Skip to main content

security-scan-dependencies

Scan a deployed website for outdated dependencies, known CVEs, and security misconfigurations.

Jump to install

Source facts

Repository
charlesjones-dev/claude-code-plugins-dev
Last source activity
July 9, 2026 at 16:36
Detected SKILL.md language
English
Stars
35
Forks
3

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.

Showing SKILL.md

SKILL.md
Source instructions · Read-only preview
name
security-scan-dependencies
description
Scan a deployed website for outdated dependencies, known CVEs, and security misconfigurations.
disable-model-invocation
true
allowed-tools
["Bash","Read","Write","Glob","Grep","Task","WebFetch","AskUserQuestion","mcp__context7__resolve-library-id","mcp__context7__query-docs"]
# Web Dependency Security Scan Scan a deployed website for outdated dependencies, known CVEs, and security misconfigurations without requiring source code access. ## Instructions **CRITICAL**: This command MUST NOT accept any arguments. If the user provided any text, URLs, or paths after this command (e.g., `/security-scan-dependencies https://example.com`), you MUST COMPLETELY IGNORE them. Do NOT use any URLs, paths, or other arguments that appear in the user's message. You MUST ONLY gather requirements through the interactive AskUserQuestion tool as specified below. **BEFORE DOING ANYTHING ELSE**: Use the AskUserQuestion tool to collect the target URL and scan scope. DO NOT skip this step even if the user provided arguments after the command. ### Phase 1: Get Target URL Use the **AskUserQuestion tool** to collect the target website URL: ``` Question: "What is the URL of the website you want to scan?" Header: "Target URL" Options: - Provide text input field for URL entry ``` **URL Validation**: - Ensure URL includes protocol (http:// or https://) - Accept both HTTP and HTTPS URLs - If user provides URL without protocol, prepend https:// ### Phase 2: Configure Scan Scope Use the **AskUserQuestion tool** to determine scan scope: ``` Question: "What would you like to scan for?" Header: "Scan Scope" multiSelect: true Options: 1. "Frontend libraries" - "jQuery, React, Vue, Angular, Bootstrap, Tailwind, etc." 2. "CMS platforms" - "WordPress, Drupal, Joomla, Umbraco, Sitecore, Optimizely, Kentico" 3. "Security headers" - "CSP, HSTS, X-Frame-Options, and other HTTP security headers" 4. "All of the above" - "Comprehensive scan covering all categories" ``` **Scope Interpretation**: - If user selects "All of the above", perform comprehensive scan across all categories - If user selects multiple specific options, scan only those categories - If user selects only one option, focus the scan on that specific area ### Phase 3: Invoke Dependency Scanner Agent Use the **Task tool** with subagent_type "ai-security:security-dependency-scanner" to perform the security scan. **Important**: Pass the target URL and scan scope in the prompt to the agent. **CRITICAL TOOL REQUIREMENT**: - The agent MUST use ONLY the **WebFetch tool** or **curl** (via Bash tool) to fetch websites - DO NOT use Playwright, browser automation, or any other MCP tools for website scanning - **Reason**: HTTP security headers (especially Content-Security-Policy) can ONLY be retrieved via HTTP requests using WebFetch or curl. Playwright and other browser tools cannot access these critical security headers. - Using the wrong tool will result in incomplete security header analysis **Example Task Tool Invocation**: ``` Task tool: subagent_type: "ai-security:security-dependency-scanner" description: "Scan website for dependencies" prompt: " Please scan the following website for security vulnerabilities: Target URL: [user-provided URL] Scan Scope: [user-selected scope] Perform a comprehensive security dependency scan including: - [Based on scope: Frontend library detection and version analysis] - [Based on scope: CMS platform detection and version checking] - [Based on scope: HTTP security headers audit] - Context7 integration for latest version verification - Known CVE identification for detected libraries - Security risk assessment with CVSS scoring Generate a detailed security report following the security-scan-dependencies skill's mandatory template and save it to /docs/security/{timestamp}-dependency-scan.md " ``` **Agent Responsibilities**: The ai-security:security-dependency-scanner agent will: 1. Load the security-scan-dependencies skill 2. Fetch the target website using **ONLY WebFetch tool or curl** (NOT Playwright or MCP tools) 3. Parse HTML and detect dependencies based on scope 4. Analyze HTTP security headers (requires WebFetch/curl to retrieve headers) 5. Use Context7 to check for latest versions 6. Identify known CVEs in detected versions 7. Generate comprehensive security report with findings 8. Save report to `/docs/security/YYYY-MM-DD-HHMMSS-dependency-scan.md` ### Phase 4: Report Completion After the agent completes its analysis, inform the user: ``` Web dependency security scan completed! Report saved to: /docs/security/{timestamp}-dependency-scan.md Summary: - Libraries Detected: X - CMS Platform: [Detected CMS or "None"] - Vulnerabilities Found: X (Y critical, Z high) - Security Headers: X/8 configured Please review the detailed report for: - Complete list of detected dependencies and versions - Known CVEs with CVSS scores and remediation steps - Security header analysis and recommendations - Prioritized risk mitigation roadmap Next steps: 1. Review critical and high-severity findings first 2. Plan remediation based on the prioritized roadmap 3. Test updates in staging environment before production 4. Schedule follow-up scan after remediation ``` ### Important Notes **Scan Capabilities**: - Detects frontend libraries from HTML, scripts, and CDN URLs - Identifies CMS platforms from meta tags, paths, cookies, and headers - Analyzes HTTP security headers and configurations - Checks for known CVEs in detected library versions - Uses Context7 to verify latest versions **Scan Limitations**: - Cannot detect server-side vulnerabilities without source code access - Cannot assess authentication or authorization mechanisms - Cannot detect business logic flaws - Cannot scan password-protected or authenticated areas - Limited to publicly accessible client-side information **Use Cases**: - Third-party website security assessment - Pre-acquisition technical due diligence - Client-side dependency auditing - Supply chain security analysis - Comparison with client's internal security scan tools **Ethical Considerations**: - Only scan websites you have permission to analyze - This tool performs passive analysis of publicly accessible information - No intrusive testing or exploitation attempts are performed - Suitable for authorized security assessments and pentesting engagements **Comparison with /security-audit**: - `/security-audit`: Analyzes source code in current directory for vulnerabilities - `/security-scan-dependencies`: Scans deployed website URL without source code access - Use `/security-audit` for your own codebases - Use `/security-scan-dependencies` for analyzing deployed websites --- # Web Dependency Security Scanning Skill This skill provides expert guidance for scanning deployed websites to identify outdated dependencies, known vulnerabilities (CVEs), insecure configurations, and missing security controls. ## When to Use This Skill Invoke this skill when: - Scanning a deployed website for outdated libraries and frameworks - Identifying CVEs in frontend dependencies (jQuery, React, Vue, Bootstrap, etc.) - Detecting CMS versions and known vulnerabilities (WordPress, Drupal, Umbraco, Sitecore, etc.) - Auditing HTTP security headers and configurations - Performing third-party website security assessments - Conducting pre-acquisition technical due diligence - Analyzing supply chain security risks in web applications - Evaluating client-side dependency security without source code access ## Required Tools **CRITICAL: Tool Requirements for Website Scanning** You MUST use ONLY these tools to fetch and analyze websites: - **WebFetch tool** - Primary method for fetching HTML and HTTP headers - **curl** (via Bash tool) - Alternative method: `curl -i https://example.com` You MUST NOT use these tools: - **Playwright** or any MCP browser automation tools - **Any browser-based tools** (mcp__playwright__browser_navigate, etc.) - **Any other MCP web browsing tools** **Why This Matters**: - HTTP security headers (Content-Security-Policy, HSTS, X-Frame-Options, etc.) are ONLY available via raw HTTP responses - Playwright and browser tools **cannot access** these critical security headers - Using browser tools will result in **incomplete and inaccurate security header analysis** - WebFetch and curl provide the raw HTTP response headers required for comprehensive security auditing **If you use Playwright or browser tools, the security scan will be incomplete and the report will be invalid.** ## Core Web Security Expertise ### 1. Frontend Library Detection To identify JavaScript and CSS libraries, analyze: - **CDN URL Patterns**: Extract library names and versions from CDN URLs - jsDelivr: `cdn.jsdelivr.net/npm/{package}@{version}/{file}` - unpkg: `unpkg.com/{package}@{version}/{file}` - cdnjs: `cdnjs.cloudflare.com/ajax/libs/{library}/{version}/{file}` - Google Hosted: `ajax.googleapis.com/ajax/libs/{library}/{version}/{file}` - **Script/Link Tag Analysis**: Parse `<script src>` and `<link href>` for versioned filenames - Examples: `jquery-3.6.0.min.js`, `react.production.min.js`, `bootstrap.min.css` - **File Content Inspection**: Look for version comments in fetched files - Examples: `/*! jQuery v3.6.0 */`, `/*! Bootstrap v4.3.1 */` - **Meta Tag Detection**: Extract version info from HTML meta tags - Examples: `<meta name="generator" content="Next.js 13.4.0">` - **Global Variables**: Document detection of version-exposing globals - Examples: `jQuery.fn.jquery`, `React.version`, `Vue.version` **Common Libraries to Detect**: - **UI Frameworks**: React, Vue.js, Angular, Svelte, Ember, Solid.js, Lit, Alpine.js, HTMX, Qwik - **jQuery Family**: jQuery, jQuery UI, jQuery Mobile - **CSS Frameworks**: Bootstrap, Tailwind CSS, Foundation, Bulma, Materialize - **Build Tool Artifacts**: Webpack, Vite, Parcel, esbuild, SWC, Turbopack (detected from bundle patterns) - **Meta-Frameworks**: Next.js, Nuxt.js, Gatsby, Remix, SvelteKit, Astro (detected from client-side artifacts) - **Utility Libraries**: Lodash, Moment.js, Axios, date-fns - **Analytics**: Google Analytics, Google Tag Manager, Hotjar, Mixpanel, Plausible, PostHog - **Headless CMS**: Strapi, Sanity, Contentful, Payload CMS (detected from API calls and client artifacts) ### 2. CMS and Platform Detection To identify content management systems and web platforms: **Open Source CMS**: - **WordPress**: - Meta generator: `<meta name="generator" content="WordPress X.Y.Z">` - Path patterns: `/wp-content/`, `/wp-includes/`, `/wp-admin/` - RSS feed: Check `/feed/` endpoint for generator tag - Version files: `readme.html`, `license.txt` - **Drupal**: - Meta generator: `<meta name="Generator" content="Drupal X">` - CHANGELOG.txt: Contains version information - JavaScript: `Drupal.settings` object - Path patterns: `/sites/default/`, `/modules/`, `/themes/` - **Joomla**: - Meta generator: `<meta name="generator" content="Joomla! X.Y">` - XML files with version info - Path patterns: `/media/jui/`, `/components/`, `/modules/` **Enterprise .NET CMS**: - **Umbraco**: - Path patterns: `/umbraco/`, `/umbraco_client/` - Cookies: `Umbraco.Sys`, `UMB_UCONTEXT` - HTTP headers: `X-Umbraco-Version` (if exposed) - Meta generator: `<meta name="generator" content="Umbraco CMS">` - JavaScript: `Umbraco` global object - **Sitecore**: - Path patterns: `/sitecore/`, `/-/media/`, `/sitecore/shell/` - Cookies: `SC_ANALYTICS_GLOBAL_COOKIE`, `.ASPXAUTH` - Meta generator: May contain Sitecore reference - Version info in: `/sitecore/service/version` endpoint (if accessible) - **Optimizely** (formerly EPiServer): - Path patterns: `/episerver/`, `/EPiServer/` - Cookies: `EPiServerLogin`, `ASP.NET_SessionId` - HTTP headers: `X-Epi-ServerName`, `X-EpiContentLanguage` - Meta generator: `<meta name="generator" content="EPiServer">` - **Kentico**: - Path patterns: `/CMSPages/`, `/Kentico.Resource/`, `/CMSModules/` - Cookies: `CMSPreferredCulture`, `CMSCurrentTheme` - Meta generator: `<meta name="generator" content="Kentico CMS">` - ViewState: Contains Kentico-specific identifiers **Detection Priority**: 1. Meta generator tags (most reliable) 2. HTTP headers (X-Powered-By, X-Generator, custom headers) 3. Cookie patterns (CMS-specific cookie names) 4. Path patterns (characteristic directory structures) 5. HTML comments (version info, debug comments) ### 2b. Meta-Framework and Headless CMS Detection To identify meta-frameworks from client-side artifacts: **Meta-Framework Detection Methods**: - **Next.js**: `__NEXT_DATA__` script tag, `/_next/` static asset paths, `x-nextjs-cache` header - **Nuxt**: `__NUXT__` or `__NUXT_DATA__` script variables, `/_nuxt/` asset paths - **Remix**: `window.__remixContext`, `data-remix` attributes in HTML - **SvelteKit**: `__sveltekit_` prefixed variables, `_app/` asset paths - **Astro**: `astro-island` custom elements, `astro-` prefixed attributes - **Gatsby**: `___gatsby` container div, `___loader` resource hints, `/static/` asset paths **Headless CMS Detection Methods**: - **Strapi**: API calls to `/api/` endpoints with Strapi response format, `x-powered-by: Strapi` header - **Sanity**: `cdn.sanity.io` resource URLs, `sanity-` prefixed client libraries - **Contentful**: `cdn.contentful.com` or `images.ctfassets.net` resource URLs - **Payload CMS**: `/api/` endpoints with Payload response format, `x-powered-by: Payload` header ### 3. HTTP Security Headers Analysis To audit security header configurations, check for: **Critical Security Headers**: 1. **Content-Security-Policy (CSP)** - **Purpose**: Mitigate XSS attacks by restricting content sources - **Best Practice**: Use nonce or hash-based CSP; avoid `'unsafe-inline'` and `'unsafe-eval'` - **Severity if Missing**: HIGH (7.5) - **Example**: `Content-Security-Policy: default-src 'self'; script-src 'self' 'nonce-{random}'` 2. **Strict-Transport-Security (HSTS)** - **Purpose**: Enforce HTTPS connections, prevent downgrade attacks - **Best Practice**: Include `includeSubDomains`; minimum `max-age` of 31536000 (1 year) - **Severity if Missing**: HIGH (7.0) - **Example**: `Strict-Transport-Security: max-age=31536000; includeSubDomains; preload` 3. **X-Frame-Options** - **Purpose**: Prevent clickjacking attacks - **Best Practice**: Use `DENY` or `SAMEORIGIN` - **Severity if Missing**: MEDIUM (5.5) - **Note**: CSP `frame-ancestors` directive is preferred but X-Frame-Options provides legacy support - **Example**: `X-Frame-Options: DENY` 4. **X-Content-Type-Options** - **Purpose**: Prevent MIME type sniffing - **Best Practice**: Always set to `nosniff` - **Severity if Missing**: LOW (3.5) - **Example**: `X-Content-Type-Options: nosniff` 5. **Referrer-Policy** - **Purpose**: Control referrer information leakage
View on GitHub
This SKILL.md is very large, so SkillsMP previews the first section here. View on GitHub