选择你使用的 Agent
方法一:命令行安装(推荐)
推荐(无需提前安装 clawhub)
npx clawhub@latest --dir ~/.claude/skills install audit-code或使用 clawhub CLI(需提前安装)
clawhub --dir ~/.claude/skills install audit-code⚠️ 需要 Node.js 18+,没有 Node?请使用下方方法二直接下载 ZIP。 安装 Node.js →
方法二:手动下载安装(无需 Node)
下载 ZIP,解压后将文件夹放到以下路径,重启 Agent 即可:
安装路径
~/.claude/skills/audit-code/💡解压后将文件夹放到上方路径,重启 Agent 即可生效
--- name: audit-code description: Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities disable-model-invocation: true allowed-tools: Read, Glob, Grep, Bash context: fork ---
Security-focused code review of project source code. Covers OWASP-style vulnerabilities, hardcoded secrets, dangerous function calls, and patterns relevant to AI-assisted development.
Run the auditor against the target path:
python3 "$SKILL_DIR/scripts/audit_code.py" "$ARGUMENTS"
If $ARGUMENTS is empty, default to $PROJECT_ROOT.
Structured report with severity-ranked findings, file locations, and actionable remediation steps.
The repository's .claude/settings.json includes PreToolUse hooks that warn on dangerous Bash and Write operations. These hooks are advisory only -- they produce warnings but do not block execution.
{"decision": "block"}instead of warning messages
安装 审计守则 后,可以对 AI 说这些话来触发它
Help me get started with Audit Code
Explains what Audit Code does, walks through the setup, and runs a quick demo based on your current project
Use Audit Code to security-focused code review for hardcoded secrets, dangerous calls...
Invokes Audit Code with the right parameters and returns the result directly in the conversation
What can I do with Audit Code in my developer & devops workflow?
Lists the top use cases for Audit Code, with example commands for each scenario
将技能文件夹放到 ~/.claude/skills/audit-code/ 目录(个人级,所有项目可用),或 .claude/skills/audit-code/(项目级)。重启 AI 客户端后,用 /audit-code 主动调用,或让 AI 根据上下文自动发现并使用。
审计守则 支持 Claude、Cursor、OpenClaw,可与这些 AI 平台无缝集成,扩展其能力。
审计守则 可免费安装使用。请查阅仓库了解许可证信息。
针对硬编码机密、危险调用和常见漏洞进行以安全为中心的代码审查
审计守则 属于「Developer & DevOps」分类,该分类的技能帮助 AI 智能体在此领域执行专业任务。
Automate my developer & devops tasks using Audit Code
Identifies repetitive steps in your workflow and sets up Audit Code to handle them automatically