安全审查质量门禁
原名:audit-integrity
为防御性安全审查建立证据、复核、重试和自我校验规则。
中文 Skills 技能说明
适合多个安全检查智能体需要统一输出质量与诚实边界的场景。所有结论必须指向真实证据并说明不确定性,不可为了完成任务降低标准;仅用于已授权的防御性审计。
上游能力依据
上游原始适用说明:Shared audit integrity framework for all AppSec agents — enforces output quality, intellectual honesty, and continuous improvement through anti-rationalization guards, self-critique loops, retry protocols, non-negotiable behaviors, self-reflection quality gates (1-10 scoring, ≥8 threshold), and a self-learning system with lesson/memory governance for security analysis agents.
上游 SKILL.md 主要章节(保留原文标题):
- When to Use
- Components
- Execution Flow
- Agent-Specific Adaptation
- Example extensions per agent type
使用边界
先确认授权范围、资产边界和证据来源。输出用于防御性检查与人工决策,不自动执行攻击、绕过或破坏性操作。
作者、翻译与许可证
- 原作者
- GitHub, Inc. 与 awesome-copilot contributors
- 中文翻译
- CEOFans翻译
- 许可证
- MIT
- 上游来源
- https://github.com/github/awesome-copilot/tree/83561bd7d8a46fcda0581aedabdf8eac7cb196b6/skills/audit-integrity
适用范围
平台:linux、macos、windows;标签:安全与合规、安全审查质量门禁
安全提示
基础静态扫描不等于绝对安全。技能可能调用命令、浏览器、云服务或本地文件,请在最小权限环境中使用,高风险操作必须人工确认。
如发现侵权、许可证或安全问题,可在本页前台提交投诉,管理员复核后可立即下架。