跳到主要内容
知仓学习社ZHICANG

git-forensics-scanner

Git diff forensics for surfacing and classifying code changes for trojan detection

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Git Forensics Scanner

Surfaces and classifies all code changes in a repository using git diff analysis, providing structured change sets for downstream semantic analysis.

Purpose

The first phase of nation-state trojan detection: identify exactly what changed, how much changed, and classify each change by risk level. Small diffs in critical code paths are flagged as highest-risk since business-logic trojans typically modify 1-5 lines.

Capabilities

Change Set Extraction

  • Unstaged changes (git diff)
  • Staged changes (git diff --cached)
  • Commit range diffs (git diff <base>..<head>)
  • Branch diffs (git diff <base>...<head>)
  • Per-file patch extraction with full hunk context

Change Classification

  • code — Logic, algorithms, formulas, control flow
  • config — Constants, parameters, thresholds, defaults
  • data-model — Schemas, types, model properties, ORM mappings
  • cosmetic — Formatting, comments, whitespace, rounding wrappers

Risk Triage

  • Files with 1-5 line changes in prediction/financial/auth code → HIGH RISK
  • Single-character operator changes → CRITICAL RISK
  • Comment-only changes accompanying code changes → CAMOUFLAGE RISK

Input Schema

{
  "type": "object",
  "required": ["projectRoot"],
  "properties": {
    "projectRoot": {
      "type": "string",
      "description": "Absolute path to the git repository"
    },
    "scanMode": {
      "type": "string",
      "enum": ["uncommitted", "commit-range", "branch-diff"],
      "default": "uncommitted"
    },
    "baseRef": {
      "type": "string",
      "description": "Base git reference (for commit-range/branch-diff)"
    },
    "headRef": {
      "type": "string",
      "description": "Head git reference (for commit-range/branch-diff)"
    },
    "targetPaths": {
      "type": "array",
      "items": { "type": "string" },
      "description": "Limit scan to specific paths"
    }
  }
}

Output Schema

{
  "type": "object",
  "required": ["totalFiles", "files"],
  "properties": {
    "totalFiles": { "type": "number" },
    "totalInsertions": { "type": "number" },
    "totalDeletions": { "type": "number" },
    "files": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "path": { "type": "string" },
          "insertions": { "type": "number" },
          "deletions": { "type": "number" },
          "hunks": { "type": "number" },
          "classification": { "type": "string" },
          "rawDiff": { "type": "string" },
          "riskLevel": { "type": "string" }
        }
      }
    }
  }
}

Usage Example

skill: {
  name: 'git-forensics-scanner',
  context: {
    projectRoot: '/path/to/project',
    scanMode: 'uncommitted'
  }
}

Process Files

  • nation-state-trojan-detection.js — Phase 1: Git Forensics task

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/security-compliance/skills/git-forensics-scanner/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能