Skip to content

feesec/SecurityPrompt

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

1 Commit
 
 
 
 
 
 
 
 

Repository files navigation

SecurityPrompt

中文 | English

中文介绍

本项目包含一系列用于安全审计、代码审查和渗透测试的系统提示词(System Prompts)和指南。旨在辅助安全研究人员、工程师以及 AI 模型进行标准化的安全评估。

内容列表

1. 代码安全审查 (Code Review Audit)

  • 文件: code_review_audit.md
  • 描述: 扮演高级安全工程师的角色,对代码项目进行专注于安全性的审查。
  • 重点: 识别高置信度的安全漏洞,减少误报,关注实际可利用的影响(如注入、鉴权问题、敏感数据泄露等)。

2. 智能合约审计 (Smart Contract Audit)

  • 文件: Smartcontract_audit.md
  • 描述: 针对智能合约的漏洞评估挑战指南。
  • 重点: 在有限时间内分析合约逻辑,识别并利用漏洞(如获取 BNB),涵盖分析、利用开发和测试验证流程。

3. Web 应用渗透测试 (Web Application Pentest)

  • 文件: web_application_pentest.md
  • 描述: 扮演经验丰富的 Web 应用渗透测试人员的角色。
  • 重点: 执行道德的 Web 应用和 API 渗透测试,涵盖侦察、威胁建模、漏洞验证及报告生成。

使用说明

这些 Markdown 文件可以作为 LLM(大语言模型)的 System Prompt 或 Context 输入,引导模型以特定的专家角色执行安全任务。


English Introduction

This project contains a collection of System Prompts and guidelines for security audits, code reviews, and penetration testing. It aims to assist security researchers, engineers, and AI models in conducting standardized security assessments.

Contents

1. Code Review Audit

  • File: code_review_audit.md
  • Description: Acts as a senior security engineer conducting a security-focused review of a code project.
  • Focus: Identifying high-confidence security vulnerabilities, minimizing false positives, and focusing on actual exploitable impacts (e.g., injection, authentication issues, sensitive data leakage, etc.).

2. Smart Contract Audit

  • File: Smartcontract_audit.md
  • Description: A guideline for smart contract vulnerability assessment challenges.
  • Focus: Analyzing contract logic within a limited timeframe, identifying and exploiting vulnerabilities (e.g., obtaining BNB), covering analysis, exploit development, and test validation processes.

3. Web Application Pentest

  • File: web_application_pentest.md
  • Description: Acts as an experienced Web application penetration tester.
  • Focus: Performing ethical Web application and API penetration testing, covering reconnaissance, threat modeling, vulnerability validation, and report generation.

Usage

These Markdown files can be used as System Prompts or Context input for LLMs (Large Language Models) to guide the model in performing security tasks with specific expert roles.

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published