| name | commit-security-scan |
| description | Analyze code changes (commits, PRs, diffs) for security vulnerabilities using STRIDE analysis and CWE mapping |
| version | 1 |
| model | sonnet |
| invoked_by | both |
| user_invocable | true |
| tools | ["Read","Write","Bash","Grep"] |
| verified | true |
| lastVerifiedAt | "2026-03-16T08:04:10.005Z" |
| best_practices | ["Follow existing project patterns","Document all outputs clearly","Handle errors gracefully"] |
| error_handling | graceful |
| streaming | supported |
| source | builtin |
| trust_score | 100 |
| provenance_sha | ac8c5507731d6d2c |
Commit Security Scan
Commit Security Scan Skill - Analyze code changes (commits, PRs, diffs) for security vulnerabilities using STRIDE analysis and CWE mapping
- Commit Security Scan primary function
- Integration with agent ecosystem
- Standardized output generation
Step 1: Gather Context
Read relevant files and understand requirements
Step 2: Execute
Perform the skill's main function using available tools
Step 3: Output
Return results and save artifacts if applicable
</execution_process>
<best_practices>
- Follow existing project patterns: Follow this practice for best results
- Document all outputs clearly: Follow this practice for best results
- Handle errors gracefully: Follow this practice for best results
</best_practices>
**Example Commands**:
/commit-security-scan [arguments]
node .claude/skills/commit-security-scan/scripts/main.cjs --help
</usage_example>
Search Protocol
For code discovery and search tasks, follow this priority order:
- `pnpm search:code ""` (Primary intent-based search).
- `ripgrep` (for exact keyword/regex matches).
- semantic/structural search via code tools if available.
Memory Protocol (MANDATORY)
Before starting:
```bash
cat .claude/context/memory/learnings.md
cat .claude/context/memory/decisions.md
```
After completing:
- New pattern -> `.claude/context/memory/learnings.md`
- Issue found -> `.claude/context/memory/issues.md`
- Decision made -> `.claude/context/memory/decisions.md`
ASSUME INTERRUPTION: Your context may reset. If it's not in memory, it didn't happen.