Skip to content
AI & Agents
Skill

/security-scan

对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。

BOOST
From plugin
anbeime-skill
7.4k78 skills
Install
$ npx -y skills add anbeime/skill --skill security-scan --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/security-scan

Context preview

The summary Claude sees to decide when to auto-load this skill.

对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。

SKILL.md

security-scan.SKILL.md
name: security-scan
description: 对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。
assign_when: 该 Worker 是文档入口的安全守门人,负责域名黑名单、OA 许可校验与可疑来源拦截;任何文件进入系统前必须经其把关。

合规安检 Skill(锦衣卫)

使用方式

  • 由锦衣卫 Worker 在收到文件/URL 时调用,作为流水线的第一道闸门。
  • 输出结构化判定(`pass` / `reject`),并写入 provenance 交由太史阁留痕。

输入(Input)

  • `target`:待检对象,二选一
  • 本地文件路径(PDF / PPT / Excel / Word / 图片)
  • 外部 URL(需先解析域名)
  • `policy_ref`:(可选)覆盖默认策略的合规规则集引用

输出(Output)

  • `verdict`:`pass` 或 `reject`
  • `report`:安全扫描报告,含命中的黑名单项、许可状态、风险等级
  • `trace_id`:本次扫描的 provenance 追踪 ID(用于太史阁留痕)

依赖(Dependencies)

  • Sci-Hub 等已知违规域名黑名单(本地 CSV/JSON)
  • OA 文档许可校验库(本地规则)
  • 文件类型探测(`python-magic`)

失败处理(Failure Handling)

  • 扫描服务不可用:**拒绝文件并告警**,绝不降级放行(零信任底线)。
  • 文件类型无法识别:标记 `reject` 并写入原因,交由管理员确认。
  • 黑名单库读取失败:回退到「全拒 + 告警」保守策略,并提示运维修复。

复用价值(Reuse Value)

  • 与具体业务解耦:任何文档处理系统(RAG、知识库、合同审查)均可直接挂载此 Skill 作入口安检。
  • 判定标准可配置:通过替换 `policy_ref` 适配不同行业的合规基线。

复赛代码包执行(runnable package)

  • 真实入口:`scripts/run_security_scan.py`
  • 执行等价于 `core.runtime.AgentSession.run_stage("security-scan")`,调用 `security.jinyiwei.JinYiWeiAgent`(纯 Python,零外部依赖,可离线运行)。
  • 运行:`python skills/security-scan/scripts/run_security_scan.py`
  • 产物:`examples/snse_survey/skill_outputs/security_scan.json`(黄卡 + 扫描报告)。
Ships withanbeime-skill

收录最全、更新最快的AI Agent技能库,涵盖文档处理、内容创作、编程开发、机器学习、自动化工作流等多个领域的精选技能包。 🧠 知易智能基座 :20+模型自由切换,知识永远留在你手里 —一个对话框调度所有模型,240+技能即插即用,四色卡片让AI真正记住你。 👉 申请体验

Get the whole plugin

Other skills on anbeime-skill.

agent-team
Skill

agent-team

产品经理与项目管理专家在应对复杂项目时,使用此技能可动态组建包含“执行、指挥、评审”的专属AI团队。实时查看多智能体辩论与决策全过程,共享统一上下文记忆,一键完成从会议决策到系统构建的全流…

agentkit-multimedia-shopping
Skill

agentkit-multimedia-sh…

电商运营与内容创作者在需要制作带货短视频时,用此技能一键生成9:16竖屏数字人成片。自动编排AI绘画、语音合成与视频生成,快速产出“小省导购员”专属形象与专业配音,让多模态视频制作省时省力…

antinet-doc-parse
Skill

antinet-doc-parse

软件开发工程师与数据科学家在构建RAG系统时,当需处理PDF/Word/Excel等多格式复杂文档,用此技能可自动触发三级解析降级,一键输出高置信度结构化Markdown与元数据,免去繁琐…