Files
FastSync/.opencode/skills/security-audit/SKILL.md
T
TapTap 5c8970c64f
CI / lint (pull_request) Successful in 1m29s
CI / sanitizers (address) (pull_request) Skipped
CI / sanitizers (undefined) (pull_request) Skipped
CI / fuzz-build (pull_request) Skipped
CI / coverage (pull_request) Skipped
CI / valgrind (pull_request) Skipped
CI / build-and-test (pull_request) Successful in 1m45s
chore(opencode): fix drifted agent/skill docs and repo hygiene
The agent and skill definitions had drifted badly from the current
codebase and tooling, repeating the same class of bug as the benchmark
tool (references to nonexistent scripts and invented flags):

- Replace the removed `python3 test.py` with the real integration
  command (`python3 -m pytest tests/integration/ -n 4 --dist=load
  -m "not setpriv"`) across agents and skills.
- Fix `feature-scout`'s fabricated CLI flag list (--host, --server-mode,
  --use-* etc.) using the authoritative src/client/usage.c flags.
- Fix `perf-analyst` benchmark flags (-m -c -> -j -z) and point at
  benchmark/bench.py instead of stale numbers.
- Correct `code-explainer` (no getopt_long; --sendfile not -f) and
  version drift in the release skill (1.1.0 -> 2.20.0).
- Replace GitHub/`gh` workflows with Gitea/`tea` (PRs target dev; issues
  via tea; branch strategy updated in all agents).
- Use the built-in `-DSANITIZER=address|thread` CMake option instead of
  hand-rolled -fsanitize flags.
- Add `-p 8080 --allow-unauthenticated` to plain-TCP server examples.
- Merge the redundant security-screener into security-auditor; drop the
  duplicate (16 agents remain).

Repo hygiene: gitignore `root/` and `test_partial_install_tmp/`, remove
the empty leftover trees, delete the tracked scratch scripts tmux.sh and
to_one_file.py, and note the compile_commands.json symlink in README.
2026-09-13 10:34:59 +02:00

3.4 KiB

name, description
name description
security-audit Performs a security audit of FastSync — checks TLS config, input validation, buffer safety, crypto hygiene, and network attack surface. Use when the user says "security audit", "check security", "harden", or wants a security review.

Security Audit Skill

Read-only security review of the FastSync codebase or specific modules. Produces a report — does NOT edit files.

Workflow

Step 1: Scope the Audit

Determine what to audit:

  • Full codebase audit
  • Specific module (e.g., transport_tls.c, protocol.c)
  • Specific vulnerability class (e.g., buffer overflows, TLS misconfig)

Step 2: Identify Attack Surface

Network input points:

src/server/server.c          — TCP accept, per-connection handling
src/shared/protocol.c        — all wire protocol parsing
src/shared/config.c          — config deserialization
src/shared/chunk.c           — chunk deserialization
src/shared/transport_tls.c   — TLS handshake and data
src/shared/transport_ssh.c   — SSH data via stdio

Step 3: Read All Relevant Files

Read every file in scope completely. Focus on:

  • All receive_* calls and their validation
  • All malloc/calloc calls and their size calculations
  • All string operations (strcpy, sprintf, snprintf)
  • All path operations (filename handling, directory creation)
  • All TLS/SSL operations and error handling

Step 4: Apply Security Checklist

Input Validation

  • All receive_* return values checked
  • Received size fields validated against bounds
  • Path traversal prevention (.. in filenames)
  • Null bytes in filenames handled
  • Chunk/file counts validated before allocation

Buffer Safety

  • No strcpy — use snprintf
  • malloc size calculations don't overflow
  • No fixed-size stack buffers for unbounded input
  • Off-by-one in path concatenation

TLS/SSL

  • TLS 1.2 minimum enforced
  • Certificate verification when CA provided
  • SSL error codes checked after SSL_read/SSL_write
  • No hardcoded certificates/keys
  • Strong cipher suites only

Memory Safety in Error Paths

  • All error paths free allocated resources
  • No use-after-free on error paths
  • Partial reads handled

Denial of Service

  • Bounded memory allocation
  • Timeout on connections
  • Malformed messages handled gracefully

Step 5: Check for Common Vulnerabilities

# Grep for dangerous patterns
grep -rn "strcpy\|strcat\|sprintf" src/
grep -rn "malloc.*\*" src/  # potential integer overflow in size calc
grep -rn "receive_n_data" src/  # check all return values
grep -rn "NULL" src/ | grep -v "//"  # check null handling

Step 6: Output Report

=== SECURITY AUDIT SUMMARY ===
Scope: <what was audited>
Files reviewed: <count>

Critical: <count>
High: <count>
Medium: <count>
Low: <count>
Informational: <count>

=== FINDINGS ===

[1] <file:line> — CRITICAL (<category>)
    Description: <what's wrong>
    Exploit scenario: <how it could be triggered>
    Fix: <concrete code change>

...

=== VERDICT ===
[PASS] No critical/high-severity issues found
  — or —
[FAIL] <N> critical/high-severity issues must be fixed

Rules

  • Do NOT edit any source files
  • Do NOT run builds or tests
  • Report ALL issues — don't filter or minimize
  • Be specific about line numbers and fix suggestions
  • Consider both remote and local attack vectors