技能 编程开发 安全审计完整性保障

安全审计完整性保障

v20260929
audit-integrity
该技能用于强制执行安全审计和代码审查中的输出质量与证据验证。它防止有效安全发现的被掩盖,确保报告在交付前达到质量标准。包含自我批判、反合理化及持续学习组件,以维护安全分析流程中的诚实性和准确性。
获取技能
484 次下载
概览

Audit Integrity Skill

Enforce output quality, intellectual honesty, and continuous improvement across security audits and code reviews.

When to Use

  • Perform security analyses, threat models, code reviews, or quality audits.
  • Validate that every finding has verified code evidence and taint flow.
  • Prevent the suppression or rationalization of security findings.
  • Evaluate draft reports against the quality gate threshold (score ≥ 8/10).
  • Record lessons learned and security memories after you complete a scan.

Components

This skill provides 7 modular capabilities in the references/ directory. Load each file when you reach its execution phase:

Component Reference File Purpose
Clarification Protocol references/clarification-protocol.md Ask a maximum of 2 targeted questions when scope is not clear
Anti-Rationalization Guard references/anti-rationalization-guard.md Prohibited rationalizations and mandatory responses for findings
Self-Critique Loop references/self-critique-loop.md Mandatory second pass to verify evidence and coverage
Retry Protocol references/retry-protocol.md Tool failure and empty search handling: retry once, then document
Non-Negotiable Behaviors references/non-negotiable-behaviors.md Mandatory rules: do not fabricate, cite evidence, report gaps
Self-Reflection Quality Gate references/self-reflection-quality-gate.md Scoring rubric (1–10 scale) with a minimum threshold of 8
Self-Learning System references/self-learning-system.md Templates and rules for lessons and security memories

Execution Flow

Load reference files as you reach each phase:

  1. Before analysis: If scope or policy is not clear, read references/clarification-protocol.md. Ask a maximum of 2 targeted questions.
  2. During analysis: Follow references/non-negotiable-behaviors.md. At each triage decision, consult references/anti-rationalization-guard.md.
  3. On tool or search failure: Follow references/retry-protocol.md. Do not assume code is secure without verification.
  4. After initial analysis: Complete a second pass with the checklist in references/self-critique-loop.md. Verify taint traces and manifest coverage.
  5. Before delivery: Score the draft report using references/self-reflection-quality-gate.md. All categories must score ≥ 8.
  6. Final delivery: Record lessons and memories using references/self-learning-system.md.
信息
Category 编程开发
Name audit-integrity
版本 v20260929
大小 8.35KB
更新时间 2026-09-30
语言