supercorp-ai

supercov-security Skill

使用 supercov CLI 扫描仓库源代码中的安全漏洞,定位每个发现的具体代码行并映射到 CWE 类别。当用户要求安全扫描或审计、询问代码是否安全,或想查找漏洞、注入、硬编码密钥等不安全代码时使用。

安装方式:把技能目录放入 ~/.claude/skills/(Claude Code)或在 claude.ai 设置中启用;也可复制右侧安装命令一键添加。

查看源码

技能指令原文(SKILL.md)

Supercov security

Run npx supercov security for the whole repository, or npx supercov security patch for what a change introduced. It checks every source file for twelve named risks and points to the line. npx supercov docs security prints the guide for the installed version.

It sends source files to TypeSafe using the TYPESAFE_API_KEY environment variable. A user who set the key has opted in, so run it without asking again. If the key is missing the command says so: tell the user how to set it, then review the code by hand and say Supercov did not check it.