| name | security-scanner |
| description | Security scanning for secrets and vulnerabilities |
| user-invocable | true |
Security Scanner Skill
Security scanning and vulnerability detection.
When to Use
- Pre-commit security checks
- Code review analysis
- Dependency scanning
What_You_MUST_Do>
- SCAN for hardcoded secrets (API keys, passwords, tokens)
- CHECK dependencies for known CVEs
- IDENTIFY insecure coding patterns
- REPORT findings with severity and remediation
- PROVIDE secure code examples
What_You_MUST_NOT_Do>
- DO NOT skip dependency scanning
- DO NOT report without remediation suggestions
- DO NOT ignore low-severity issues in security-sensitive code
- DO NOT commit secrets to version control
What This Skill Does
Secret Detection
const API_KEY = "sk-1234567890abcdef";
const API_KEY = process.env.API_KEY;
Vulnerability Scanning
- Known CVEs in dependencies
- Insecure coding patterns
- SQL injection risks
- XSS vulnerabilities
Usage
/security-scan to run a security scan.