Use when / 当用户请求 code/AppSec audit:source/sink、taint、Web/API/GraphQL/OAuth、CSP/CORS/Cookie、LLM prompt injection、access control/authorization bypass、SSRF/XSS/SQLi、backdoor/Webshell、security regression。仅限授权范围。手动触发:使用 coff0xc-secure-code-appsec。
$npx -y skills add coff0xc/coffee-skill --skill coff0xc-secure-code-appsecInstalls into the current project.
Run `npx skills use "https://github.com/coff0xc/coffee-skill" --skill "coff0xc/coffee-skill/coff0xc-secure-code-appsec"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/coff0xc/coffee-skill" that are relevant to the current task. Run `npx skills add "https://github.com/coff0xc/coffee-skill"` and select the relevant skills, then follow their instructions.