返回 Skill 列表
extension
分类: 开发与工程无需 API Key

security-vulnerability-audit

使用Trunk(Trivy和OSV-scanner)审计安全漏洞的工作流程。在检查项目漏洞、硬编码密钥或修复安全缺陷时使用。

person作者: jakexiaohubgithub

Security Vulnerability Audit

This skill provides a structured process for identifying and reporting security vulnerabilities in the codebase using Trunk's integrated security tools.

Audit Workflow

  1. Run Security Scan: Execute the project's security linting script.

    pnpm run lint:security
    

    Note: This command runs trunk check --all --scope security, which triggers both Trivy and OSV-scanner.

  2. Analyze Findings: Review the output from Trunk. Pay close attention to:

    • Critical/High vulnerabilities in dependencies (reported by osv-scanner).
    • Hard-coded secrets or configuration issues (reported by trivy).
  3. Compile Report: Use the findings to create a summary of the security posture.

Reporting Format

For each significant finding, provide:

  • Severity: [Critical/High/Medium/Low]
  • Tool: [Trivy/OSV-Scanner]
  • Description: [Brief description of the vulnerability]
  • Impact: [What happens if exploited?]
  • Recommendation: [How to fix it, e.g., "Update package X to version Y"]

Resources