跳到主要内容
知仓学习社ZHICANG

secure-coding-training-skill

Developer security training and assessment for secure coding practices and vulnerability prevention

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,9 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Secure Coding Training Skill

Purpose

Deliver and manage developer security training programs to improve secure coding practices, assess developer security knowledge, and track training effectiveness in reducing vulnerabilities.

Capabilities

Training Module Delivery

  • Deliver language-specific secure coding modules
  • Provide framework-specific security training
  • Offer vulnerability-focused lessons (OWASP Top 10)
  • Present hands-on coding challenges
  • Assign interactive security labs
  • Schedule training pathways by role

Knowledge Assessment

  • Generate skill assessment quizzes
  • Create coding-based security challenges
  • Measure comprehension through practical tests
  • Track knowledge retention over time
  • Compare against industry benchmarks
  • Certify competency levels

Gap Identification

  • Analyze assessment results for knowledge gaps
  • Correlate with actual vulnerability findings
  • Identify team-level weaknesses
  • Map gaps to training modules
  • Prioritize training needs
  • Track improvement over time

Training Path Recommendations

  • Recommend personalized learning paths
  • Suggest role-appropriate modules
  • Prioritize based on project needs
  • Adapt to technology stack
  • Consider compliance requirements
  • Update based on threat landscape

Certification Management

  • Issue training completion certificates
  • Track certification expiration
  • Manage recertification requirements
  • Generate compliance reports
  • Maintain training transcripts
  • Support audit requests

Effectiveness Measurement

  • Correlate training with vulnerability reduction
  • Track secure code review metrics
  • Measure time to remediation improvement
  • Compare pre/post training assessments
  • Generate ROI reports
  • Monitor long-term behavior change

Training Modules

By Language

  • Java security best practices
  • Python secure coding
  • JavaScript/Node.js security
  • C/C++ memory safety
  • Go security patterns
  • .NET security guidelines

By Vulnerability Type

  • Injection prevention (SQL, XSS, LDAP)
  • Authentication/authorization security
  • Cryptographic best practices
  • Input validation techniques
  • Output encoding strategies
  • Secure session management

By Framework

  • Spring Security
  • Django security
  • Express.js security
  • ASP.NET Core security
  • React security patterns
  • Angular security best practices

Integrations

  • Secure Code Warrior: Interactive secure coding training
  • HackEDU: Hands-on security training
  • OWASP WebGoat: Deliberately insecure application
  • Kontra: Application security training
  • Immersive Labs: Cyber skills development
  • Security Journey: Secure development training

Target Processes

  • Security Awareness Training Program
  • Secure SDLC Implementation
  • Developer Onboarding
  • Compliance Training Requirements

Input Schema

{
  "type": "object",
  "properties": {
    "trainingType": {
      "type": "string",
      "enum": ["assessment", "module-delivery", "certification", "gap-analysis", "path-recommendation"],
      "description": "Type of training activity"
    },
    "targetAudience": {
      "type": "object",
      "properties": {
        "developers": { "type": "array", "items": { "type": "string" } },
        "teams": { "type": "array", "items": { "type": "string" } },
        "roles": { "type": "array", "items": { "type": "string" } }
      }
    },
    "technologies": {
      "type": "array",
      "items": { "type": "string" },
      "description": "Programming languages and frameworks"
    },
    "vulnerabilityFocus": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": ["injection", "broken-auth", "xss", "insecure-deserialization", "ssrf", "access-control", "crypto", "logging"]
      }
    },
    "complianceRequirements": {
      "type": "array",
      "items": {
        "type": "string",
        "enum": ["PCI-DSS", "HIPAA", "SOC2", "GDPR", "FedRAMP"]
      }
    },
    "assessmentDifficulty": {
      "type": "string",
      "enum": ["beginner", "intermediate", "advanced", "expert"]
    }
  },
  "required": ["trainingType"]
}

Output Schema

{
  "type": "object",
  "properties": {
    "activityId": {
      "type": "string"
    },
    "trainingType": {
      "type": "string"
    },
    "timestamp": {
      "type": "string",
      "format": "date-time"
    },
    "participantSummary": {
      "type": "object",
      "properties": {
        "totalParticipants": { "type": "integer" },
        "completedTraining": { "type": "integer" },
        "inProgress": { "type": "integer" },
        "notStarted": { "type": "integer" }
      }
    },
    "assessmentResults": {
      "type": "object",
      "properties": {
        "averageScore": { "type": "number" },
        "passingRate": { "type": "number" },
        "topPerformers": { "type": "array" },
        "needsImprovement": { "type": "array" }
      }
    },
    "knowledgeGaps": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "topic": { "type": "string" },
          "gapSeverity": { "type": "string" },
          "affectedDevelopers": { "type": "integer" },
          "recommendedModules": { "type": "array" }
        }
      }
    },
    "trainingPaths": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "developerId": { "type": "string" },
          "recommendedModules": { "type": "array" },
          "estimatedDuration": { "type": "string" },
          "priority": { "type": "string" }
        }
      }
    },
    "certifications": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "developerId": { "type": "string" },
          "certificationName": { "type": "string" },
          "issueDate": { "type": "string" },
          "expirationDate": { "type": "string" }
        }
      }
    },
    "effectivenessMetrics": {
      "type": "object",
      "properties": {
        "vulnerabilityReduction": { "type": "number" },
        "avgRemediationTimeImprovement": { "type": "string" },
        "secureCodeReviewPassRate": { "type": "number" }
      }
    }
  }
}

Usage Example

skill: {
  name: 'secure-coding-training-skill',
  context: {
    trainingType: 'assessment',
    targetAudience: {
      teams: ['backend-team', 'frontend-team']
    },
    technologies: ['Java', 'JavaScript', 'Python'],
    vulnerabilityFocus: ['injection', 'xss', 'broken-auth'],
    assessmentDifficulty: 'intermediate'
  }
}

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/security-compliance/skills/secure-coding-training-skill/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能