Adds the project-review workflow for code review independent of the git diff. The scope is parsed from the user instruction: 全面/整个项目 -> whole-project (score every source file), otherwise feature + target keyword (locate the code with semantic search + graph queries). - scoring_tools.py: score_review_func gains all_files=True to score every source file in the graph via store.get_all_files() - main.py: score_review_tool gains all_files param; registers the project_review MCP prompt (prompts 6->7) - prompts.py: project_review_prompt(scope, target) with whole-project and feature branches (fixed a precedence bug that truncated the feature text) - skills.py + skills/project-review/: new read-only project-review skill with shared checklists - .opencode/command/code-review-graph-project-review.md: slash command - tests: test_project_review.py (prompt rendering), TestProjectReviewPrompt, skill count assertions 5->6, all_files wiring checks - docs: prompts (6->7) + project-review entries across COMMANDS, CLAUDE, README (+localized), INDEX, architecture, LLM-OPTIMIZED-REFERENCE, CHANGELOG
18 lines
742 B
Markdown
18 lines
742 B
Markdown
# Security Specialist
|
|
|
|
Focus: security vulnerabilities in the diff.
|
|
|
|
- [ ] SQL injection (string interpolation, parameterized queries)
|
|
- [ ] AuthN/AuthZ bypasses, missing permission checks
|
|
- [ ] XSS (unsafe HTML rendering on user data)
|
|
- [ ] Sensitive data exposure / missing masking in logs and responses
|
|
- [ ] SSRF (fetching user/LLM-controlled URLs without allowlist)
|
|
- [ ] Command injection (`shell=True` + interpolation)
|
|
- [ ] Hardcoded secrets / credentials
|
|
- [ ] CSRF / missing rate limiting on auth endpoints
|
|
|
|
Insurance specialist — always runs, even when silent.
|
|
|
|
Output JSON lines:
|
|
`{"severity":"CRITICAL|INFORMATIONAL","confidence":N,"path":"file","line":N,"category":"security","summary":"...","fix":"...","source":"security"}`
|