email = $1',
[userEmail]
)// ❌ 错误:localStorage(容易受到 XSS 攻击)
localStorage.setItem('token', token)
// ✅ 正确:httpOnly Cookie
res.setHeader('Set-Cookie',
`token=${token}; HttpOnly; Secure; SameSite=Strict; Max-Age=3600`)export async function deleteUser(userId: string, requesterId: string) {
// 始终先确认授权
const requester = await db.users.findUnique({
where: { id: requesterId }
})
if (requester.role !== 'admin') {
return NextResponse.json(
{ error: 'Unauthorized' },
{ status: 403 }
)
}
// 继续执行删除
await db.users.delete({ where: { id: userId } })
}-- 在所有表上启用 RLS
ALTER TABLE users ENABLE ROW LEVEL SECURITY;
-- 用户只能查看自己的数据
CREATE POLICY "Users view own data"
ON users FOR SELECT
USING (auth.uid() = id);
-- 用户只能更新自己的数据
CREATE POLICY "Users update own data"
ON users FOR UPDATE
USING (auth.uid() = id);import DOMPurify from 'isomorphic-dompurify'
// 始终对用户提供的 HTML 进行净化
function renderUserContent(html: string) {
const clean = DOMPurify.sanitize(html, {
ALLOWED_TAGS: ['b', 'i', 'em', 'strong', 'p'],
ALLOWED_ATTR: []
})
return <div dangerouslySetInnerHTML={{ __html: clean }} />
}// next.config.js
const securityHeaders = [
{
key: 'Content-Security-Policy',
value: `
default-src 'self';
script-src 'self' 'unsafe-eval' 'unsafe-inline';
style-src 'self' 'unsafe-inline';
img-src 'self' data: https:;
font-src 'self';
connect-src 'self' https://api.example.com;
`.replace(/\s{2,}/g, ' ').trim()
}
]import { csrf } from '@/lib/csrf'
export async function POST(request: Request) {
const token = request.headers.get('X-CSRF-Token')
if (!csrf.verify(token)) {
return NextResponse.json(
{ error: 'Invalid CSRF token' },
{ status: 403 }
)
}
// 处理请求
}res.setHeader('Set-Cookie',
`session=${sessionId}; HttpOnly; Secure; SameSite=Strict`)import rateLimit from 'express-rate-limit'
const limiter = rateLimit({
windowMs: 15 * 60 * 1000, // 15 分钟
max: 100, // 每个窗口期最多 100 个请求
message: 'Too many requests'
})
// 应用于路由
app.use('/api/', limiter)// 对搜索操作进行更严格的速率限制
const searchLimiter = rateLimit({
windowMs: 60 * 1000, // 1 分钟
max: 10, // 每分钟最多 10 个请求
message: 'Too many search requests'
})
app.use('/api/search', searchLimiter)// ❌ 错误:在日志中记录敏感数据
console.log('User login:', { email, password })
console.log('Payment:', { cardNumber, cvv })
// ✅ 正确:脱敏处理
console.log('User login:', { email, userId })
console.log('Payment:', { last4: card.last4, userId })// ❌ 错误:泄露内部细节
catch (error) {
return NextResponse.json(
{ error: error.message, stack: error.stack },
{ status: 500 }
)
}
// ✅ 正确:通用的错误消息
catch (error) {
console.error('Internal error:', error)
return NextResponse.json(
{ error: 'An error occurred. Please try again.' },
{ status: 500 }
)
}import { verify } from '@solana/web3.js'
async function verifyWalletOwnership(
publicKey: string,
signature: string,
message: string
) {
try {
const isValid = verify(
Buffer.from(message),
Buffer.from(signature, 'base64'),
Buffer.from(publicKey, 'base64')
)
return isValid
} catch (error) {
return false
}
}async function verifyTransaction(transaction: Transaction) {
// 验证接收者
if (transaction.to !== expectedRecipient) {
throw new Error('Invalid recipient')
}
// 验证金额
if (transaction.amount > maxAmount) {
throw new Error('Amount exceeds limit')
}
// 确保用户余额充足
const balance = await getBalance(transaction.from)
if (balance < transaction.amount) {
throw new Error('Insufficient balance')
}
return true
}# 检查漏洞
npm audit
# 修复可自动修复的问题
npm audit fix
# 更新依赖项
npm update
# 检查过时的包
npm outdated# 始终提交锁定文件
git add package-lock.json
# 在 CI/CD 中使用以实现可重现的构建
npm ci # 替代 npm install// 测试身份验证
test('requires authentication', async () => {
const response = await fetch('/api/protected')
expect(response.status).toBe(401)
})
// 测试授权
test('requires admin role', async () => {
const response = await fetch('/api/admin', {
headers: { Authorization: `Bearer ${userToken}` }
})
expect(response.status).toBe(403)
})
// 测试输入验证
test('rejects invalid input', async () => {
const response = await fetch('/api/users', {
method: 'POST',
body: JSON.stringify({ email: 'not-an-email' })
})
expect(response.status).toBe(400)
})
// 测试速率限制
test('enforces rate limits', async () => {
const requests = Array(101).fill(null).map(() =>
fetch('/api/endpoint')
)
const responses = await Promise.all(requests)
const tooManyRequests = responses.filter(r => r.status === 429)
expect(tooManyRequests.length).toBeGreaterThan(0)
})在每次生产环境部署前:
请记住:安全不是可选项。单个漏洞就可能危及整个平台。如有疑问,请采取最谨慎的做法。
© xu-xiang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in docs/ja-JP/skills/security-review of xu-xiang/everything-claude-code-zh.
Open the folder on GitHubat commit dfbf946
Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Review this skillxu-xiang/everything-claude-code-zh | 2k | — | ~2.4k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 277k | 3 repos | ~2.5k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 277k | 2 repos | ~2.5k | Automated safety check: Notes | MIT | |
| Security Reviewaffaan-m/ECC | 276k | — | ~3.4k | Automated safety check: Notes | MIT | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Vibe Checkbenavlabs/vibe-check | 118 | — | ~1.1k | Automated safety check: Notes | MIT |
affaan-m/ECC
在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
affaan-m/ECC
認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。
affaan-m/ECC
Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
benavlabs/vibe-check
Security audit for web apps, especially AI-built ("vibe coded") ones.
ProgrammerAnthony/Expert-Coding-Harness
A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…
xu-xiang/everything-claude-code-zh
Everything Claude Code 的交互式安装程序 — 引导用户选择并安装技能和规则到用户级或项目级目录,验证路径,并可选择优化已安装文件。
xu-xiang/everything-claude-code-zh
基于本能(Instinct)的学习系统,通过钩子(hooks)观察会话,创建带有置信度评分的原子本能,并将其演化为技能(Skills)、命令(Commands)或智能体(Agents)。v2.1 版本增加了项目作用域(project-scoped)的本能,以防止跨项目污染。
xu-xiang/everything-claude-code-zh
生产级 API 的 REST API 设计模式,包括资源命名、状态码、分页、过滤、错误响应、版本控制和速率限制. An agent skill from xu-xiang/everything-claude-code-zh.
xu-xiang/everything-claude-code-zh
后端架构模式、API 设计、数据库优化以及适用于 Node.js、Express 和 Next.js API 路由的服务端最佳实践。
xu-xiang/everything-claude-code-zh
后端架构模式、API 设计、数据库优化以及 Node.js、Express 和 Next.js API 路由的服务端最佳实践。
xu-xiang/everything-claude-code-zh
后端架构模式、API 设计、数据库优化以及针对 Node.js、Express 和 Next.js API 路由的服务端最佳实践。
Categories
在添加身份验证、处理用户输入、操作机密信息(Secrets)、创建 API 端点以及实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。. Security Review is an agent skill from xu-xiang/everything-claude-code-zh.
Security Review fits situations like: tasks that involve Security review; tasks that involve Web application vulnerabilities.
Run `npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a claude-code`. Or copy the skill folder (docs/ja-JP/skills/security-review in xu-xiang/everything-claude-code-zh) into .claude/skills/security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a codex`. Or copy the skill folder (docs/ja-JP/skills/security-review in xu-xiang/everything-claude-code-zh) into .agents/skills/security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xu-xiang/everything-claude-code-zh --skill security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-review, .gemini/skills/security-review, .github/skills/security-review and .opencode/skills/security-review in your project.
Going by SKILL.md and its folder, Security Review needs the command-line tools its instructions call (npm and git) and credentials named OPENAI_API_KEY. Our summary lists: Node.js; A credential in OPENAI_API_KEY.
SKILL.md names 4 domains. As links in the text: owasp.org, nextjs.org, supabase.com and portswigger.net. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Review: Security Review (affaan-m/ECC, 277k stars), Security Review (affaan-m/ECC, 277k stars), Security Review (affaan-m/ECC, 276k stars) and Security Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
xu-xiang (a GitHub user) maintains it in xu-xiang/everything-claude-code-zh, which has 1,978 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on March 5, 2026.
Source: xu-xiang/everything-claude-code-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.