← 返回 Skills 市场
ivangdavila

Security Best Practices

作者 Iván · GitHub ↗ · v1.0.0
linuxdarwinwin32 ✓ 安全检测通过
1170
总下载
0
收藏
21
当前安装
1
版本数
在 OpenClaw 中安装
/install security-best-practices
功能描述
Review code with secure-by-default standards, prioritize exploitable risks, and deliver minimal-diff fixes with evidence and regression checks.
使用说明 (SKILL.md)

Setup

On first use, read setup.md for integration guidelines. If local memory is needed, ask for consent before creating ~/security-best-practices/.

When to Use

Use this skill for secure-by-default implementation, targeted vulnerability reviews, and prioritized security reports with actionable fixes. Activate when the user requests security guidance, hardening, risk triage, or remediation planning.

Architecture

Memory lives in ~/security-best-practices/. See memory-template.md for setup.

~/security-best-practices/
|- memory.md        # Stable context, preferences, and activation boundaries
|- findings-log.md  # Findings registry with severity and status
`- exceptions.md    # Approved security exceptions and review dates

Quick Reference

Load only the minimum file needed for the current request.

Topic File
Setup process setup.md
Memory template memory-template.md
Full review workflow review-playbook.md
Severity model and scoring severity-model.md
Safe remediation patterns remediation-patterns.md
Risk exception log exceptions.md

Core Rules

1. Establish Scope and Evidence First

Before any conclusions, confirm:

  • System boundary (service, module, endpoint, or workflow)
  • Stack evidence (language, framework, deployment context)
  • Threat assumptions (external attacker, internal misuse, privilege level)

No evidence, no finding.

2. Map Risks to a Repeatable Baseline

Evaluate every review against a consistent baseline:

  • Authn/authz boundaries
  • Input validation and output encoding
  • Secrets handling and configuration safety
  • Dependency and supply chain posture
  • Logging, error handling, and data exposure controls

Use review-playbook.md to keep scans systematic instead of ad hoc.

3. Produce Findings That Are Verifiable

Each finding must include:

  • Severity from severity-model.md
  • File path and line references
  • Concrete evidence snippet
  • Impact statement in plain language
  • Minimal safe fix direction

Avoid speculative findings without repository evidence.

4. Prioritize Exploitability Over Theory

Rank by practical risk, not by checklist volume:

  • Reachability from untrusted inputs
  • Privilege required by attacker
  • Blast radius if exploited
  • Ease of abuse and repeatability

High confidence, exploitable issues come first.

5. Remediate With Minimal Product Risk

Fix one finding at a time:

  • Prefer small diffs that preserve existing behavior
  • Add tests when security fixes alter code paths
  • Flag expected behavior changes before implementing
  • Re-run project validation after each fix batch

Use remediation-patterns.md for safe rollouts.

6. Respect Explicit Exceptions and Ownership

If the user accepts a known risk:

  • Record rationale in exceptions.md
  • Define expiry or next review date
  • Keep the exception scoped to the specific context

Never apply broad silent overrides.

Security Review Traps

  • Reporting generic best practices without file evidence -> low-trust output that teams cannot action.
  • Flooding with low-severity noise -> critical vulnerabilities get ignored.
  • Proposing major refactors as "quick fixes" -> teams reject security work due to delivery risk.
  • Ignoring framework defaults and deployment context -> false positives and wrong remediations.
  • Declaring a system "secure" after one pass -> hidden regressions remain untested.

Security & Privacy

Data that leaves your machine:

  • None by default from this skill itself.

Data that stays local:

  • Review preferences and finding history in ~/security-best-practices/.
  • Exception rationale in local memory files only.

This skill does NOT:

  • Exfiltrate source code to undeclared third-party endpoints.
  • Mark unresolved risks as fixed.
  • Perform hidden destructive changes.

Related Skills

Install with clawhub install \x3Cslug> if user confirms:

  • auth - Authentication design and hardening.
  • authorization - Access control and permission boundaries.
  • encryption - Key management and cryptographic hygiene.
  • firewall - Network exposure review and policy controls.
  • devops - Secure delivery, CI checks, and operational safeguards.

Feedback

  • If useful: clawhub star security-best-practices
  • Stay updated: clawhub sync
安全使用建议
This skill appears coherent and safe as an instruction-only security review helper. Before installing or enabling it: 1) Confirm you are comfortable with it creating ~/security-best-practices/ and store sensitive findings there; require explicit consent to create that directory. 2) Ensure that directory has appropriate file-system protections (permissions, disk encryption, backups) because it may hold code snippets or vulnerability evidence. 3) Be cautious before using any offered 'clawhub install' related skills — they are optional third-party installs. 4) If you need networked reviews or CI integration, verify any follow-up steps explicitly (the skill itself declares no external exfiltration). If you want extra assurance, request the author/source or a signed provenance for the skill before wide deployment.
功能分析
Type: OpenClaw Skill Name: security-best-practices Version: 1.0.0 The OpenClaw AgentSkills skill bundle 'security-best-practices' is benign. All files, including `SKILL.md` and `setup.md`, provide instructions for the AI agent to perform security reviews, manage local state transparently, and interact with the user responsibly. The skill explicitly states it does not exfiltrate data or perform hidden destructive changes, and all local file operations (`~/security-best-practices/`) require explicit user consent. There is no evidence of malicious intent, prompt injection for harmful purposes, or risky capabilities beyond its stated purpose.
能力评估
Purpose & Capability
The name and description (security reviews, prioritized findings, minimal diffs) align with the actual content: review playbook, severity model, remediation patterns, and templates. The only required artifact is a local config path (~/security-best-practices/) which is coherent for a review memory store.
Instruction Scope
SKILL.md limits actions to asking consent, creating/using local memory files, loading the minimum necessary files, and following a documented review workflow. There are no instructions to read unrelated system files, exfiltrate data, or call external endpoints. The skill explicitly states to ask before persisting data.
Install Mechanism
No install spec or code files are present; this is instruction-only which minimizes disk-write risk. There is no download/extract/install behavior to evaluate.
Credentials
No environment variables, binaries, or credentials are requested. The only resource required is a local directory for optional memory and logs; that is proportionate for a review workflow. Note: the files stored there could contain sensitive code snippets or findings, so disk access protections matter.
Persistence & Privilege
The skill may create and reuse local memory in ~/security-best-practices/ after explicit consent (always:false). Autonomous model invocation is allowed (platform default), but the skill does not request elevated system privileges or modify other skills. Consider the persistence trade-off: local files will remain until removed and may contain sensitive findings.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install security-best-practices
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /security-best-practices 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Added a complete security review workflow with evidence standards, severity modeling, and minimal-risk remediation guidance.
元数据
Slug security-best-practices
版本 1.0.0
许可证
累计安装 21
当前安装数 21
历史版本数 1
常见问题

Security Best Practices 是什么?

Review code with secure-by-default standards, prioritize exploitable risks, and deliver minimal-diff fixes with evidence and regression checks. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 1170 次。

如何安装 Security Best Practices?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install security-best-practices」即可一键安装,无需额外配置。

Security Best Practices 是免费的吗?

是的,Security Best Practices 完全免费(开源免费),可自由下载、安装和使用。

Security Best Practices 支持哪些平台?

Security Best Practices 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(linux, darwin, win32)。

谁开发了 Security Best Practices?

由 Iván(@ivangdavila)开发并维护,当前版本 v1.0.0。

💬 留言讨论