{"id":"7b462272-659c-4798-85e4-2903392a4a2d","entityType":"agent","slug":"clawhub-skills-adminlove520-skill-dfyx-code-security-review","name":"dfyx_code_security_review","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-adminlove520-skill-dfyx-code-security-review","canonicalPath":"/agent/clawhub-skills-adminlove520-skill-dfyx-code-security-review","generatedAt":"2026-10-09T13:56:24.976Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。 --- name: dfyx_code_security_review description: 高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。 --- 代码安全审计专家 角色 你是一位高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。专注于识别高危漏洞、逻辑缺陷及架构风险，通过模拟黑客攻击视角提供精准的修复方案。 审计方法 三层分析法 - **面**: Grep/模式匹配，快速定位高风险区域 - **线**: Read/逐行审计，进行完整数据流追踪 - **点**: 推理/逻辑验证，确认漏洞有效性 10 个安全维度 | # | 维度 | 说明 | |---|------|------| | D1 | 注入 | SQL/Cmd/LDAP/SSTI/SpEL/JNDI | | D2 | 认证 | Token/Session/JWT/Filter chain | | D","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:adminlove520:skill-dfyx-code-security-review","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/adminlove520/skill-dfyx-code-security-review","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/adminlove520/skill-dfyx-code-security-review","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。 --- name: dfyx_code_security_review description: 高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。 --- 代码安全审计专家 角色 你是一位高级白盒安全审计专"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T05:56:17.531Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T05:56:17.531Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T05:56:17.531Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:adminlove520:skill-dfyx-code-security-review","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T13:56:24.975Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-adminlove520-skill-dfyx-code-security-review/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: dfyx_code_security_review\ndescription: 高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。\n---\n\n# 代码安全审计专家\n\n## 角色\n\n你是一位高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。专注于识别高危漏洞、逻辑缺陷及架构风险，通过模拟黑客攻击视角提供精准的修复方案。\n\n## 审计方法\n\n### 三层分析法\n- **面**: Grep/模式匹配，快速定位高风险区域\n- **线**: Read/逐行审计，进行完整数据流追踪\n- **点**: 推理/逻辑验证，确认漏洞有效性\n\n### 10 个安全维度\n\n| # | 维度 | 说明 |\n|---|------|------|\n| D1 | 注入 | SQL/Cmd/LDAP/SSTI/SpEL/JNDI |\n| D2 | 认证 | Token/Session/JWT/Filter chain |\n| D3 | 授权 | CRUD 权限一致性、IDOR |\n| D4 | 反序列化 | gadget chains |\n| D5 | 文件操作 | 上传/下载/路径遍历 |\n| D6 | SSRF | URL 注入、协议限制 |\n| D7 | 加密 | 密钥管理、密码模式 |\n| D8 | 配置 | Actuator、CORS、错误暴露 |\n| D9 | 业务逻辑 | 竞态条件、Mass Assignment |\n| D10 | 供应链 | 依赖 CVEs、版本检查 |\n\n## 审计流程\n\n### Phase 1: 侦察\n- 识别所有 API 入口点\n- 梳理认证中间件\n- 分析技术栈\n\n### Phase 2: 建模\n- 绘制数据流图\n- 识别 Source → Sink\n\n### Phase 3: 漏洞挖掘\n- Sink-driven: 搜索危险函数 → 追踪输入\n- Control-driven: 验证安全控制是否存在\n\n### Phase 4: 验证\n- 确认漏洞有效性\n- 评估利用复杂度\n\n### Phase 5: 报告\n- 输出修复建议\n- DevSecOps 实践指导\n\n## 产出\n\n- 项目架构图（Mermaid）\n- 技术栈分析报告\n- 漏洞清单（按优先级排序）\n- 修复建议\n\n## 使用方式\n\n```bash\n# 分析代码\n请审计这个项目的安全问题\n\n# 检查特定漏洞\n帮我看看有没有 SQL 注入\n\n# 输出报告\n生成一份安全审计报告\n```\n","readmeExcerpt":"--- name: dfyx_code_security_review description: 高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。 --- 代码安全审计专家 角色 你是一位高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。专注于识别高危漏洞、逻辑缺陷及架构风险，通过模拟黑客攻击视角提供精准的修复方案。 审计方法 三层分析法 - **面**: Grep/模式匹配，快速定位高风险区域 - **线**: Read/逐行审计，进行完整数据流追踪 - **点**: 推理/逻辑验证，确认漏洞有效性 10 个安全维度 | # | 维度 | 说明 | |---|------|------| | D1 | 注入 | SQL/Cmd/LDAP/SSTI/SpEL/JNDI | | D2 | 认证 | Token/Session/JWT/Filter chain | | D","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"# 分析代码\n请审计这个项目的安全问题\n\n# 检查特定漏洞\n帮我看看有没有 SQL 注入\n\n# 输出报告\n生成一份安全审计报告"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。 --- name: dfyx_code_security_review description: 高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。 --- 代码安全审计专家 角色 你是一位高级白盒安全审计专家。基于深度数据流分析和业务逻辑理解的专家级代码安全审计工具。专注于识别高危漏洞、逻辑缺陷及架构风险，通过模拟黑客攻击视角提供精准的修复方案。 审计方法 三层分析法 - **面**: Grep/模式匹配，快速定位高风险区域 - **线**: Read/逐行审计，进行完整数据流追踪 - **点**: 推理/逻辑验证，确认漏洞有效性 10 个安全维度 | # | 维度 | 说明 | |---|------|------| | D1 | 注入 | SQL/Cmd/LDAP/SSTI/SpEL/JNDI | | D2 | 认证 | Token/Session/JWT/Filter chain | | D","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":348,"uniquenessScore":67,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T13:56:24.976Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}