AgentStack
SKILL verified MIT Self-run

Omv Audit

skill-bx33661-oh-my-vul-omv-audit · by bx33661

|

No reviews yet
0 installs
8 views
0.0% view→install

Install

$ agentstack add skill-bx33661-oh-my-vul-omv-audit

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Omv Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

omv-audit

深度审计一个 candidate 漏洞发现,填充 Evidence.v1 文件,为 /omv-report 做好准备。

Stay in passive research mode: read public source code only. Do not send requests to live services, do not auto-execute PoC code. Local analysis, static reasoning, and local test descriptions are allowed.

Invocation

/omv-audit  [--force]
  • ` 对应 .omv/findings/.yaml` 文件
  • --force 允许重新审计已为 confirmed/blocked 的文件

Reference Loading

按需加载,不要一次性全读:

  • 审计方法论与置信度框架:references/audit-playbook.md
  • CVSS v3.1 度量决策表:references/shared/cvss-builder.md
  • 生态系统 sink registry(npm/Python/Go/Rust/Java/Ruby):references/patterns/npm.md 等同目录文件
  • Evidence.v1 字段定义与 evidence/submission 评分规则:contracts/evidence.v1.yaml
  • ThreatMap.v1 图证据字段:contracts/threat-map.v1.yaml
  • Verification.v1 对抗复核 sidecar:contracts/verification.v1.yaml

审计目标

读取 .omv/findings/.yaml 后,你的目标是将以下字段填写为具体、可验证的值(非 unknown):

必填(confirmed 所需)

  • versions.tested — 实际测试的版本号
  • evidence.source — 攻击者可控的输入入口(含 file:line)
  • evidence.sink — 危险操作(含 file:line)
  • evidence.guard — 缺失或可绕过的防御(含 file:line 或"不存在"的说明)
  • evidence.reproducer — 本地复现步骤描述
  • evidence.observed_result — 本地运行后实际观测到的结果(若 passive 模式无法在本地执行,保留 unknown,在 provenance.unverified_fields 中列出,交由 /omv-repro 完成)
  • cvss.vector / cvss.score / cvss.severity
  • dedup.* — NVD/GHSA/生态系统数据库检索结果
  • verdict.* — 当前可利用性判断(proven|plausible|blocked|disproven)、置信度和原因

如何达到目标,由你自主决定。 根据 finding 的实际情况——漏洞类别、已有线索、代码结构——自主选择切入点、阅读哪些文件、花多少精力在每个环节。参考 references/audit-playbook.md 获取思维框架,但不要把它当作执行脚本。

如果 finding 属于 npm、Python、Go、Rust、Java 或 Ruby,按需加载 references/patterns/ 下对应生态文件,用其中的 source pattern、sink signature、expected guard、evidence criteria、false-positive checks 和 CWE 映射辅助判断。Pattern registry 是方法论,不是真实漏洞案例库;不要加载无关生态 registry。

当证据链足够清楚时,生成可选 ThreatMap.v1 sidecar,记录 source → transform → sink 的 dataflow 路径:

omv threat-map init 

这会在 .omv/threatmaps/.yaml 生成骨架(finding_idpackage 块已从 finding 填好,paths: [] 留待填写)。然后在每个已确认的 source → sink 路径下补一条 paths[] 条目:source(type/location/description)、transforms[](中间每一步:parse/decode/normalize/validate/authorize)、sinkguard(present/bypassable)、confidence。Schema 见 contracts/threat-map.v1.yaml。ThreatMap 是 Evidence.v1 的补充,不替代 evidence.source / evidence.sink / evidence.guard 摘要字段;sidecar 不修改父 Evidence.v1 文件。填写后运行 omv threat-map validate

如果进行了 verifier 对抗复核,先运行 omv verification init ,再把 verifier 的结论写入 .omv/verifications/.yaml:同意则 decision.status: pass;找到反证则 decision.status: fail 并填写 disagreements / required_changes。写完运行 omv verification validate 。不要只把 verifier 结论留在聊天记录里。

解释审计结论时使用方法论语言:说明输入如何到达 sink、guard 为什么缺失或可绕过、哪些证据仍不充分。除非用户提供真实 finding 作为上下文,否则不要把真实包或真实 CVE 当作教程示例。

约束边界

以下是硬约束,不可逾越:

  1. 不攻击线上服务 — 所有分析基于公开源代码和本地环境
  2. 不自动执行 PoCevidence.reproducer 只写步骤描述,不自动运行
  3. **submission score 返回 OK 时,才允许把结论作为 confirmed 交给 /omv-report`

Subagent Team Orchestration

本 skill 支持 Claude Code subagent 编排。你在审计流程中可以显式委托给专门的 subagent 角色,让它们在独立的 context 里并行或串行完成子任务:

# 数据流分析 → 交给 dataflow-tracer subagent(2-5 个文件静态分析)
Use the dataflow-tracer subagent to analyze: [finding_id], [package_url], [vuln_class]

# Guard 可绕过性评估 → 交给 guard-checker subagent(独立 context + bypass-bias)
Use the guard-checker subagent to evaluate whether the guard at [file:line] is bypassable

# CVSS 评分 → 交给 cvss-analyst subagent(纯推理,无网络访问)
Use the cvss-analyst subagent to compute CVSS for: [vuln_class], [impact_fields]

# 去重检索 → 交给 dedup-analyst subagent(WebSearch + WebFetch)
Use the dedup-analyst subagent to check duplicates for: [ecosystem], [package], [vuln_class]

# 对抗复核 → 交给 verifier subagent(默认反驳 bias),并写入 Verification.v1
Use the verifier subagent to refute the dataflow-tracer's conclusion for: [finding_id], then record the result in .omv/verifications/.yaml

推荐编排序列(全量审计)

stage 1: dataflow-tracer    → {source, sink, guard_note}
stage 2: guard-checker      → {bypassable, method}(仅在 guard 存在时调)
stage 3: dedup-analyst      → {dedup 状态}(与 stage 1 并行)
stage 4: cvss-analyst       → {vector, score, severity}
stage 5: verifier           → 对抗复核 source→sink 链,输出 Verification.v1 review
stage 6: synthesize         → 汇聚后写 Evidence.v1 + ThreatMap.v1 + Verification.v1

编排决策规则:已知的字段跳过对应阶段(例如 dedup 已 searched 则跳过 stage 3;cvss 已填则跳过 stage 4)。Subagent 调用是建议而非强制——你可以在单 context 内完成全部审计或用 subagent 协助部分环节,取决于 finding 复杂度和你的判断。无论是否使用 subagent,只要做了对抗复核,结论都必须记录到 Verification.v1 sidecar。

Subagent 定义位置

每个 subagent 的定义文件在 .claude/agents/ 目录,frontmatter 声明了 tools 白名单、model、以及行为描述。Claude Code 根据描述自动将自然语言委托请求路由到正确的 subagent。

以下是硬约束,不可逾越:

  1. 不攻击线上服务 — 所有分析基于公开源代码和本地环境
  2. 不自动执行 PoCevidence.reproducer 只写步骤描述,不自动运行
  3. **submission score 返回 OK 时,才允许把结论作为 confirmed 交给 /omv-report`

结论规则

审计结束后根据证据完整性选择结论:

| 结论 | 触发条件 | 下一步 | |---|---|---| | confirmed | 五项 source/sink/guard/reproducer/result 全部已知,submission score ≥ 75 | 运行 omv findings validate ,提示用户运行 /omv-report | | blocked | 证据链断裂,或发现疑似重复 CVE,或无法本地复现 | 填写 blockers,运行 omv findings validate (预期 FAIL) | | candidate(保留) | 部分字段已填但 submission score 不足;或 observed_result 为 unknown 但其他字段已填 | 展示缺失项清单;若仅缺 observed_result,提示运行 /omv-repro |

同时更新 verdict

  • 已本地证明可利用:exploitability: provenconfidence: high|medium
  • 证据链合理但未复现:exploitability: plausibleconfidence: medium|low
  • 默认防护、环境前置或证据断裂阻止利用:exploitability: blocked
  • 审计证明不是漏洞:exploitability: disproven

如果尝试 confirmed 但 CLI validation 失败,必须保持或恢复为 candidate,逐条展示 validation errors,不得提示用户提交报告。

审计结束时始终运行:

omv findings validate 

然后运行或建议:

omv findings workflow

如本轮做出关键判断(确认 source -> sink、发现 guard 缺失、判定重复或 blocked),在 .omv/notes/.md 追加一条时间戳决策记录。不要把 notebook 内容写入 Evidence.v1。

Use the CLI result for lifecycle handoff:

  • If the finding remains candidate because only evidence.observed_result is missing, tell the user to run /omv-repro .
  • If the finding is confirmed and validation returns OK, tell the user to run /omv-report .
  • If the finding is blocked, tell the user to review blockers and optionally run omv findings archive --reason blocked.

Deterministic Helpers

  • omv findings validate — 校验字段完整性,输出 evidence/submission 分数
  • omv findings promote --status confirmed|blocked — 更新 status 字段
  • omv threat-map init — 生成 .omv/threatmaps/.yaml ThreatMap.v1 dataflow 骨架
  • omv threat-map validate — 校验 ThreatMap.v1 图证据和 Evidence 摘要一致性
  • omv verification init — 生成 .omv/verifications/.yaml Verification.v1 对抗复核骨架
  • omv verification validate — 校验 Verification.v1 和 Evidence hash 是否过期
  • omv findings workflow — 显示 active findings 的下一步动作
  • python3 shared/scripts/resolve_source_path.py --ecosystem npm --pkg — 获取源文件 raw URL
  • python3 shared/scripts/collect_metadata.py --repo — 获取仓库元数据

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.