Runs a comprehensive security scan on any frontend or backend project regardless of language or framework. Detects hardcoded secrets, authentication gaps, XSS vulnerabilities (Vue v-html, React dangerouslySetInnerHTML, Angular [innerHTML]/bypassSecurityTrust*, Svelte {@html}), SQL/NoSQL/command injection, insecure dependencies via npm/pnpm/yarn audit (monorepo aware — runs in every package directory), OWASP Top 10 issues, missing input validation (frontend and backend), error disclosure, and transport security issues. Integrates Semgrep, Trivy, and Gitleaks when installed, and provides install instructions for missing tools. Generates a Markdown report. Use this skill for security reviews, vulnerability assessments, and reporting findings to the team.
2026-05-07