SYSTEM DOCUMENTATION & REQUIREMENTS
💡 This Skill requires bandit, pylint, mypy, flake8, findsecbugs, spotbugs, checkstyle, pmd, eslint, npm, jshint, gosec, staticcheck, golangci-lint, phpstan, psalm, php-cs-fixer, safety, pip-audit, snyk, npm-audit, yarn-audit, sonar-scanner, requests, urllib3, beautifulsoup4, lxml, trufflehog, gitleaks, pyyaml, toml, configparser, trivy, docker, kubernetes, kubescape, tfsec, checkov, jinja2, markdown, weasyprint, colorama, tqdm, rich, click, pandas, numpy, jsonpath-ng, scapy, nmap, cryptography, pycryptodome, flask, django, fastapi, psycopg2-binary, pymysql, sqlalchemy, pymongo, pika, kafka-python, pyjwt, passlib, bcrypt, pydantic, cerberus, marshmallow, bleach, markupsafe, dompurify, phonenumbers, pre-commit, black, isort, autopep8, logging, python-json-logger, regex, pathlib, mimetypes, concurrent-futures, and includes scripts (resource) and references (resource) and templates (resource) components.
What problem does it solve?
This Skill automates the process of identifying security vulnerabilities in source code, saving developers and security teams significant time and effort in manual code reviews.
Core Features & Use Cases
- Comprehensive Language Support: Audits code written in Java, Python, Go, PHP, JavaScript/Node.js, C/C++, .NET/C#, Ruby, and Rust.
- Multi-dimensional Analysis: Covers 10 critical security dimensions including injection, authentication, authorization, deserialization, SSRF, and business logic flaws.
- Use Case: A development team can use this Skill to perform a quick security check on a new feature before deployment, or a security team can use it for a deep dive audit on a critical application.
Quick Start
Use the dfyx_code_security_review skill to audit the code security of the project located at /path/to/project.