Skip to content
Back to skills

Security Scan Assistant

ASecurity

[UDS] 引導自動化安全掃描、相依套件審計和機密偵測

  • 75 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 4, 2026
developmentbashsqlnodegitsecurity

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned September 4, 2026

npx -y skills add AsiaOstrich/universal-dev-standards --skill security-scan-assistant --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Scan Assistant?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Scan Assistant
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/asiaostrich-security-scan-assistant-213f9149/badge)](https://www.skillsdirectory.com/skills/asiaostrich-security-scan-assistant-213f9149)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
source: ../../../../skills/security-scan-assistant/SKILL.md
source_version: 1.0.0
translation_version: 1.0.0
last_synced: 2026-03-23
status: current
description: "[UDS] 引導自動化安全掃描、相依套件審計和機密偵測"
name: scan
allowed-tools: Read, Grep, Glob, Bash(npm:audit, npx:*)
scope: universal
argument-hint: "[scan type or target | 掃描類型或目標]"
---

# 安全掃描助手

> **語言**: [English](../../../../skills/security-scan-assistant/SKILL.md) | 繁體中文

自動化相依套件、機密資訊和授權合規的安全掃描。

## 掃描類型

| 類型 | 工具範例 | 用途 |
|------|----------|------|
| **相依套件審計** | npm audit, pip-audit, Snyk | 檢測已知 CVE |
| **機密偵測** | gitleaks, trufflehog | 偵測洩漏的憑證 |
| **授權合規** | license-checker, SPDX | 驗證開源授權相容性 |
| **SAST** | Semgrep, CodeQL | 靜態分析程式碼模式 |

## 工具整合

| 工具 | 指令 | 範圍 |
|------|------|------|
| npm audit | `npm audit --json` | Node.js 相依套件 |
| Snyk | `npx snyk test` | 多語言相依套件 |
| Trivy | `trivy fs .` | 檔案系統與容器 |
| gitleaks | `gitleaks detect` | Git 歷史機密 |
| SPDX | `npx spdx-tool` | 授權 SBOM 產出 |

## 嚴重程度分類與 SLA

| 嚴重程度 | SLA | 標準 |
|----------|-----|------|
| **Critical** | 24 小時 | 遠端執行、認證繞過、資料外洩 |
| **High** | 72 小時 | 權限提升、SQL 注入 |
| **Medium** | 2 週 | XSS、CSRF、資訊洩漏 |
| **Low** | 下個 Sprint | 缺少 Header、冗長錯誤訊息 |

## 工作流程

```
SCAN ──► TRIAGE ──► PRIORITIZE ──► FIX ──► VERIFY
```

## 使用方式

- `/scan` - 完整掃描(相依套件 + 機密 + 授權)
- `/scan --deps` - 僅相依套件審計
- `/scan --secrets` - 僅機密偵測
- `/scan --license` - 授權合規檢查

## 下一步引導

`/scan` 完成後,AI 助手應建議:

> **掃描完成。建議下一步:**
> - 執行 `/security` 深入安全審查
> - 執行 `/checkin` 確認修復符合提交規範
> - 執行 `/commit` 提交安全修復
> - 更新相依套件 → `npm update` 或 `pip install --upgrade`

## 參考

- 核心規範:[security-standards.md](../../../../core/security-standards.md)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…