发现和使用优秀的技能扩展
对代码库进行全面的安全审计和漏洞分析。在明确要求进行安全分析、代码安全审查、漏洞评估、SAST扫描或识别源代码中的安全问题时使用。涵盖注入缺陷、访问控制失效、硬编码密钥、不安全的数据处理、身份验证弱点、LLM安全以及隐私违规。
Conduct comprehensive security audits and vulnerability analysis on codebases. Use when explicitly asked for security analysis, code security review, vulnerability assessment, SAST scanning, or identifying security issues in source code. Covers injection flaws, broken access control, hardcoded secrets, insecure data handling, authentication weaknesses, LLM safety, and privacy violations.