{"slug":"pdlc-security","title":"pdlc-security","summary":"安全审计","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-23T18:54:25.826137Z","repo":{"url":"https://github.com/kanfu-panda/pdlc-skills","stars":17,"forks":2,"license":"MIT","updatedAt":"2026-09-25T12:29:01Z"},"bodyHtml":"<hr>\n<p>name: pdlc-security\ndescription: 安全审计\nargument-hint: &lt;模块 | 服务名&gt;\nallowed-tools: Read, Write, Edit, Glob, Grep, Bash\nlayer: 3\nstage: quality\nproduces:</p>\n<ul>\n<li>docs/04_testing/security/</li>\n</ul>\n<hr>\n<h1>安全审计</h1>\n\n<p>⛔ <strong>IRON LAW · 不可违反的硬门禁</strong></p>\n<p>以下规则为<strong>不可协商</strong>的执行约束：</p>\n<ol>\n<li><strong>文件必须落盘</strong>：所有带编号（功能ID / 缺陷ID）的文档，必须作为实际文件写入磁盘，不可仅在对话中输出。</li>\n<li><strong>阶段必须落章</strong>：每个阶段完成后必须在状态机 <code>docs/.pdlc-state/&lt;feature-id&gt;.json</code> 追加 history，不可跳过。</li>\n<li><strong>测试必须存在</strong>：进入 <code>/pdlc-implement</code> 前，对应测试必须存在且处于红灯状态。违反则中止。</li>\n<li><strong>自检必须执行</strong>：段二自检为强制步骤，不得以\"已经很好了\"为由跳过。</li>\n<li><strong>防循环</strong>：段三修复为单次，不递归。无法自动修复的问题记录到报告，继续往下走。</li>\n<li><strong>状态必推进</strong>：成功执行某 phase 后 <code>current_stage</code> 必须变更。收尾时若发现 <code>current_stage</code> 未推进，视为失败并报错，<strong>不得静默返回</strong>（防止外层循环拿滞后的状态空转烧额度）。唯一例外：命中人工点主动 block 时，<code>current_stage</code> 保持不变但必须写 <code>last_phase_result.ok=false</code> + <code>blocked_reason</code>。</li>\n</ol>\n<p><strong>违反任一条 = 立即中止当前命令，输出违规详情，等待人工介入。</strong></p>\n\n<p>对指定服务或应用进行安全审计，检查常见安全漏洞。</p>\n<h2>审计范围</h2>\n<ol>\n<li><p><strong>OWASP Top 10 检查</strong></p>\n<ul>\n<li>SQL 注入</li>\n<li>XSS（跨站脚本）</li>\n<li>CSRF（跨站请求伪造）</li>\n<li>不安全的直接对象引用</li>\n<li>安全配置错误</li>\n<li>敏感数据泄露</li>\n<li>缺失的访问控制</li>\n<li>不安全的反序列化</li>\n<li>使用含已知漏洞的组件</li>\n<li>日志记录和监控不足</li>\n</ul>\n</li>\n<li><p><strong>认证与授权</strong></p>\n<ul>\n<li>密码存储方式（是否加盐哈希）</li>\n<li>Token 生成与验证</li>\n<li>接口权限控制</li>\n<li>会话管理</li>\n</ul>\n</li>\n<li><p><strong>数据安全</strong></p>\n<ul>\n<li>敏感信息是否加密存储</li>\n<li>环境变量中是否有硬编码密钥</li>\n<li>日志中是否打印敏感数据</li>\n<li>API 响应中是否泄露内部信息</li>\n</ul>\n</li>\n<li><p><strong>依赖安全</strong></p>\n<ul>\n<li>检查依赖包是否有已知漏洞</li>\n<li>检查是否使用了过时的库版本</li>\n</ul>\n</li>\n</ol>\n<h2>输出格式</h2>\n<blockquote>\n<p>⚠️ <strong>必须创建文件，不可仅在对话中输出。</strong></p>\n</blockquote>\n<p><strong>【必须创建文件】</strong> 在 <code>docs/07_reviews/code/</code> 下创建安全审计报告：</p>\n<ul>\n<li>文件名: <code>YYYYMMDD-&lt;服务名&gt;-security-audit.md</code></li>\n<li><strong>文档顶部包含 PDLC 追溯头</strong>：\n<pre><code>&lt;!-- PDLC-TRACE --&gt;\n&lt;!-- 功能名称: &lt;服务名&gt; --&gt;\n&lt;!-- 阶段: 安全审计 --&gt;\n&lt;!-- 创建时间: &lt;ISO 8601&gt; --&gt;\n</code></pre>\n</li>\n<li>按严重程度分级：紧急 / 高危 / 中危 / 低危 / 信息</li>\n<li>每个问题包含：位置、描述、风险、修复建议、参考链接</li>\n<li><strong>创建后验证</strong>：确认文件已存在于 <code>docs/07_reviews/code/</code> 目录</li>\n<li>在对话中输出报告摘要，但<strong>完整报告必须在文件中</strong></li>\n</ul>\n<h2>要求</h2>\n\n<p>\uD83C\uDF10 <strong>Output language for generated artifacts</strong></p>\n<p>All generated artifacts (PRDs, design docs, code comments, review reports,\ntest plans, deployment manuals, changelog entries, etc.) follow this policy:</p>\n<ol>\n<li><p><strong>Default — match the conversation language exactly</strong>:</p>\n<ul>\n<li>用户用中文与 Claude 对话 → 产中文文档、中文代码注释、中文报告</li>\n<li>User talks to Claude in English → produce English artifacts</li>\n<li>User talks in another language → produce artifacts in that language</li>\n<li><strong>Never silently default to a fixed language regardless of the user's input.</strong></li>\n</ul>\n</li>\n<li><p><strong>Explicit override always wins</strong>: when the user specifies a language for\nan artifact (e.g. \"write the PRD in English\", \"用英文写 API 设计文档\",\n\"output the deploy doc in Japanese\"), use that language for that artifact,\nregardless of conversation language.</p>\n</li>\n<li><p><strong>Mixed-language requirements</strong>: if the user wants some artifacts in one\nlanguage and others in a different language (common: Chinese PRD + English\nAPI docs for partners), honour each per-artifact instruction.</p>\n</li>\n<li><p><strong>Uncertain</strong>: if you cannot reliably detect the conversation language,\nask once before producing the first artifact.</p>\n</li>\n</ol>\n<p>This policy applies to <strong>content</strong> (prose, comments, headings). It does\n<strong>not</strong> override technical conventions like English variable names, English\ngit commit subjects, or English error codes when the project's conventions\nrequire them.</p>\n\n<ul>\n<li>给出具体的代码位置和修复代码示例</li>\n<li>关键漏洞标注修复优先级</li>\n</ul>\n<p>审计目标: $ARGUMENTS</p>\n\n<h2>段四：交接（Handoff）</h2>\n<p>命令完成后必须输出以下格式的最终消息：</p>\n<pre><code>✅ &lt;阶段名&gt; 完成：&lt;主要产出物路径&gt;\n\uD83D\uDCCA 自检：&lt;通过数&gt;/&lt;总数&gt; 通过（若有未通过，附要点）\n\uD83D\uDCE6 状态快照：docs/.pdlc-state/&lt;feature-id&gt;.json\n\uD83D\uDC49 下一步：/pdlc-&lt;next_step&gt;\n   （如果有分叉）或 /pdlc-&lt;alt&gt;（条件：&lt;选择依据&gt;）\n</code></pre>\n<p><strong>规则：</strong></p>\n<ul>\n<li>主流程命令（写状态机的命令；下一跳见正文里「本命令的状态机取值」）必须显式输出\"下一步\"，不可省略</li>\n<li>工具型命令（Layer 3）可以没有 <code>next_step</code>，此时输出 <code>\uD83D\uDC49 下一步：（本次流程结束，无后续）</code></li>\n<li>分叉场景必须说明<strong>选择条件</strong>，例如\"若需补充测试用例 → <code>/pdlc-tdd</code>；若测试已齐 → <code>/pdlc-review</code>\"</li>\n</ul>\n\n<p><strong>本命令的 handoff 输出：</strong></p>\n<pre><code>✅ 安全审计报告 完成\n\uD83D\uDCE6 产出：docs/04_testing/security/&lt;feature-id&gt;-audit.md\n\uD83D\uDC49 下一步：（本次流程结束，无后续）\n</code></pre>\n","files":[{"path":"SKILL.md","sizeBytes":6027,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-23T18:54:58.625781Z","sha256":"9B589AE88875A35F1CD007300BEB380410A0C7A839F7AE96919A7CBA0DF79F18","sizeBytes":3506},"review":null,"source":{"repositoryUrl":"https://github.com/kanfu-panda/pdlc-skills","path":"skills/pdlc-security","license":"MIT","commit":"181ecf1fddc46f1e5f3ab04f64f93ae42d35fa34","subtreeSha":"1E16EB98F804AF5D82BA3A4EE8BF62B3607D4F83EE88ADC3429F18700F3C989D","lastSyncedAt":"2026-10-01T15:23:29.701635Z"},"reviewedAt":"2026-09-23T18:56:30.176575Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/kanfu-panda/pdlc-skills/tree/main/skills/pdlc-security"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install kanfu-panda-pdlc-skills@llmmart"},{"target":"git","command":"git clone https://github.com/kanfu-panda/pdlc-skills.git"}]}