Security Analyzer
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.
$ npx skills add bagofwords1/bagofwords --skill security-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install bagofwords1/bagofwords security-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-scan .claude/skills/security-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-scan" agent skill from https://github.com/bagofwords1/bagofwords/tree/main/.agents/skills/security-scan into .claude/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/bagofwords1/bagofwords/tree/main/.agents/skills/security-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add bagofwords1/bagofwords --skill security-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install bagofwords1/bagofwords security-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/security-scan .agents/skills/security-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-scan" agent skill from https://github.com/bagofwords1/bagofwords/tree/main/.agents/skills/security-scan into .agents/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bagofwords1/bagofwords --skill security-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install bagofwords1/bagofwords security-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/security-scan .cursor/skills/security-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-scan" agent skill from https://github.com/bagofwords1/bagofwords/tree/main/.agents/skills/security-scan into .cursor/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/bagofwords1/bagofwords.git --path .agents/skills/security-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add bagofwords1/bagofwords --skill security-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install bagofwords1/bagofwords security-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/security-scan .gemini/skills/security-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/bagofwords1/bagofwords/tree/main/.agents/skills/security-scan into .gemini/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install bagofwords1/bagofwords security-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add bagofwords1/bagofwords --skill security-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/security-scan .github/skills/security-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/bagofwords1/bagofwords/tree/main/.agents/skills/security-scan into .github/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add bagofwords1/bagofwords --skill security-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install bagofwords1/bagofwords security-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/security-scan .opencode/skills/security-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/bagofwords1/bagofwords/tree/main/.agents/skills/security-scan into .opencode/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-scanRun a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.
Security Scan is an agent skill from bagofwords1/bagofwords. Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. Use for "scan with Snyk", "resolve the security issues", dependency-CVE cleanup, or a pre-release security pass.
Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review, Containers and Static analysis and SAST. It works with Snyk, npm and Docker. The repository describes itself as: Chat with your data - with memory, rules, and observability built in. Deploy in 2 minutes.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ed624e0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvyarnnpmcurlapt-getFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.snyk.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SNYK_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Scan loads about 1.7k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 659 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 659 words (~1,681 tokens).
“Four independent surfaces, each with its own scan command and remediation style. Scan all four, triage (many findings are dev-only or false positives), fix the real ones, and re-scan to prove the fix before committing.”
Just SKILL.md in .agents/skills/security-scan of bagofwords1/bagofwords.
Open the folder on GitHubat commit ed624e0
Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Scan this skillbagofwords1/bagofwords | 458 | — | ~1.7k | Automated safety check: Pass | Custom licence | |
| Security Analyzeraiskillstore/marketplace | 430 | — | ~1.2k | Automated safety check: Notes | None | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Triage Image Cvesactivepieces/activepieces | 25k | — | ~3.6k | Automated safety check: Pass | Custom licence | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT |
aiskillstore/marketplace
Comprehensive security vulnerability analysis for codebases and infrastructure.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
activepieces/activepieces
Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
staruhub/ClaudeSkills
全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…
bagofwords1/bagofwords
Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…
bagofwords1/bagofwords
Add a new data source / connection type (e.g. An agent skill from bagofwords1/bagofwords.
bagofwords1/bagofwords
Add a new LLM model to the preset catalog, or a whole new LLM provider — with the mandatory pre-flight verification of model id, pricing, and context window against the provider's official docs.
bagofwords1/bagofwords
Update the product docs at docs.bagofwords.com (Mintlify) with text and fresh screenshots after a user-facing change ships.
bagofwords1/bagofwords
The locale/i18n architecture of bagofwords — catalogs, resolution order, RTL, backend contracts — and the procedures for adding strings, adding a locale, or translating UI.
bagofwords1/bagofwords
Run a live QA pass over the app — first map all user-facing functionality, then boot the full stack and manually exercise flows with Playwright, recording pass/fail evidence and filing a QA report.
Categories
Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. Security Scan is an agent skill from bagofwords1/bagofwords. Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.
Security Scan fits situations like: resolve the security issues; dependency-CVE cleanup; A pre-release security pass.
Run `npx skills add bagofwords1/bagofwords --skill security-scan -a claude-code`. Or copy the skill folder (.agents/skills/security-scan in bagofwords1/bagofwords) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add bagofwords1/bagofwords --skill security-scan -a codex`. Or copy the skill folder (.agents/skills/security-scan in bagofwords1/bagofwords) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bagofwords1/bagofwords --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.
Going by SKILL.md and its folder, Security Scan needs the command-line tools its instructions call (uv, yarn, npm, curl and apt-get) and credentials named SNYK_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in SNYK_TOKEN.
SKILL.md names 1 domain. In commands or code: api.snyk.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Scan has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Scan: Security Analyzer (aiskillstore/marketplace, 430 stars), Code Audit (3stoneBrother/code-audit, 893 stars), Triage Image Cves (activepieces/activepieces, 25k stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
bagofwords1 (a GitHub organization) maintains it in bagofwords1/bagofwords, which has 458 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 8, 2026.
Source: bagofwords1/bagofwords on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.