跳转到主要内容
此内容尚未提供您的语言版本,正在以英文显示。

Security Scan

技能 已验证 活跃

Run full security scans on the codebase using Ruflo security tools

目的

To provide developers with a reliable and configurable tool for identifying security vulnerabilities and CVEs within their codebase, ensuring a more secure software development lifecycle.

功能

  • Run full security scans
  • Select scan depth (quick, standard, full)
  • Check for known CVEs
  • Identify input validation and path traversal issues
  • Store scan findings via MCP

使用场景

  • Integrate security scanning into CI/CD pipelines
  • Proactively identify and remediate vulnerabilities before deployment
  • Perform in-depth security audits of codebases
  • Ensure compliance with security best practices

非目标

  • Performing dynamic application security testing (DAST)
  • Acting as a runtime security monitor
  • Remediating vulnerabilities automatically

工作流

  1. Specify scan depth (quick, standard, or full)
  2. Execute scan using `npx @claude-flow/cli@latest security scan --depth DEPTH`
  3. Optionally run specific checks like `security cve --check`
  4. Generate a markdown report using `security report --format markdown`
  5. Store findings via MCP using `memory_store`
  6. Train post-task hooks upon successful completion

实践

  • Security Auditing
  • Vulnerability Management
  • Code Quality Assurance

先决条件

  • Node.js and npm/npx installed
  • Claude Code environment

安装

请先添加 Marketplace

/plugin marketplace add ruvnet/ruflo
/plugin install ruflo-security-audit@ruflo

质量评分

已验证
99 /100
1 day ago 分析

信任信号

最近提交1 day ago
星标50.2k
许可证MIT
状态
查看源代码

类似扩展

Semgrep Rule Creator

100

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.

技能
trailofbits

Github

100

Use gh for GitHub issues, PR status, CI/logs, comments, reviews, releases, and API queries.

技能
steipete

Cli Creator

100

Build a composable CLI for Codex from API docs, an OpenAPI spec, existing curl examples, an SDK, a web app, an admin tool, or a local script. Use when the user wants Codex to create a command-line tool that can run from any repo, expose composable read/write commands, return stable JSON, manage auth, and pair with a companion skill.

技能
openai

Migrate Validate

100

Validate pending migrations for foreign key consistency, rollback safety, and best practices

技能
ruvnet

Moyu (摸鱼)

100

감지된 과잉 엔지니어링 패턴: (1) 사용자가 명시적으로 요청하지 않은 코드나 파일을 수정할 때 (2) 요청되지 않은 새로운 추상화 계층(클래스, 인터페이스, 팩토리, 래퍼)을 생성할 때 (3) 요청되지 않은 주석, 문서, JSDoc, 타입 주석을 추가할 때 (4) 요청되지 않은 새로운 종속성을 도입할 때 (5) 최소 편집 대신 파일 전체를 다시 작성할 때 (6) diff 범위가 사용자의 요청을 명백히 초과할 때 (7) 사용자가 "너무 많아", "거기는 건드리지 마", "X만 변경해", "간단하게", "그만"과 같은 신호를 보낼 때 (8) 발생할 수 없는 시나리오에 대한 오류 처리, 유효성 검사, 방어적 코드를 추가할 때 (9) 요청되지 않은 테스트, 설정 스캐폴딩, 문서를 생성할 때

技能
uucz

Safe Mode

100

Prevent destructive operations using Claude Code hooks. Three modes — cautious (warn on dangerous commands), lockdown (restrict edits to one directory), and clear (remove restrictions). Uses PreToolUse matchers for Bash, Edit, and Write.

技能
rohitg00