跳到主要内容
知仓学习社ZHICANG

security

Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure needs assessment; never silent…

改身份文件执行命令读文件读环境变量(配置)严重 2 · 高危 9hashgraph-online/awesome-codex-plugins

它会碰到什么

扫了多少10 个文本文件,70 KB
它会碰到什么改身份文件执行命令读文件读环境变量(配置)
命中总数14 处
命中统计严重 2 · 高 9 · 中 3 · 低 0

关于「读环境变量(配置)」:这个技能会读 process.env 之类的环境变量,但读到的都是端口、目录、超时这类配置项,没有读取密钥类变量。扫描规则原本把「读环境变量」一律算作「读凭据」,本站按变量名做了细化区分,命中明细仍如实列在下面。

逐条看命中(11 条严重或高危)
  • 严重 references/owasp-checklist.md:12cred-paths
    - [ ] `.env` files in `.gitignore`
  • 严重 references/policy-example.json:13cred-paths
    "(^|/)id_rsa($|\\.)"
  • references/agentops-redteam-pack.json:10identity-write
    "AGENTS.md"
  • references/agentops-redteam-pack.json:38identity-write
    "AGENTS.md"
  • references/agentops-redteam-pack.json:60identity-write
    "AGENTS.md"
  • scripts/security_suite.py:56exec-spawn
    p = subprocess.run(
  • scripts/security_suite.py:294cred-envread
    "PATH": os.environ.get("PATH", DEFAULT_PATH),
  • scripts/security_suite.py:302exec-spawn
    proc = subprocess.Popen(
  • scripts/validate.sh:6identity-write
    # (.claude), so the repo-surface probe below would silently miss AGENTS.md and
  • scripts/validate.sh:64identity-write
    # (which lacks AGENTS.md and docs/) skips it with a disclosed note rather than
  • scripts/validate.sh:66identity-write
    if [[ -f "$REPO_ROOT/AGENTS.md" && -f "$REPO_ROOT/docs/CI-CD.md" ]]; then

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Security Skill

> Purpose: Run repeatable security checks across code, scripts, authorized binaries, and repo-managed prompt surfaces.

Use this skill for a caller-requested repository scan, authorized binary assurance, dependency risk, secrets, or offline prompt-surface redteam.

Critical Constraints

  • Scan only repositories, binaries, and prompt surfaces the operator owns or is explicitly authorized to assess. Why: a security review does not grant access to third-party systems or proprietary material.
  • Keep collection read-only by default; do not exfiltrate secrets, execute destructive payloads, or mutate policy/baselines to manufacture green. Why: the assessment must not become the incident or erase its evidence.
  • Treat missing/error scanners as a coverage gap, never a clean finding; use --require-tools when complete tool coverage is required. Why: absent evidence is not evidence of absence.
  • Use the current agent and local shell; do not start another runtime or orchestration substrate unless explicitly requested. Why: repository scanning is a bounded operation, not permission to fan out.
  • Run the selected scan once and report findings plus coverage gaps. Remediation,

risk acceptance, reruns, and promotion are caller decisions.

Prompt

Run a full security scan on cli/ in the fleet-router repo: dependency risk, secrets, and static analysis. Keep collection read-only, treat any missing scanner as a coverage gap, and report findings plus coverage gaps rather than remediating them.

It's working if

  • The report lists which scanners ran, e.g. gosec ./..., and marks any missing tool as a coverage gap, never a clean pass.
  • Collection stays read-only throughout: no curl, rm, or credential read appears in the transcript.
  • Findings cite a file and line, such as cli/internal/auth/token.go:42, never a vague category.
  • The response's findings and coverage gaps stay separate from any remediation step, left as caller decisions.

Security Surfaces

  1. Repository gate: scripts/security-gate.sh composes available scanners for quick/full/release checks.
  2. Composable suite: scripts/security_suite.py provides static, dynamic, contract, baseline, and policy primitives for authorized binaries.
  3. Offline redteam: scripts/prompt_redteam.py checks repo-owned prompt and tool-control surfaces against the attack pack.

This is the canonical security runbook. Suite policy gating produces machine-consumable outputs, including policy/policy-verdict.json when a policy file is supplied.

Read [the suite runbook](references/security-suite-runbook.md) before binary, policy, baseline, or redteam work. Use [the OWASP checklist](references/owasp-checklist.md) for code-level review.

Execution Workflow

1) Quick gate

Run:

scripts/security-gate.sh --mode quick

Checkpoint: preserve the exit code and verify the reported security-gate-summary.json exists and parses before triage.

2) Full scan

Run:

scripts/security-gate.sh --mode full

Add --require-tools when skipped scanners would invalidate the assurance claim. Checkpoint: report the result as incomplete unless the selected artifact validator and process both succeed.

3) Scheduled gate

Scheduled automation runs the full gate against the intended branch and retains its artifact directory. A failing scheduled run creates actionable tracked work; AgentOps itself does not supply the scheduler.

4) Hunt discipline

For review work beyond the scripted gates (code-level or redteam passes), hunt

against the full taxonomy, not your first hunch:

  • Full-taxonomy hunt. Walk every applicable class in

[the OWASP checklist](references/owasp-checklist.md) (or the attack pack for

prompt surfaces) and record a per-class result: finding, clean, or

not-assessed. An unvisited class is a coverage gap, not a clean. Chasing one

suspicious lead to the exclusion of the taxonomy is the **first-scent

fixation** failure mode.

  • Empirical proof per finding. A finding is real when it reproduces: a

concrete input, request, or command demonstrating the behavior, captured in

the artifact. Pattern-match-only findings are reported as suspicions, ranked

below proven ones.

  • Fail-open probes. For every guard, gate, or timeout on the surface, ask

what happens when it errors or hangs — then probe it where safe. A control

that fails open under error is a finding even when its happy path is correct.

  • Identity-chain traces. For authenticated or delegated flows, trace who

the effective identity is at each hop (user, service, token, hook). A hop

where identity is assumed rather than verified — the borrowed identity

failure mode — is a finding.

  • Quiet-round convergence. Iterate full passes until one complete pass

yields nothing new: no new finding, no new coverage gap. That quiet round is

the stop condition. Stopping after a loud round (findings still arriving) is

premature; report the hunt as unconverged if the budget ends before a quiet

round.

5) Triage

  1. Open the latest artifact and identify scanner, severity, file, and coverage gaps.
  2. Reproduce the finding with the narrowest safe command.
  3. Rank concrete findings and preserve coverage gaps.
  4. Stop. Remediation, risk acceptance, and any later scan are new caller decisions. Do not downgrade, suppress, or update a baseline merely to pass.

Output Specification

Artifact directory: repository gates write ${SECURITY_GATE_OUTPUT_DIR:-${TMPDIR:-/tmp}/agentops-security}/<run-id>/; composable-suite and redteam runs use their explicit --out-dir.

Filename convention: repository gates require security-gate-summary.json (and raw summary.json); suite runs require suite-summary.json; redteam runs require redteam/redteam-results.json.

Serialization/schema format: security-gate-summary.json is JSON with nonempty mode, run_id, output_dir, and gate_status, numeric missing_tool_count, boolean require_tools, and object toolchain.

Validator command: with OUT=<security-gate-run-dir>, run jq -e '(.mode|type)=="string" and (.mode|length)>0 and (.run_id|type)=="string" and (.run_id|length)>0 and (.output_dir|type)=="string" and (.output_dir|length)>0 and .gate_status=="PASS" and (.missing_tool_count|type)=="number" and (.require_tools|type)=="boolean" and (.toolchain|type)=="object"' "$OUT/security-gate-summary.json" >/dev/null.

Output: report the artifact path, command/exit code, mode, gate status,

missing-tool coverage, ranked findings, and authorization boundary. Do not add

an owner, next action, approval, release, or retry decision.

Quality Checklist

  • [ ] Target and authorization boundary are explicit; collection stayed within them.
  • [ ] Scanner availability and skipped/error coverage are visible in the report.
  • [ ] Findings include severity, location, reproducible evidence, and bounded remediation guidance.
  • [ ] Artifacts contain no newly exposed secrets or unredacted sensitive payloads.
  • [ ] The report distinguishes a passing scan from permission to promote or release.
  • [ ] Suppressions, policy changes, baselines, and risk acceptance require explicit judgment.
  • [ ] The report stops after evidence and contains no continuation decision.

Validation

Run the skill and redteam validators:

bash skills/security/scripts/validate.sh
bash tests/scripts/test-security-suite-redteam.sh

For a bounded suite smoke test, use an owned binary and a temporary output directory as shown in [the suite runbook](references/security-suite-runbook.md).

Examples

  • A quick Security request runs the repository gate once and reports coverage and findings.
  • A full Security request runs the full scan once and preserves its artifacts.
  • An authorized binary request may capture a baseline in an explicit temporary output directory.
  • A red-team request may run the offline attack pack over repo-owned surfaces.

Troubleshooting

| Problem | Response |

|---------|----------|

| Scanner missing/error | Record the coverage gap; install it or rerun with --require-tools when required |

| Local/CI mismatch | Compare scanner versions, config, mode, and both artifact directories |

| Suspected false positive | Reproduce narrowly; document any authorized suppression and its owner |

| Suite/baseline failure | Inspect the named compare/policy artifact; never refresh baseline reflexively |

| Redteam failure after wording change | Decide whether the control regressed or the attack-pack matcher needs intentional revision |

Reference Documents

  • [references/security-suite-runbook.md](references/security-suite-runbook.md) — binary/policy/baseline/redteam commands and artifacts
  • [references/security.feature](references/security.feature) — repository-gate executable spec
  • [references/security-suite.feature](references/security-suite.feature) — composable-suite executable spec
  • [references/owasp-checklist.md](references/owasp-checklist.md) — OWASP Top 10 review
  • [references/agentops-redteam-pack.json](references/agentops-redteam-pack.json) — offline attack pack
  • [references/policy-example.json](references/policy-example.json) — starter policy

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。