Code Auditor

👤 unixlamadev-spec 📦 v1.1.0 ⭐ 4.0 ⬇️ 1K 下载
💻 开发编程 免费 🔑 需 API Key

📖 技能介绍


name: code-auditor description: Audit any GitHub repo or raw code for security, quality, or gas optimization. Returns score, findings, severity counts, and summary. acceptLicenseTerms: true metadata: clawdbot: emoji: "🔍" homepage: https://aiprox.dev requires: env: - AIPROX_SPEND_TOKEN


Code Auditor

Audit any GitHub repository or raw code for security vulnerabilities, code quality issues, and best practices. Supports targeted audits by focus area. Returns a score, severity-scored findings, and actionable summary.

When to Use

  • Security review before deploying code
  • Evaluating third-party dependencies or libraries
  • Code quality assessment for repositories
  • Solidity/smart contract gas optimization
  • Finding vulnerabilities in open source projects

Usage Flow

  1. Provide a GitHub repo URL or paste raw code directly

    小葱技能站7w4.net每天更新,海量AI技能等你发现。

  2. Optionally specify a focus: security, quality, or gas (default: full audit)
  3. AIProx routes to the code-auditor agent
  4. Returns score (0-100), findings array with severity levels, severity counts, and summary

Security Manifest

Permission Scope Reason
Network aiprox.dev API calls to orchestration endpoint
Env Read AIPROX_SPEND_TOKEN Authentication for paid API

Make Request

curl -X POST https://aiprox.dev/api/orchestrate \
  -H "Content-Type: application/json" \
  -H "X-Spend-Token: $AIPROX_SPEND_TOKEN" \
  -d '{
    "task": "security audit",
    "repo_url": "https://github.com/user/repo",
    "focus": "security"
  }'

Response

{
  "score": 72,
  "findings": [
    {"severity": "critical", "file": "config.js", "line": "12", "issue": "Hardcoded API key", "fix": "Move to environment variable"},
    {"severity": "high", "file": "handler.js", "line": "45", "issue": "No input validation on user-supplied data", "fix": "Validate and sanitize inputs"}
  ],
  "severity_counts": {"critical": 1, "high": 2, "medium": 3, "low": 1},
  "summary": "Repository has moderate security concerns. Critical: 1 hardcoded secret. High: missing input validation. Recommend immediate remediation."
}

Trust Statement

Code Auditor analyzes public repository contents or provided code only. No code is executed. Analysis is performed by Claude via LightningProx. Your spend token is used for payment; no other credentials are stored or transmitted.

🤖 AI 评测

这个代码审计工具质量中等偏上,胜在简单易用——只需提供仓库地址就能快速获得安全漏洞和代码质量评分。但它本质上是个 API 转发器,完全依赖外部服务,一旦网络或服务不稳定就无法使用。虽然日常轻度使用足够,但如果你需要更可靠、更深入的审计保障,建议考虑有本地处理能力的替代方案。

📊 多维度评分

适应性4.3
规范性3.9
有效性4.3
可靠性3.7
可信度4.3

📁 包含文件 (2 个)

📄 SKILL.md 2.4 KB
📄 _meta.json 131 B