eni-code-security-workflow
SkillDocs & knowledge[DOCUMENTATION ONLY] [仅文档] Source, dependency, supply-chain, SAST, SCA, and remediation workflow for operator-owned repositories.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the eni-code-security-workflow skill
What this skill tells your AI
The instructions your AI receives, as published by alicewe1/alice_skill in _modules/eni-code-security-workflow/SKILL.md and read by ahel’s review.
仅文档:本 Skill 提供方法与检查表,不宣称自带可执行脚本。
Code Security Workflow
Build a language and dependency inventory. Threat-model entry points. Combine Semgrep-style pattern scans, OSV dependency matching, Trivy-style SBOM and configuration review, and manual data-flow validation. Reproduce each finding, fix a copy or branch, and add regression tests.
Persist checkpoints before long runs. Record commands, versions, hashes, evidence paths, assumptions, and verification results. Chain through eni-universal-workflow and finish with delivery.
Signals
- GitHub stars
- 26
- Forks
- 4
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
eni-code-security-workflow- Source
- github.com/alicewe1/alice_skill