Skip to content

Repository files navigation

About

These tools are used by Cybersecurity operations teams at the University of Illinois to help assess security risks in code.

This resource helps comply with University of Illinois Cybersecurity standards - including IT-07, IT08, and IT13.

See Cybersecurity Development on the Illinois Knowledge Base for information about our development standards.

Tools

Cybersecurity Review

  • The Cybersecurity Development team at the University of Illinois maintains these AI "skills", /code-risk and /code-cost for identifying possible vulnerabilities and maintenance costs in local source code.
  • We update this AI "skill" after OWASP updates the OWASP Top Ten, roughly every four years.
  • This "skill" is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle.
    • We consider this skill suitable for exploration and education.
    • We want to help interpret and respond to these reports - they can be confusing, may contain false positives, and will raise questions.
  • We recommend also requesting a Code Risk Discussion engagement for more sensitive code, as we find that Code Risk Discussions catch issues that these "skills" cannot.
  • Campus faculty and staff responsible for custom code supporting campus users can contact securitysupport@illinois.edu for assistance.

Installation

gh skill install techservicesillinois/secdev-code-risk-tools

Then follow the interactive prompts to choose between the available skills, where they should be available, and for which AI engines.

Data Sources

For data sensitivity, see Data Classification.

Data Store Data Type Sensitivity Notes
Report Files Descriptions of Code Risks Detected Sensitive - May contain detected vulnerabilities in a live system. Developers are encouraged to treat reports files as Traffic Light Protocol:Amber
Your AI Agent Training AI Approved for Campus Use should not train on your source code. Other AI may train on files you allow it to access. Sensitive Non-public source code may be Sensitive, and should only be shared with approved AI.

Endpoint Connections

Endpoint Purpose Stage Access Contact
Your AI Agent Applies these patterns to your code to produce reports. Development Reads your code and environment Your AI Agent Vendor
OWASP Web Resources Your agent may access OWASP resources from the OWASP web site to help analyze your code. Development Read https://owasp.org/projects/top-ten

Product Support

Only the latest version of this product is supported by Cybersecurity teams at the University of Illinois Urbana-Champaign on a best-effort basis.

As of the last update to this README, the expected End-of-Life and End-of-Support dates of this product are January 2029.

  • OWASP updates the Top Ten every four years. Next expected is in 2029.
  • Success with these tools will vary by AI tool.

About

Tools for University of Illinois developers to explore risk in their code bases

Resources

Code of conduct

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages