Loading...
Loading...
Compare original and translation side by side
Python 3.10+
pip install medusa-securitypython -m medusa --versionPython 3.10+
pip install medusa-securitypython -m medusa --versionundefinedundefinedundefinedundefinedmedusa scan . --format sarif --ai-onlymedusa scan . --format sarif --ai-onlymedusa scan . --format sarif --quickmedusa scan . --format sarif --quickundefinedundefinedundefinedundefined.claude/skills/medusa-security/scripts/| Script | Purpose |
|---|---|
| Parses SARIF v2.1.0 output |
| Parses Medusa JSON output |
| Formats findings with OWASP mapping |
| Orchestrates the full pipeline |
| Wraps Medusa CLI invocation |
| Deterministic report writer (no Glob recursion) |
.claude/skills/medusa-security/scripts/| 脚本名称 | 用途 |
|---|---|
| 解析SARIF v2.1.0输出格式 |
| 解析Medusa原生JSON输出格式 |
| 为检测结果添加OWASP映射信息并格式化 |
| 编排完整的扫描处理流程 |
| 封装Medusa CLI调用逻辑 |
| 生成确定性报告(避免Glob递归超时) |
undefinedundefinedundefinedundefinedGlobnode .claude/skills/medusa-security/scripts/security-review.cjs/.claude/context/reports/security-review-medusa-scan-2026-02-17.md.claude/hooks/.claude/lib/.claude/skills/medusa-security/scripts/.claude/CLAUDE.mdGlobnode .claude/skills/medusa-security/scripts/security-review.cjs/.claude/context/reports/security-review-medusa-scan-2026-02-17.md.claude/hooks/.claude/lib/.claude/skills/medusa-security/scripts/.claude/CLAUDE.md.claude/skills/medusa-security/**/*.claude/skills/medusa-security/**/*| Severity | Action | Timeline |
|---|---|---|
| CRITICAL | Immediate fix | Before any merge |
| HIGH | Fix before release | Same sprint |
| MEDIUM | Fix in next sprint | Next cycle |
| LOW | Track and address | Backlog |
| 严重程度 | 处理措施 | 时间要求 |
|---|---|---|
| CRITICAL | 立即修复 | 合并代码前完成 |
| HIGH | 发布前修复 | 同一迭代内完成 |
| MEDIUM | 下一个迭代修复 | 下一周期内完成 |
| LOW | 跟踪并处理 | 放入待办清单 |
| Agent | Usage |
|---|---|
| Primary consumer. Use for comprehensive security reviews. |
| Use for targeted vulnerability scanning with authorization. |
| Use AI-only scan as part of code review workflow. |
| Agent名称 | 用途说明 |
|---|---|
| 主要使用者,用于全面安全评审。 |
| 用于授权后的定向漏洞扫描。 |
| 将仅AI扫描作为代码评审流程的一部分。 |
undefinedundefinedundefinedundefinedpatterns.jsonissues.mdrecordGotcha()const manager = require('.claude/lib/memory/memory-manager.cjs');
manager.recordGotcha({
text: 'False positive: medusa flags X pattern in Y context',
area: 'security-scanning',
});
manager.recordPattern({
text: 'Prompt injection found in CLAUDE.md context files',
area: 'ai-security',
});patterns.jsonissues.mdrecordGotcha()const manager = require('.claude/lib/memory/memory-manager.cjs');
manager.recordGotcha({
text: 'False positive: medusa flags X pattern in Y context',
area: 'security-scanning',
});
manager.recordPattern({
text: 'Prompt injection found in CLAUDE.md context files',
area: 'ai-security',
});security-architectstatic-analysissemgrep-rule-creatorinsecure-defaultsvariant-analysissecurity-architectstatic-analysissemgrep-rule-creatorinsecure-defaultsvariant-analysis