Security
WanLaiCode 安全
wanlaicode/codex-security面向代码库的安全扫描
- 12 次下载
- 下载量
- 评分
- 1 条评论
- 评论
- 共 8 个 Skill
- Skill
关于此 Plugin
提供可复用的安全扫描、分析、验证和调查工作流,适用于代码、diff 和相关制品。
- 分类
- Security
能力
内含 Skill
点击 Skill 名称查看完整说明。
attack-path-analysisUse when Codex is already in the attack-path-analysis phase of a security scan or the user explicitly asks to trace a security finding from source to sink and calibrate severity. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
deep-security-scanUse when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Run repeated independent repository-wide discovery passes with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, and final reporting once. Repository-wide targets only; do not use for PRs, commits, branch diffs, working-tree diffs, or scoped paths.
finding-discoveryUse when Codex is already in the finding-discovery phase of a security scan or the user explicitly asks to discover candidate security findings in a repository or code change. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
fix-findingUse when the user explicitly asks to fix and verify a validated or plausible security finding. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
security-diff-scanUse when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
security-scanUse when the user asks for a repository-wide or scoped-path security scan.
threat-modelUse when Codex is already in the threat-modeling phase of a security scan, the user explicitly invokes $threat-model, or the user explicitly asks to create, update, or persist a repository threat model. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
validationUse when Codex is already in the validation phase of a security scan or the user explicitly asks to determine whether one or more candidate security findings are valid. Do not use as the primary trigger for full PR, commit, branch, patch, or repository scans.
评分与评论
来自 Plugin 使用者的反馈。
评论
0 条评论
正在加载评论