feat: add opencode agents and skills for development workflows
New agents: - architect: system design, module interactions, data flow - debugger: crash/memory/thread debugging with ASan, TSan, valgrind, gdb - security-auditor: TLS, input validation, buffer safety, crypto audit - refactorer: DRY, separation of concerns, API simplification - integrator: integration tests, CI/CD pipeline, end-to-end verification - code-explainer: architecture walkthrough, code explanation New skills: - debug-workflow: structured debugging workflow - refactor: code restructuring with test verification - security-audit: full security review with checklist - benchmark: performance benchmarking with multi-run medians - release: version bump, tests, tagging Improved existing: - c-reviewer: added security checklist - cmake-expert: added ASan/TSan/UBSan configs, ccache, cross-compilation - perf-analyst: added perf/valgrind/gprof commands - test-writer: added fuzzing harnesses, integration test patterns - pr-build: added sanitizer build variants - pr-review: added security review, performance impact assessment
This commit is contained in:
@@ -69,12 +69,29 @@ For each changed file, review for:
|
||||
- Functions return appropriate error values
|
||||
- Error messages are useful
|
||||
|
||||
**Security**
|
||||
- No `strcpy`/`strcat`/`sprintf` — use `snprintf` with bounds
|
||||
- `malloc` size calculations don't overflow
|
||||
- Path traversal prevention (`..` in filenames)
|
||||
- No fixed-size stack buffers for unbounded input
|
||||
- TLS error codes checked after `SSL_read`/`SSL_write`
|
||||
- No hardcoded certificates, keys, or credentials
|
||||
- Received file permissions validated (no SUID/SGID injection)
|
||||
- Denial of service: bounded memory, malformed messages handled
|
||||
|
||||
**Performance Impact**
|
||||
- Unnecessary memory copies in hot paths
|
||||
- Excessive malloc/free in tight loops
|
||||
- Missing `sendfile()` opportunity for large files
|
||||
- Compression level appropriate for use case
|
||||
- Queue sizing appropriate for workload
|
||||
|
||||
### Step 5: Categorize findings
|
||||
|
||||
For each issue:
|
||||
1. **File:line** — exact location
|
||||
2. **Severity** — critical / warning / style
|
||||
3. **Category** — memory / thread / protocol / logic / error
|
||||
3. **Category** — memory / thread / protocol / security / performance / logic / error
|
||||
4. **Description** — what's wrong and how to fix it
|
||||
|
||||
### Step 6: Output report
|
||||
|
||||
Reference in New Issue
Block a user