Security

WanLaiCode 安全

wanlaicode/codex-security

面向代码库的安全扫描

版本
下载 Plugin

207.2 KB · 2026年7月8日

12 次下载
下载量
5 分,1 人评分
评分
1 条评论
评论
共 8 个 Skill
Skill

关于此 Plugin

提供可复用的安全扫描、分析、验证和调查工作流,适用于代码、diff 和相关制品。

分类
Security

能力

  • Interactive
  • Read
  • Write

内含 Skill

点击 Skill 名称查看完整说明。

共 8 个 Skill
attack-path-analysisUse when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
deep-security-scanUse when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Run repeated independent repository-wide discovery passes with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, and final reporting once. Repository-wide targets only; do not use for PRs, commits, branch diffs, working-tree diffs, or scoped paths.
finding-discoveryUse when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
fix-findingUse when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
security-diff-scanUse when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
security-scanUse when the user asks for a repository-wide or scoped-path security scan.
threat-modelUse when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a repository threat model. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
validationUse when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.

评分与评论

来自 Plugin 使用者的反馈。

评分

1 人评分
5.0

评论

0 条评论

正在加载评论