Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification.
Scanned 9/2/2026
Install to Claude Code
npx -y skills add sickn33/agentic-awesome-skills --skill code-audit --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Code Audit?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sickn33-code-audit-agentic-awesome-skills)More formats (shields.io, HTML) on the badges page.
---
name: code-audit
description: "Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification."
risk: safe
source: "https://github.com/zhaoxuya520/reverse-skill"
source_repo: "zhaoxuya520/reverse-skill"
source_type: community
date_added: "2026-08-25"
license: "MIT"
license_source: "https://github.com/zhaoxuya520/reverse-skill/blob/main/LICENSE"
---
# Source Code Security Audit
## When to Use
- Reviewing a codebase for security defects with static analysis.
- Verifying that a vulnerability fix actually removes the flawed pattern.
## 适用场景
- 白盒审计、PR/差分安全审查
- Semgrep / CodeQL / Bandit / gosec 等 SAST
- 危险 API、注入点、鉴权缺失、加密误用
- 与 `supply-chain-security/` 分工:本 skill 偏**自有代码逻辑**,供应链偏依赖与管道
## 工作流
### 1. 范围与威胁模型
```text
□ 信任边界:用户输入、文件、反序列化、SSRF、鉴权中间件
□ 高价值资产:鉴权、支付、管理端、密钥处理
```
### 2. 自动扫描
```bash
semgrep --config auto .
# 或项目规则包
semgrep --config p/owasp-top-ten .
```
### 3. 人工验证(MUST)
```text
□ 每个 SAST 命中:可达性?可利用性?误报?
□ 鉴权:IDOR/越权、缺校验、错误的多租户隔离
□ 注入:SQL/命令/模板/LDAP
□ 加密:硬编码密钥、ECB、自定义 crypto
```
### 4. 产出
```text
Finding:位置 + 数据流 + PoC + 修复建议
可选 ATT&CK / CWE 编号
```
## 工具链
| 工具 | 语言/场景 |
|------|-----------|
| Semgrep | 多语言快速规则 |
| CodeQL | 深数据流(GitHub) |
| Bandit | Python |
| gosec / staticcheck | Go |
| SpotBugs / FindSecBugs | Java |
## 参考
- `references/sast-review-checklist.md`
- `../supply-chain-security/` `../api-security/` `../llm-security/`(Agent 代码)
## 路由上下文
**上游**: MASTER R26
**角色**: `ops/role-map.md` cae
**下游**: 依赖漏洞 → supply-chain;运行时验证 → pentest-tools
## 任务完成自检
- [ ] 是否人工验证而非只贴扫描器输出?
- [ ] 是否含修复建议?
- [ ] 是否限定在授权仓库范围?
- [ ] Checklist?
## Limitations
- Static analysis produces false positives; manual triage is required.
- Coverage depends on language support of the chosen SAST engine.
> Adapted from [zhaoxuya520/reverse-skill](https://github.com/zhaoxuya520/reverse-skill) (MIT).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!