Compliance 代码审查
- 作者仓库星标 1
- 作者仓库 claude-skills
Compliance Evidence Collector
Overview
Gather code, config, docs, and operational proof points for audits and internal compliance reviews.
Core Workflow
- Survey the relevant files, configs, runtime signals, or artifacts to identify the important components and boundaries.
- Map the relationships, dependencies, or graph structure that explain how the system or corpus fits together.
- Highlight missing links, risky assumptions, or ambiguous edges that affect understanding or change safety.
- Return a concise map plus the next best checks or follow-up actions.
Deliver
- A structured map of components, dependencies, or graph relationships.
- The highest-risk gaps, missing links, or ambiguous edges.
- Concrete next checks or actions based on the mapped structure.
Guardrails
- Do not infer strong relationships without evidence from code, config, or runtime artifacts.
- Separate confirmed connections from plausible but unverified ones.
- Prefer a smaller high-confidence map over a speculative complete one.
- Do not invent metrics, policy decisions, customer commitments, or ownership that the inputs do not support.
- 流狐分类
- 安全
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 88 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @00PrabalK00 · 未声明 license
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 即装即用
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- 未声明
- 底层运行要求
- 未声明
- 检测到的文件与系统行为
-
- 只读
- 检测到的网络行为
- 仅限本地
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Gather code, config, docs, and operational proof points for audits and internal compliance reviews.
Survey the relevant files, configs, runtime signals, or artifacts to identify the important components and boundaries. Map the relationships, dependencies, or graph structure that explain how the system or corpus fits together.
A structured map of components, dependencies, or graph relationships. The highest-risk gaps, missing links, or ambiguous edges. Concrete next checks or actions based on the mapped structure.
Do not infer strong relationships without evidence from code, config, or runtime artifacts. Separate confirmed connections from plausible but unverified ones. Prefer a smaller high-confidence map over a speculative complete one.
# Compliance Evidence Collector
## Overview
Gather code, config, docs, and operational proof points for audits and internal compliance reviews.
## Core Workflow
1. Survey the relevant files, configs, runtime signals, or artifacts to identify the important components and boundaries.
2. Map the relationships, dependencies, or graph structure that explain how the system or corpus fits together.
3. Highlight missing links, risky assumptions, or ambiguous edges that affect understanding or change safety.
4. Return a concise map plus the next best checks or follow-up actions.
## Deliver
- A structured map of components, dependencies, or graph relationships.
- The highest-risk gaps, missing links, or ambiguous edges.
- Concrete next checks or actions based on the mapped structure.
## Guardrails
- Do not infer strong relationships without evidence from code, config, or runtime artifacts.
- Separate confirmed connections from plausible but unverified ones.
- Prefer a smaller high-confidence map over a speculative complete one.
- Do not invent metrics, policy decisions, customer commitments, or ownership that the inputs do not support. 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> Overview → Core Workflow → Deliver → Guardrails
要点 -> Gather code, config, docs, and operational proof points for audits and internal compliance reviews. · 1. Survey the relevant files, configs, runtime signals, or artifacts to identify the important components and boundaries. · - A structured map of components, dependencies, or graph relationships. · - Do not infer strong relationships without evidence from code, config, or runtime artifacts.
文件/命令 -> 原文未列出明确文件或命令
内容 SHA-256 -> 15c37442d5eb
方法与流程
适用与边界
原文中的明确线索