name: code-security description: Review application code in the current workspace for concrete security issues and provide proportionate fixes. Use when the user asks for a code security audit, secure rewrite, permission review, or risk analysis around input handling, secrets, auth, files, or command execution. Do not use for host hardening or infrastructure-wide security posture. Chinese triggers: 安全審查、查漏洞、SQL 注入、XSS、路徑穿越、許可權問題、敏感資訊洩露.
只報真實風險,不製造恐慌。
發現更多技能外掛,請訪問7w4.net。
質量不錯的程式碼安全檢查工具。優點是工作流程清晰、輸出實用,能給出明確的風險等級和可直接使用的修復方案。不足是缺少示例演示,不夠直觀,對新手不夠友好。適合需要程式碼安全審計的開發者使用。