跳到主要内容
Supermarket
返回能力市场
Agent Pack
design

r03-anthropics-skills-security

🔒 Security & Compliance skill suite derived from anthropics/skills.

TeamArtisanThriveTeamArtisanThrive
65/ 100

公开评测 · 综合采用结论

具备基础能力,但文档或工程质量仍需完善

查看评测依据 评测我的项目基于公开项目证据,非安全认证或安装推荐
48stars
最近更新 5个月前
评测生成时间(北京时间)
本报告引擎
v3.10.0
当前引擎
v3.16.0

本报告与当前引擎使用不同规则;原分数不会自动更新,不同版本的分数不宜直接对比。

重新评测此项目

进入后确认来源与额度,提交才会创建任务。

Evaluation report

综合采用结论

65
C
满分 100
需要完善低风险
决策摘要

具备基础能力,但文档或工程质量仍需完善

74%
中置信度
67
文档
100
安全
53
质量
52
活跃
23
采用
  • 基础评测完成+25/25确定性评分与静态安全扫描已完成
  • README 有效证据+11/254,363 个去重后的有效字符
  • 独立证据来源+8/202 类非重复证据,重复文件不叠加
  • 仓库元数据+10/10已取得仓库状态与采用数据
  • 活跃记录+5/5已取得最近提交时间
  • AI 复核+15/15已完成结构化 AI 证据复核
How it works · 流程图

安全审计命令执行流程

README描述了每个命令遵循的5步交互模式,属于单一任务的连续处理步骤,适合用flow图表示。

AI 提取 · 证据约束

左右滑动查看完整图示

安全审计命令执行流程README描述了每个命令遵循的5步交互模式,属于单一任务的连续处理步骤,适合用flow图表示。确认后开始生成结果基于结果建议后续范围确认步骤1实时分析步骤2结果表格步骤3行动计划步骤4后续步骤步骤5
图示依据
  • • README中'Interaction Pattern'列出5步结构
  • • README中'Progress Display Example'展示分析过程
  • • README中'Findings Table'展示结果表格
五维表现
该套件针对安全与合规场景提供了10个命令和5个工作流,概念清晰,但缺少实际实现细节和可复现示例,安装步骤不完整,无法验证真实可用性。
质量证据
  • README中'Commands'表格列出10个命令,如/owasp-scan、/dep-cve
  • README中'Workflows'表格列出5个工作流,如secure-sdlc、breach-response
  • README中'Quick Install'提供cp命令,但未说明文件结构
  • README中'Progress Display Example'展示输出格式
  • README中'Interaction Pattern'定义5步结构
采用建议
优势
  • 问题与用途描述
  • 有效 README
  • 可执行示例
  • 输出或结果说明
  • 未发现已知高风险模式
关注点
  • 缺少安装或接入步骤
  • 缺少输入、参数或工具说明
  • 缺少错误处理或排障
  • 安装步骤不完整,缺少实际文件结构或SKILL.md内容
  • 命令和参数说明不足,仅给出示例用法,无详细参数定义
适合

安全审计与合规检查的流程框架参考、需要结构化输出和进度跟踪的安全工具设计、作为开发安全相关Skill的模板、快速了解安全命令集和交互模式

不建议直接用于

直接用于生产环境的安全扫描或合规审计、需要精确参数和可靠输出的自动化集成、依赖具体实现细节的二次开发

也有自己的公开项目?先看完证据,再用当前规则生成独立报告。

评测我的项目 →
文档证据
67/100
问题与用途描述10 分
有效 README12 分
安装或接入步骤14 分
可执行示例16 分
输入、参数或工具说明11 分
输出或结果说明9 分
限制、权限或边界12 分
错误处理或排障8 分
许可证信息5 分
结构化章节3 分
安全证据
低风险
未发现已知高风险模式

静态扫描不是安全保证,生产接入前仍应人工复核权限和数据边界。

优先改进清单
  1. 01补充安装或接入步骤
  2. 02补充输入、参数或工具说明
  3. 03补充错误处理或排障
方法、证据与局限展开
数据来源

GitHub Repository API

扫描范围

2 个文件 · 8,086 字符

评测引擎

v3.10.0 · AI 复核已启用(deepseek-chat)

局限
  • 静态评测不会安装或执行项目代码
  • 安全扫描基于高信号文件与已知模式,不能替代人工审计
  • 流行度只反映采用程度,不代表安全或工程质量

30 天热度趋势

README

🔒 Security & Compliance Skills Suite

Derived from anthropics/skills

Domain Commands Workflows License

Adaptation of anthropics/skills for Security & Compliance use cases. Source focus: official Anthropic skill templates, webapp testing, comms


What This Skill Suite Does

Security audits, vulnerability management, GDPR/SOC2/ISO27001 compliance and incident response.

This collection provides 10 specialised commands and 5 multi-step workflows, all with a consistent structured-output UI so you always know exactly where you are and what to do next.


Quick Install

# Clone this skill
cp -r . ~/.claude/skills/r00-anthropics-skills--security/

# Register in Claude Code
# In a Claude Code session:
/read ~/.claude/skills/r00-anthropics-skills--security/SKILL.md

Commands

CommandDescription
/owasp-scanOWASP Top-10 code scan with exploit description, CVSS score and remediation
/dep-cveDependency CVE report with exploitability score and upgrade path
/gdpr-auditGDPR data-flow map, consent gaps and DPA checklist
/soc2-readinessSOC 2 Type II readiness gap analysis across all 5 Trust Service Criteria
/threat-modelSTRIDE threat model for architecture diagram with risk matrix
/pentest-reportStructured penetration test report: executive summary, findings and remediation
/secret-detectPre-commit secret detection hook config with entropy scanning
/iam-auditIAM least-privilege audit: over-permissioned roles, stale access and MFA gaps
/incident-playbookSecurity incident playbook: triage → contain → eradicate → recover → lessons
/privacy-policyGDPR/CCPA-compliant privacy policy generator from data inventory

Usage:

/owasp-scan <target>
/dep-cve --scope full --output md

Workflows (Multi-step)

WorkflowDescription
secure-sdlcShift-left SDLC: threat model → code scan → DAST → pen test → sign-off
breach-responseData breach response: detect → assess → notify → remediate → post-mortem
compliance-auditFull compliance audit: scope → gap analysis → evidence → remediation plan
zero-trust-designZero-trust architecture design: identity → network → workload → data layers
vendor-securityThird-party vendor security assessment: questionnaire → risk score → decision

Usage:

/workflows:secure-sdlc <target> --scope full

UI Design

All commands display structured output with:

  • Progress panels — real-time step tracking
  • Findings tables — sorted by severity (🔴🟠🟡🟢)
  • Action checklists — quick wins → medium-term → strategic
  • Summary cards — at-a-glance metrics after each command

Progress Display Example

╔══════════════════════════════════════════════════╗
║  Security Audit  —  api.domain.com               ║
╠══════════════════════════════════════════════════╣
║  OWASP scan      ✓   14 checks run                ║
║  CVE scan        ✓   234 deps checked             ║
║  IAM audit       ⟳   Scanning roles …             ║
║  GDPR check      ░   Pending                      ║
╚══════════════════════════════════════════════════╝

FINDINGS  (sort: severity desc)
┌──────┬──────────────────────────────┬──────────┬──────────────┐
│ Sev  │ Finding                      │ CVSS     │ Status       │
├──────┼──────────────────────────────┼──────────┼──────────────┤
│  🔴  │ SQL injection /api/search    │  9.8     │ ✗ Open       │
│  🔴  │ JWT none-alg accepted        │  9.1     │ ✗ Open       │
│  🟠  │ CORS wildcard on /api/*      │  6.5     │ ⚠ In-Review  │
│  🟡  │ Missing rate limiting        │  5.3     │ ⚠ In-Review  │
│  🟢  │ CSP header present           │   —      │ ✓ Pass       │
└──────┴──────────────────────────────┴──────────┴──────────────┘

Interaction Pattern

Every command follows this 5-step structure:

① Scope Confirmation  — verify target and options with user
② Live Analysis       — progress bar while working
③ Findings Table      — structured results sorted by impact
④ Action Plan         — prioritised, time-boxed recommendations
⑤ Next Steps          — suggested follow-up commands

Source Repository

This suite is derived from anthropics/skills which focuses on: official Anthropic skill templates, webapp testing, comms.

Improvements in this adaptation:

  • Domain-specific command vocabulary for Security & Compliance
  • Enhanced structured output with visual progress tracking
  • Prioritised action plans with time estimates
  • Workflow orchestration for end-to-end processes
  • Consistent UI conventions across all commands

License

MIT — free to use, modify and distribute.