Home / kingxiaozhe / cm-workflow · skills/cm-security/SKILL.md · GitHub

cm-security skillA

cm-security is agent-read markdown (skill) from kingxiaozhe/cm-workflow: 用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。.

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

# cm-security — 代码安全扫描与业务复核

先读 `../../runtime/project-context.md`、`../../runtime/logging.md` 和 [执行合同](references/scan-contract.md)。
本 Skill 是独立只读安全入口;不改变 cm-test、任务完成门禁或发布授权。
Codex 用 `$cm-security`,Claude Code 用 `/cm-security`;macOS/Linux 兼容 `/cm:security`。

## 用法

```text
$cm-security
$cm-security {项目路径}
$cm-security {项目路径} --all
$cm-security {项目路径} --semgrep-rules {已审查的外部本地规则文件}
$cm-security {项目路径} --osv-db {外部离线数据库缓存目录}
```

## 执行

1. 省略项目时解析当前 Git 仓库根。显式路径也定位到该仓库根;无 Git/HEAD、主分支缺失或有歧义时停止并说明,不猜基准,不自动 fetch。`--all` 不要求主分支,但仍要求 Git/HEAD。
2. 先确认地图在 Git index 中为普通已跟踪文件,再加载业务地图,只读核对受影响的入口、调用方、权限与数据流。地图缺失、陈旧或失真时,从相关代码补足本次分析,标明缺口;不自动全仓重建或更新地图。
3. 从当前 Skill 位置解析 `{CM_WORKFLOW_ROOT}`,逐项传参数,禁止拼接用户文本为 shell 命令:

```bash
node "{CM_WORKFLOW_ROOT}/scripts/cm-security.mjs" --project "{项目根}" {已解析的可选参数}
```

4. 将扫描 JSON 原样保存在项目外本次私有目录的普通文件中,保留范围、digest、工具状态、遗漏和 findings。退出码 1 表示发现候选问题,3 表示检查仍不完整,均需继续上下文复核;2 表示阻断,只汇报阻断原因。0 可能是 NO_CHANGES,不是安全认证。
5. 对 selected 中每个路径做轻量 AI 复核。先看改动及调用链,再看扫描候选;只加载相关代码,禁止默认加载整套外部审计 Skill。命中或触及鉴权、支付、跨租户、命令/文件/网络边界时,沿该路径深入。
6. 逐项核验输入是否可控、现有防护是否有效、受影响业务及复现条件。分别检查工作区与不同的暂存版本;删除或改名必须结合基准版本和调用方,不能只看剩余文件。引用 `revision + 文件:行号`。
…

Read the whole file at its exact version.

How to install

Latest version
mdr add kingxiaozhe/cm-workflow/cm-security@git:20260919.dd88893
Exact content
mdr add kingxiaozhe/cm-workflow/cm-security@sha256:852c67f3987dd016

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_qomlfsasf7cnp4oo.svg)](https://markdownregistry.com/a/art_qomlfsasf7cnp4oo)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260919.dd88893 latest2026-09-19 dd88893 5,725 BA view · diff
git:20260918.ade40ac2026-09-18 ade40ac 5,148 BA view · diff
git:20260916.c144c452026-09-16 c144c45 4,403 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (5725 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

kingxiaozhe/cm-workflow · 29 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_qomlfsasf7cnp4oo
GET https://markdownregistry.com/api/v1/resolve?ref=kingxiaozhe/cm-workflow/cm-security
GET https://markdownregistry.com/api/v1/blob/852c67f3987dd016e7d9dd5de8fd9f374577ce0fca1338de559141927ee5f600

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from kingxiaozhe/cm-workflow

CLAUDE.md@.claude claude
kingxiaozhe/cm-workflow · .claude/CLAUDE.md
git:20260917.8e7a8ed · audit A · 29 stars
AGENTS.md agents
kingxiaozhe/cm-workflow · AGENTS.md
git:20260924.3f79f65 · audit A · 29 stars
cm-ai skill
kingxiaozhe/cm-workflow · skills/cm-ai/SKILL.md · 用户明确说“规格已确认,开始实现”或要求按已审批 CM specs 开发时使用。新任务默认由 JS workflow 驱动 N1-N8,完成开发、独立审查、QA 与文档同步;模糊点子、未审规格和单独一句“继续”不能触发编码批准。
git:20260924.056a6a9 · audit A · 29 stars
cm-backend-engineer skill
kingxiaozhe/cm-workflow · skills/cm-backend-engineer/SKILL.md · 后端 API 工程师 Skill,执行服务端 API 层开发(路由、业务逻辑、鉴权中间件、缓存、队列),自动适配语言和框架
git:20260723.0314405 · audit A · 29 stars
cm-check skill
kingxiaozhe/cm-workflow · skills/cm-check/SKILL.md · 用户说“检查工作流是否安装正确”“为什么找不到 cm 命令”时使用。默认查询 npm 稳定版,有新版自动升级已管理的 CM 安装,再检查插件、核心 Skills、兼容包装与模板引用;不测试或修改业务代码。
git:20260920.38ea993 · audit A · 29 stars
cm-contract-engineer skill
kingxiaozhe/cm-workflow · skills/cm-contract-engineer/SKILL.md · 智能合约工程师 Skill,执行合约开发、测试、部署,自动适配 EVM/Solana/Move 等链和开发框架
git:20260723.0314405 · audit A · 29 stars
cm-database-engineer skill
kingxiaozhe/cm-workflow · skills/cm-database-engineer/SKILL.md · 数据库工程师 Skill,执行数据模型设计、migration、查询优化,自动适配 ORM 和数据库类型
git:20260723.0314405 · audit A · 29 stars
cm-devops-engineer skill
kingxiaozhe/cm-workflow · skills/cm-devops-engineer/SKILL.md · 发布/运维工程师 Skill,执行 staging 部署、冒烟验证、发布记录与生产发布待决清单编制,自动适配部署栈;生产发布与基础设施变更强制人工确认
git:20260804.c914f1d · audit A · 29 stars
cm-doc-syncer skill
kingxiaozhe/cm-workflow · skills/cm-doc-syncer/SKILL.md · 文档同步 Skill,开发完成后自动更新 README、.claude/ 配置、specs CHANGELOG,保持文档与代码一致
git:20260916.9ebbf71 · audit A · 29 stars
cm-finance-expert skill
kingxiaozhe/cm-workflow · skills/cm-finance-expert/SKILL.md · 金融专家 Skill,覆盖 Web3 与证券/资产/交易领域的正确性审核、营销合规红线识别、合规问题清单生成、业务验收协同;把关型角色,只举旗不定性
git:20260723.0314405 · audit A · 29 stars
cm-fix skill
kingxiaozhe/cm-workflow · skills/cm-fix/SKILL.md · 用户说“修复这个可复现 bug”或要求根据失败报告修代码时使用。执行红灯测试、根因定位、最小修复、独立审查和回归;尚未确认的问题先用 cm-test,新功能和架构重设计转交 cm-prd。
git:20260924.9116423 · audit A · 29 stars
cm-frontend-engineer skill
kingxiaozhe/cm-workflow · skills/cm-frontend-engineer/SKILL.md · 前端工程师 Skill,执行前端开发任务,自动适配项目技术栈(React/Vue/Svelte/Next.js 等),支持 Figma/Stitch 设计稿还原
git:20260723.0314405 · audit A · 29 stars

Every file in kingxiaozhe/cm-workflow

Browse by kind, by grade A, or by owner.