Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 11 additions & 11 deletions common/security.en.md
Original file line number Diff line number Diff line change
Expand Up @@ -103,17 +103,17 @@ Add these rules to your project config file:
Periodically have AI self-audit for security issues:

```
Scan the entire src/ directory against the OWASP Top 10:
1. Injection (SQL, NoSQL, command injection)
2. Broken Authentication
3. Sensitive Data Exposure
4. XML External Entities (XXE)
5. Broken Access Control
6. Security Misconfiguration
7. Cross-Site Scripting (XSS)
8. Insecure Deserialization
9. Using Components with Known Vulnerabilities
10. Insufficient Logging & Monitoring
Scan the entire src/ directory against the OWASP Top 10:2025:
1. Broken Access Control (incl. SSRF)
2. Security Misconfiguration
3. Software Supply Chain Failures (vulnerable / unpinned dependencies)
4. Cryptographic Failures (plaintext secrets, weak algorithms)
5. Injection (SQL, NoSQL, command injection, XSS)
6. Insecure Design
7. Authentication Failures
8. Software or Data Integrity Failures (incl. insecure deserialization)
9. Security Logging and Alerting Failures
10. Mishandling of Exceptional Conditions (swallowed errors, fail-open)

For each finding, provide: file location, risk level, and remediation.
```
22 changes: 11 additions & 11 deletions common/security.md
Original file line number Diff line number Diff line change
Expand Up @@ -101,17 +101,17 @@ console.log('Payment response:', { id: response.id, status: response.status })
定期让 AI 自查安全问题:

```
扫描整个 src/ 目录,按 OWASP Top 10 检查:
1. 注入(SQL、NoSQL、命令注入)
2. 失效的身份认证
3. 敏感数据暴露
4. XML 外部实体
5. 失效的访问控制
6. 安全配置错误
7. 跨站脚本(XSS)
8. 不安全的反序列化
9. 使用含已知漏洞的组件
10. 不足的日志和监控
扫描整个 src/ 目录,按 OWASP Top 10:2025 检查:
1. 失效的访问控制(含 SSRF)
2. 安全配置错误
3. 软件供应链失效(含已知漏洞依赖、未锁版本)
4. 加密失效(明文敏感数据、弱算法)
5. 注入(SQL、NoSQL、命令注入、XSS)
6. 不安全的设计
7. 身份认证失效
8. 软件或数据完整性失效(含不安全的反序列化)
9. 安全日志与告警失效
10. 异常情况处理不当(吞异常、失败时放行)

每个问题给出:文件位置、风险等级、修复建议。
```
Loading