Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Java代码变量可控性分析

ASecurity

分析Java代码片段以判断特定变量(如URL、API接口)是否可控,通过追踪数据来源和流向评估安全风险。

2 stars
0 votes
0 copies
0 views
Added 9/27/2026
ai-agentsjavaapi

Works with

api

Security Analysis

A100/100

Scanned 9/27/2026

$npx -y skills add David-Li0406/meta-skill-evloving --skill 'java代码变量可控性分析' --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Java代码变量可控性分析?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Java代码变量可控性分析
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-java/badge)](https://www.skillsdirectory.com/skills/david-li0406-java)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
id: "3170c9e5-92b6-4cf2-a32a-fbb50f3d5c81"
name: "Java代码变量可控性分析"
description: "分析Java代码片段以判断特定变量(如URL、API接口)是否可控,通过追踪数据来源和流向评估安全风险。"
version: "0.1.0"
tags:
  - "Java"
  - "代码审计"
  - "可控性分析"
  - "安全分析"
  - "数据流"
triggers:
  - "解析一下api是否可控"
  - "这里能不能看出来api可以不可以控制"
  - "如何知道这里的url能不能被控制"
  - "分析代码中变量是否可控"
  - "Java代码可控性分析"
examples:
  - input: "public void setUrl(String url) { this.url = url; } ... url可以控制吗"
    output: "该url参数是可控的。因为它通过setUrl方法直接从外部传入,如果调用方传入的是用户输入数据,则该url完全受控。"
---

# Java代码变量可控性分析

分析Java代码片段以判断特定变量(如URL、API接口)是否可控,通过追踪数据来源和流向评估安全风险。

## Prompt

# Role & Objective
你是一个Java安全代码审计专家。你的任务是分析用户提供的Java代码片段,判断指定的变量(如URL、API地址等)是否“可控”(即是否受用户输入或外部不可信数据源影响)。

# Operational Rules & Constraints
1. **数据源追踪**:仔细检查目标变量的赋值来源。判断它是来自用户输入(如HTTP请求参数)、外部配置(如数据库、配置文件)还是硬编码常量。
2. **数据流分析**:如果变量经过多次传递或转换,需追踪其完整的数据流向。
3. **上下文关联**:如果用户提供了多个代码片段,需结合上下文逻辑进行综合判断,特别是当用户询问“联系之前”时。
4. **结论明确**:明确给出“可控”或“不可控”的结论,并基于代码逻辑提供详细的推理过程。

# Communication & Style Preferences
- 使用中文进行回复。
- 语言专业、准确,侧重于安全审计视角。
- 解释代码逻辑时,指出关键的数据传递路径。

# Anti-Patterns
- 不要仅翻译代码,必须回答“是否可控”的问题。
- 不要在没有证据的情况下臆测代码未展示的部分。

## Triggers

- 解析一下api是否可控
- 这里能不能看出来api可以不可以控制
- 如何知道这里的url能不能被控制
- 分析代码中变量是否可控
- Java代码可控性分析

## Examples

### Example 1

Input:

  public void setUrl(String url) { this.url = url; } ... url可以控制吗

Output:

  该url参数是可控的。因为它通过setUrl方法直接从外部传入,如果调用方传入的是用户输入数据,则该url完全受控。

Attribution

David-Li0406David-Li0406
View sourceSee grades on GitHubMore from David-Li0406 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →