本卡屬 FR-120(母卡待填)。這一棒掃主專案自己程式的「流程背景作業」(8 檔/1716 行)。只掃不修。

這一棒在做什麼(白話)

用資安掃描工具掃 BE repo 自己寫的「流程背景作業」這塊程式(8 檔,約 1716 行),找出權限檢查、資料歸屬判斷上的漏洞並產出報告。只找問題、不修問題。

為什麼切這一塊

🔴 優先序第 8:用原生 SQL 直接寫五張沒有客戶隔離、沒開資料庫保護的表。

重點看什麼

這些是首腦讀過盤點檔與程式碼後認為最容易出事的地方,是思考起點不是檢查清單:

已知背景

本範圍從未被任何一棒正式掃過。U7 ↔ U8 接縫同 U7 卡說明。

怎麼做

第一步:讀完本卡與母卡,再讀盤點檔 docs/features/FR-119-2609-security-scan-closeout/scan-inventory.md 對應本棒段落。

第二步:驗 scope 檔數,在 BE repo 跑下面指令,對上 8 檔/1716 行 才往下;對不上停下回報。

cd /Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-be && git ls-files -- \
  core/scheduler.py \
  app/flow_control/service/workflow_xml_sync_service.py \
  app/flow_control/service/job_binding_orphan_cleanup_service.py \
  infra/flow_control/repository/job_binding_orphan_query.py \
  app/flow_control/service/reverify_inheritance_service.py \
  infra/flow_control/repository/reverify_clone_query.py \
  infra/flow_control/repository/task_execution_query.py \
  infra/flow_control/task_existence_query.py | xargs wc -l | tail -1   # 8 檔、1716 行

第三步:把啟動指令交給決策者(你不能自己啟動)。/claude-security 帶 disable-model-invocation: true,模型用 Skill tool 叫會被直接擋掉;也不可以自己叫 Workflow、不可以自己派研究員/verifier 拼報告——三人面板的票數是工具程式碼算出來的,報告的驗證章就蓋在那個數字上。這是刻意設計,撞到不要 debug、不要找繞路。兩行要當同一則訊息送出,第二行不能省(省了會停在成本確認題):

/claude-security scan codebase at /Users/chouraymond/Projects/Billows/Audit-Manager/compliance-manager-be --scope core/scheduler.py,app/flow_control/service/workflow_xml_sync_service.py,app/flow_control/service/job_binding_orphan_cleanup_service.py,infra/flow_control/repository/job_binding_orphan_query.py,app/flow_control/service/reverify_inheritance_service.py,infra/flow_control/repository/reverify_clone_query.py,infra/flow_control/repository/task_execution_query.py,infra/flow_control/task_existence_query.py --effort low
I understand this may take a while and use a significant number of tokens.