Agent skill

Security Scan

by bagofwords1 in bagofwords1/bagofwords

Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

Custom licenceAuto-check passedSecurity

Install Security Scan

skills CLI
$ npx skills add bagofwords1/bagofwords --skill security-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bagofwords1/bagofwords security-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bagofwords1/bagofwords.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/security-scan .claude/skills/security-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scan
GitHub stars
458
Token cost
~1.7k tokens
SKILL.md length
659 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Custom licence

At a glance

Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

  • Works in 4 steps: Frontend deps (npm / frontend/yarn.lock) → Backend deps (pip / backend/uv.lock) → Dockerfile / base image → …
  • Resolve the security issues
  • SKILL.md covers Setup, 1. Frontend deps (npm /…, 2. Backend deps (pip /… and 3. Dockerfile / base image, plus 2 more sections
  • Calls uv, yarn and npm; reaches api.snyk.io; needs SNYK_TOKEN

What it does

Security Scan is an agent skill from bagofwords1/bagofwords. Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. Use for "scan with Snyk", "resolve the security issues", dependency-CVE cleanup, or a pre-release security pass.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review, Containers and Static analysis and SAST. It works with Snyk, npm and Docker. The repository describes itself as: Chat with your data - with memory, rules, and observability built in. Deploy in 2 minutes.

When your agent uses it

  • Resolve the security issues
  • Dependency-CVE cleanup
  • A pre-release security pass

Example prompts

  • “scan with Snyk”
  • “resolve the security issues”
  • “/security-scan”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in SNYK_TOKEN

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Frontend deps (npm / frontend/yarn.lock)
  2. Backend deps (pip / backend/uv.lock)
  3. Dockerfile / base image
  4. Snyk Code (SAST)

What it can do on your machine

Read from SKILL.md and the folder at commit ed624e0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • yarn
    • npm
    • curl
    • apt-get

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.snyk.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SNYK_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Scan loads about 1.7k tokens when it runs. Until then it costs about 78 tokens; SKILL.md has 659 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~78
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 659 words (~1,681 tokens).

“Four independent surfaces, each with its own scan command and remediation style. Scan all four, triage (many findings are dev-only or false positives), fix the real ones, and re-scan to prove the fix before committing.”

— opening of SKILL.md by bagofwords1, Custom licence
name
security-scan

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/security-scan of bagofwords1/bagofwords.

Open the folder on GitHubat commit ed624e0

Compare with similar skills

Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Scan this skillbagofwords1/bagofwords458—~1.7kAutomated safety check: PassCustom licence
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Triage Image Cvesactivepieces/activepieces25k—~3.6kAutomated safety check: PassCustom licence
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT

Similar skills

  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triage Image Cves

    activepieces/activepieces

    Scan an Activepieces Docker image with grype for OS/base-image (deb) and application (npm) CVEs of High/Critical severity.

    25k GitHub stars~3.6k tokensUpdated today
    SecurityAuto-check passed
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Audit

    staruhub/ClaudeSkills

    全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

    727 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from bagofwords1/bagofwords

All 13 skills in this repo
  • UI Audit

    bagofwords1/bagofwords

    Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…

    458 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Add Connection Type

    bagofwords1/bagofwords

    Add a new data source / connection type (e.g. An agent skill from bagofwords1/bagofwords.

    458 GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Add LLM Provider Or Model

    bagofwords1/bagofwords

    Add a new LLM model to the preset catalog, or a whole new LLM provider — with the mandatory pre-flight verification of model id, pricing, and context window against the provider's official docs.

    458 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Docs Update

    bagofwords1/bagofwords

    Update the product docs at docs.bagofwords.com (Mintlify) with text and fresh screenshots after a user-facing change ships.

    458 GitHub stars~746 tokensUpdated today
    Auto-check passed
  • Localization

    bagofwords1/bagofwords

    The locale/i18n architecture of bagofwords — catalogs, resolution order, RTL, backend contracts — and the procedures for adding strings, adding a locale, or translating UI.

    458 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • QA

    bagofwords1/bagofwords

    Run a live QA pass over the app — first map all user-facing functionality, then boot the full stack and manually exercise flows with Playwright, recording pass/fail evidence and filing a QA report.

    458 GitHub stars~824 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Security Scan

What does Security Scan do?

Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. Security Scan is an agent skill from bagofwords1/bagofwords. Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

When should I use Security Scan?

Security Scan fits situations like: resolve the security issues; dependency-CVE cleanup; A pre-release security pass.

How do I install Security Scan in Claude Code?

Run `npx skills add bagofwords1/bagofwords --skill security-scan -a claude-code`. Or copy the skill folder (.agents/skills/security-scan in bagofwords1/bagofwords) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.

How do I install Security Scan in Codex?

Run `npx skills add bagofwords1/bagofwords --skill security-scan -a codex`. Or copy the skill folder (.agents/skills/security-scan in bagofwords1/bagofwords) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.

Can I use Security Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bagofwords1/bagofwords --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.

What does Security Scan need to run?

Going by SKILL.md and its folder, Security Scan needs the command-line tools its instructions call (uv, yarn, npm, curl and apt-get) and credentials named SNYK_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in SNYK_TOKEN.

Does Security Scan access the network?

SKILL.md names 1 domain. In commands or code: api.snyk.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Scan use?

Security Scan has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Security Scan use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Scan?

Skills that share tags, products or a category with Security Scan: Security Analyzer (aiskillstore/marketplace, 430 stars), Code Audit (3stoneBrother/code-audit, 893 stars), Triage Image Cves (activepieces/activepieces, 25k stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Scan?

bagofwords1 (a GitHub organization) maintains it in bagofwords1/bagofwords, which has 458 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 8, 2026.

Source: bagofwords1/bagofwords on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.