Pyspector Security Audit
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.
$ npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ArabelaTso/Skills-4-SE time-aware-dependency-cve-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/time-aware-dependency-cve-scanner .claude/skills/time-aware-dependency-cve-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "time-aware-dependency-cve-scanner" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/time-aware-dependency-cve-scanner into .claude/skills/time-aware-dependency-cve-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "time-aware-dependency-cve-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/time-aware-dependency-cve-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ArabelaTso/Skills-4-SE time-aware-dependency-cve-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/time-aware-dependency-cve-scanner .agents/skills/time-aware-dependency-cve-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "time-aware-dependency-cve-scanner" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/time-aware-dependency-cve-scanner into .agents/skills/time-aware-dependency-cve-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "time-aware-dependency-cve-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ArabelaTso/Skills-4-SE time-aware-dependency-cve-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/time-aware-dependency-cve-scanner .cursor/skills/time-aware-dependency-cve-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "time-aware-dependency-cve-scanner" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/time-aware-dependency-cve-scanner into .cursor/skills/time-aware-dependency-cve-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "time-aware-dependency-cve-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ArabelaTso/Skills-4-SE.git --path skills/time-aware-dependency-cve-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ArabelaTso/Skills-4-SE time-aware-dependency-cve-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/time-aware-dependency-cve-scanner .gemini/skills/time-aware-dependency-cve-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "time-aware-dependency-cve-scanner" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/time-aware-dependency-cve-scanner into .gemini/skills/time-aware-dependency-cve-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "time-aware-dependency-cve-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ArabelaTso/Skills-4-SE time-aware-dependency-cve-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/time-aware-dependency-cve-scanner .github/skills/time-aware-dependency-cve-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "time-aware-dependency-cve-scanner" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/time-aware-dependency-cve-scanner into .github/skills/time-aware-dependency-cve-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "time-aware-dependency-cve-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ArabelaTso/Skills-4-SE time-aware-dependency-cve-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/time-aware-dependency-cve-scanner .opencode/skills/time-aware-dependency-cve-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "time-aware-dependency-cve-scanner" agent skill from https://github.com/ArabelaTso/Skills-4-SE/tree/main/skills/time-aware-dependency-cve-scanner into .opencode/skills/time-aware-dependency-cve-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "time-aware-dependency-cve-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
time-aware-dependency-cve-scannerScan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.
Time Aware Dependency Cve Scanner is an agent skill from ArabelaTso/Skills-4-SE. Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. Takes a repository path, cutoff date (YYYY-MM-DD), and optional parameters for transitive dependencies. Parses dependency manifests (package.json, pom.xml, requirements.txt, go.mod, Cargo.toml) and lockfiles to extract exact versions. Queries vulnerability databases (OSV.dev, NVD, GitHub Advisory) to identify CVEs disclosed strictly after the cutoff date. Distinguishes between newly disclosed CVEs and previously known CVEs…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/dependency_formats.md`, `references/vulnerability_databases.md` and `scripts/parse_dependencies.py`).
It sits in Security, covering Vulnerability scanning and Security review. It works with npm, Go, GitHub and Rust. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonpipgitjqFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
nvd.nist.govFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Time Aware Dependency Cve Scanner loads about 2.1k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 226 tokens; SKILL.md has 584 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 584 words, ~2,100 tokens.
.claude/skills/time-aware-dependency-cve-scanner/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Scan repositories for newly disclosed CVEs affecting dependencies after a specific cutoff date. This skill helps track when vulnerabilities were introduced and distinguish between pre-existing and newly disclosed security issues.
Basic scan:
python scripts/scan_repository.py /path/to/repo 2023-01-01Scan only direct dependencies:
python scripts/scan_repository.py /path/to/repo 2023-01-01 --no-transitiveOutput as JSON:
python scripts/scan_repository.py /path/to/repo 2023-01-01 --json > report.jsonThe scanner automatically detects and parses dependency manifests:
Supported ecosystems:
Manual parsing (if needed):
python scripts/parse_dependencies.py /path/to/repoThis extracts:
For detailed manifest formats, see references/dependency_formats.md
The scanner queries multiple databases to find CVEs:
Primary source: OSV.dev (Open Source Vulnerabilities)
Additional sources:
Manual CVE query (for testing):
python scripts/query_cves.py lodash 4.17.20 npm 2023-01-01For database details and API usage, see references/vulnerability_databases.md
The scanner filters CVEs to include only those disclosed after the cutoff date:
published date from vulnerability databasesExample:
The scanner produces a comprehensive report with:
Summary statistics:
Detailed CVE list: For each CVE:
Clear status: If no new CVEs found, explicitly reports "dependency set is clear since the given date"
Scenario: Periodic security review to find vulnerabilities disclosed since last audit
# Last audit was on 2023-06-01, check for new CVEs since then
python scripts/scan_repository.py /path/to/repo 2023-06-01Output: List of all CVEs disclosed after June 1, 2023 that affect your dependencies
Scenario: Check if new CVEs affect a specific historical codebase version
# Check if any CVEs disclosed after 2023-01-01 affect code from that date
git checkout <commit-from-2023-01-01>
python scripts/scan_repository.py . 2023-01-01Output: Shows which vulnerabilities were discovered after the code was written
Scenario: Generate reports showing vulnerability status at specific dates
# Generate quarterly reports
python scripts/scan_repository.py /path/to/repo 2023-01-01 --json > q1_report.json
python scripts/scan_repository.py /path/to/repo 2023-04-01 --json > q2_report.json
python scripts/scan_repository.py /path/to/repo 2023-07-01 --json > q3_report.jsonOutput: Time-series data showing when vulnerabilities were disclosed
Scenario: Monitor how security posture changes over time
# Compare vulnerability counts at different dates
python scripts/scan_repository.py /path/to/repo 2022-01-01 | grep "new CVE"
python scripts/scan_repository.py /path/to/repo 2023-01-01 | grep "new CVE"
python scripts/scan_repository.py /path/to/repo 2024-01-01 | grep "new CVE"Output: Trend analysis of vulnerability accumulation
For large repositories, limit the number of dependencies scanned:
python scripts/scan_repository.py /path/to/repo 2023-01-01 --max-deps 50Skip transitive dependencies to focus on direct dependencies:
python scripts/scan_repository.py /path/to/repo 2023-01-01 --no-transitiveOutput structured JSON for integration with other tools:
python scripts/scan_repository.py /path/to/repo 2023-01-01 --json | jq '.summary'TIME-AWARE DEPENDENCY CVE SCAN REPORT
======================================================================
Repository: /path/to/repo
Cutoff Date: 2023-01-01
Scan Time: 2024-02-19T10:30:00
DEPENDENCY SUMMARY
----------------------------------------------------------------------
Total Dependencies: 150
- Direct: 25
- Transitive: 125
CVE SUMMARY
----------------------------------------------------------------------
⚠ 5 new CVE(s) found after 2023-01-01
- Affecting direct dependencies: 2
- Affecting transitive dependencies: 3
Severity Breakdown:
- CRITICAL: 1
- HIGH: 2
- MEDIUM: 2
DETAILED CVE LIST
----------------------------------------------------------------------
CVE-2023-12345 [CRITICAL]
Package: lodash (npm)
Disclosed: 2023-06-15
Affected Versions: >=4.0.0, <4.17.21
Summary: Prototype pollution vulnerability...tomli for Python TOML files)The scanner scripts require:
requests library: pip install requeststomli for TOML parsing: pip install tomli© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/time-aware-dependency-cve-scanner of ArabelaTso/Skills-4-SE.
Open the folder on GitHubat commit 4f38503
Time Aware Dependency Cve Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Time Aware Dependency Cve Scanner this skillArabelaTso/Skills-4-SE | 253 | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Sca AuditOWASP/secure-agent-playbook | 187 | — | ~494 | Automated safety check: Pass | CC-BY-4.0 | |
| Pre-Commit Security Scanzereight/gitlab-mcp | 2k | 1 repos | ~859 | Automated safety check: Notes | MIT | |
| SkepticRaoFoundation/subtensor | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 |
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
OWASP/secure-agent-playbook
Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.
zereight/gitlab-mcp
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
zebbern/claude-code-guide
Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.
ArabelaTso/Skills-4-SE
Generate prioritized CVE watchlists and actionable security recommendations for repositories.
ArabelaTso/Skills-4-SE
Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).
ArabelaTso/Skills-4-SE
Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.
ArabelaTso/Skills-4-SE
Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.
ArabelaTso/Skills-4-SE
Automatically migrate Spring MVC applications to Spring Boot.
ArabelaTso/Skills-4-SE
Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.
Categories
Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date. Time Aware Dependency Cve Scanner is an agent skill from ArabelaTso/Skills-4-SE. Scan repositories for newly disclosed CVEs in dependencies after a specific cutoff date.
Time Aware Dependency Cve Scanner fits situations like: performing security audits to find new vulnerabilities since last review; checking if new CVEs affect a historical codebase version; generating compliance reports showing vulnerability status at specific dates; tracking security posture changes over time.
Run `npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a claude-code`. Or copy the skill folder (skills/time-aware-dependency-cve-scanner in ArabelaTso/Skills-4-SE) into .claude/skills/time-aware-dependency-cve-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a codex`. Or copy the skill folder (skills/time-aware-dependency-cve-scanner in ArabelaTso/Skills-4-SE) into .agents/skills/time-aware-dependency-cve-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill time-aware-dependency-cve-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/time-aware-dependency-cve-scanner, .gemini/skills/time-aware-dependency-cve-scanner, .github/skills/time-aware-dependency-cve-scanner and .opencode/skills/time-aware-dependency-cve-scanner in your project.
Going by SKILL.md and its folder, Time Aware Dependency Cve Scanner needs Python for the scripts in its folder, the command-line tools its instructions call (python, pip, git and jq) and credentials named GITHUB_TOKEN. Our summary lists: Python 3; A credential in GITHUB_TOKEN.
SKILL.md names 1 domain. As links in the text: nvd.nist.gov. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Time Aware Dependency Cve Scanner is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Time Aware Dependency Cve Scanner: Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Sca Audit (OWASP/secure-agent-playbook, 187 stars) and Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 170 skills in this directory. The repository was last updated on August 21, 2026.
Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.