Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 5 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,13 @@ for information about our development standards.

### Cybersecurity Review

- SecDev maintains an AI "skill", `/cybersecurity-review` for identifying vulnerabilities in local source code.
- We update this AI skill after OWASP updates the OWASP Top Ten, roughly every four years.
- This skill is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle.
- The Cybersecurity Development team at the University of Illinois maintains these AI "skills", `/code-risk` and `/code-cost` for identifying possible vulnerabilities and maintenance costs in local source code.
- We update this AI "skill" after OWASP updates the OWASP Top Ten, roughly every four years.
- This "skill" is intended to guide remediation efforts and is not a substitute for a mature Software Development Lifecycle.
- We consider this skill suitable for exploration and education.
- We want to help interpret and respond to these reports - they can be confusing, may contain false positives, and will raise questions.
- Campus IT Professionals can contact securitysupport@illinois.edu.
- We recommend also requesting a [Code Risk Discussion](https://answers.uillinois.edu/illinois/106153) engagement for more sensitive code, as we find that Code Risk Discussions catch issues that these "skills" cannot.
- Campus faculty and staff responsible for custom code supporting campus users can contact securitysupport@illinois.edu for assistance.

## Installation

Expand Down
Loading