上手建议:先阅读 SKILL.md 文件,了解核心原则和工作流程。
学习内容:熟悉各种攻击类型和对应的检测方法,参考 ATTACK-CLASSES.md 等文件。
实践建议:从简单的代码库开始,逐步尝试复杂的审计任务。
参考资料:Cloudflare 的博客文章《Build your own vulnerability harness》提供了更多背景信息。
06给 Codex 的 Prompt
Transform the given codebase into a security audit workflow using Cloudflare's security-audit-skill. Follow the six-phase structured audit process: reconnaissance, coverage-led hunting, candidate validation, structured output, independent record verification, and target-neutral reporting. Generate detailed reports including confirmed vulnerabilities, needs validation issues, and rejected candidates. Ensure all findings are validated by fresh verifiers and output the results in a structured format.