Security Audit Scanner
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.
$ npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install xenitV1/Antigravity-Workflows vulnerability-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/xenitV1/Antigravity-Workflows.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vulnerability-scanner .claude/skills/vulnerability-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vulnerability-scanner" agent skill from https://github.com/xenitV1/Antigravity-Workflows/tree/main/skills/vulnerability-scanner into .claude/skills/vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/xenitV1/Antigravity-Workflows/tree/main/skills/vulnerability-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install xenitV1/Antigravity-Workflows vulnerability-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xenitV1/Antigravity-Workflows.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vulnerability-scanner .agents/skills/vulnerability-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vulnerability-scanner" agent skill from https://github.com/xenitV1/Antigravity-Workflows/tree/main/skills/vulnerability-scanner into .agents/skills/vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install xenitV1/Antigravity-Workflows vulnerability-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xenitV1/Antigravity-Workflows.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vulnerability-scanner .cursor/skills/vulnerability-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vulnerability-scanner" agent skill from https://github.com/xenitV1/Antigravity-Workflows/tree/main/skills/vulnerability-scanner into .cursor/skills/vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/xenitV1/Antigravity-Workflows.git --path skills/vulnerability-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install xenitV1/Antigravity-Workflows vulnerability-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xenitV1/Antigravity-Workflows.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vulnerability-scanner .gemini/skills/vulnerability-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vulnerability-scanner" agent skill from https://github.com/xenitV1/Antigravity-Workflows/tree/main/skills/vulnerability-scanner into .gemini/skills/vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install xenitV1/Antigravity-Workflows vulnerability-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/xenitV1/Antigravity-Workflows.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vulnerability-scanner .github/skills/vulnerability-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vulnerability-scanner" agent skill from https://github.com/xenitV1/Antigravity-Workflows/tree/main/skills/vulnerability-scanner into .github/skills/vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install xenitV1/Antigravity-Workflows vulnerability-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xenitV1/Antigravity-Workflows.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vulnerability-scanner .opencode/skills/vulnerability-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vulnerability-scanner" agent skill from https://github.com/xenitV1/Antigravity-Workflows/tree/main/skills/vulnerability-scanner into .opencode/skills/vulnerability-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vulnerability-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vulnerability-scannerAdvanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.
Vulnerability Scanner is an agent skill from xenitV1/Antigravity-Workflows. Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `checklists.md` and `scripts/security_scan.py`).
It sits in Security, covering Web application vulnerabilities, Supply chain security and Threat modeling. The licence is MIT.
11 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f0a1fa7. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadGlobGrepBashFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vulnerability Scanner loads about 1.8k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 611 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Read, Glob, Grep, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from xenitV1/Antigravity-Workflows at commit f0a1fa7, republished under its MIT licence (© xenitV1). 611 words, ~1,844 tokens.
.claude/skills/vulnerability-scanner/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.Think like an attacker, defend like an expert. 2025 threat landscape awareness.
Execute for automated validation:
| Script | Purpose | Usage |
|---|---|---|
scripts/security_scan.py | Validate security principles applied | python scripts/security_scan.py <project_path> |
| File | Purpose |
|---|---|
| checklists.md | OWASP Top 10, Auth, API, Data protection checklists |
| Principle | Application |
|---|---|
| Assume Breach | Design as if attacker already inside |
| Zero Trust | Never trust, always verify |
| Defense in Depth | Multiple layers, no single point |
| Least Privilege | Minimum required access only |
| Fail Secure | On error, deny access |
Before scanning, ask:
| Rank | Category | Think About |
|---|---|---|
| A01 | Broken Access Control | Who can access what? IDOR, SSRF |
| A02 | Security Misconfiguration | Defaults, headers, exposed services |
| A03 | Software Supply Chain 🆕 | Dependencies, CI/CD, build integrity |
| A04 | Cryptographic Failures | Weak crypto, exposed secrets |
| A05 | Injection | User input → system commands |
| A06 | Insecure Design | Flawed architecture |
| A07 | Authentication Failures | Session, credential management |
| A08 | Integrity Failures | Unsigned updates, tampered data |
| A09 | Logging & Alerting | Blind spots, no monitoring |
| A10 | Exceptional Conditions 🆕 | Error handling, fail-open states |
2021 → 2025 Shifts:
├── SSRF merged into A01 (Access Control)
├── A02 elevated (Cloud/Container configs)
├── A03 NEW: Supply Chain (major focus)
├── A10 NEW: Exceptional Conditions
└── Focus shift: Root causes > Symptoms| Vector | Risk | Question to Ask |
|---|---|---|
| Dependencies | Malicious packages | Do we audit new deps? |
| Lock files | Integrity attacks | Are they committed? |
| Build pipeline | CI/CD compromise | Who can modify? |
| Registry | Typosquatting | Verified sources? |
| Category | Elements |
|---|---|
| Entry Points | APIs, forms, file uploads |
| Data Flows | Input → Process → Output |
| Trust Boundaries | Where auth/authz checked |
| Assets | Secrets, PII, business data |
Risk = Likelihood × Impact
High Impact + High Likelihood → CRITICAL
High Impact + Low Likelihood → HIGH
Low Impact + High Likelihood → MEDIUM
Low Impact + Low Likelihood → LOW| Factor | Weight | Question |
|---|---|---|
| CVSS Score | Base severity | How severe is the vuln? |
| EPSS Score | Exploit likelihood | Is it being exploited? |
| Asset Value | Business context | What's at risk? |
| Exposure | Attack surface | Internet-facing? |
Is it actively exploited (EPSS >0.5)?
├── YES → CRITICAL: Immediate action
└── NO → Check CVSS
├── CVSS ≥9.0 → HIGH
├── CVSS 7.0-8.9 → Consider asset value
└── CVSS <7.0 → Schedule for later| Scenario | Fail-Open (BAD) | Fail-Closed (GOOD) |
|---|---|---|
| Auth error | Allow access | Deny access |
| Parsing fails | Accept input | Reject input |
| Timeout | Retry forever | Limit + abort |
1. RECONNAISSANCE
└── Understand the target
├── Technology stack
├── Entry points
└── Data flows
2. DISCOVERY
└── Identify potential issues
├── Configuration review
├── Dependency analysis
└── Code pattern search
3. ANALYSIS
└── Validate and prioritize
├── False positive elimination
├── Risk scoring
└── Attack chain mapping
4. REPORTING
└── Actionable findings
├── Clear reproduction steps
├── Business impact
└── Remediation guidance| Pattern | Risk | Look For |
|---|---|---|
| String concat in queries | Injection | "SELECT * FROM " + user_input |
| Dynamic code execution | RCE | eval(), exec(), Function() |
| Unsafe deserialization | RCE | pickle.loads(), unserialize() |
| Path manipulation | Traversal | User input in file paths |
| Disabled security | Various | verify=False, --insecure |
| Type | Indicators |
|---|---|
| API Keys | api_key, apikey, high entropy |
| Tokens | token, bearer, jwt |
| Credentials | password, secret, key |
| Cloud | AWS_, AZURE_, GCP_ prefixes |
| Layer | You Own | Provider Owns |
|---|---|---|
| Data | ✅ | ❌ |
| Application | ✅ | ❌ |
| OS/Runtime | Depends | Depends |
| Infrastructure | ❌ | ✅ |
| ❌ Don't | ✅ Do |
|---|---|
| Scan without understanding | Map attack surface first |
| Alert on every CVE | Prioritize by exploitability + asset |
| Ignore false positives | Maintain verified baseline |
| Fix symptoms only | Address root causes |
| Scan once before deploy | Continuous scanning |
| Trust third-party deps blindly | Verify integrity, audit code |
Each finding should answer:
| Severity | Criteria |
|---|---|
| Critical | RCE, auth bypass, mass data exposure |
| High | Data exposure, privilege escalation |
| Medium | Limited scope, requires conditions |
| Low | Informational, best practice |
Remember: Vulnerability scanning finds issues. Expert thinking prioritizes what matters. Always ask: "What would an attacker do with this?"
© xenitV1, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in skills/vulnerability-scanner of xenitV1/Antigravity-Workflows.
Open the folder on GitHubat commit f0a1fa7
We found 22 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in xenitV1/Antigravity-Workflows, which our catalogue first saw on October 7, 2026.
Vulnerability Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vulnerability Scanner this skillxenitV1/Antigravity-Workflows | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Security and Hardeningaddyosmani/agent-skills | 103k | 1 repos | ~4.4k | Automated safety check: Notes | MIT | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Csono-session/pstack | 134 | — | ~12k | Automated safety check: Notes | MIT | |
| Expert SecurityReJeCtAll/ExpertTeam-Codex | 113 | — | ~780 | Automated safety check: Pass | MIT |
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
addyosmani/agent-skills
Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
no-session/pstack
Chief Security Officer mode. An agent skill from no-session/pstack.
ReJeCtAll/ExpertTeam-Codex
安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.
unxed/f4
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…
xenitV1/Antigravity-Workflows
Bash/Linux terminal patterns. An agent skill from xenitV1/Antigravity-Workflows.
xenitV1/Antigravity-Workflows
Mobile-first design thinking and decision-making for iOS and Android apps.
xenitV1/Antigravity-Workflows
Native multi-agent orchestration using Claude Code's Agent Tool.
xenitV1/Antigravity-Workflows
AI operational modes (brainstorm, implement, debug, review, teach, ship, orchestrate).
xenitV1/Antigravity-Workflows
Performance profiling principles. An agent skill from xenitV1/Antigravity-Workflows.
xenitV1/Antigravity-Workflows
Structured task planning with clear breakdowns, dependencies, and verification criteria.
Categories
Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows. Vulnerability Scanner is an agent skill from xenitV1/Antigravity-Workflows. Advanced vulnerability analysis principles.
Vulnerability Scanner fits situations like: tasks that involve Web application vulnerabilities; tasks that involve Supply chain security; tasks that involve Threat modeling.
Run `npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a claude-code`. Or copy the skill folder (skills/vulnerability-scanner in xenitV1/Antigravity-Workflows) into .claude/skills/vulnerability-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a codex`. Or copy the skill folder (skills/vulnerability-scanner in xenitV1/Antigravity-Workflows) into .agents/skills/vulnerability-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xenitV1/Antigravity-Workflows --skill vulnerability-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-scanner, .gemini/skills/vulnerability-scanner, .github/skills/vulnerability-scanner and .opencode/skills/vulnerability-scanner in your project.
Going by SKILL.md and its folder, Vulnerability Scanner needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Vulnerability Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Vulnerability Scanner: Security Audit Scanner (ruvnet/ruflo, 74k stars), Security and Hardening (addyosmani/agent-skills, 103k stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars) and Cso (no-session/pstack, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
xenitV1 (a GitHub user) maintains it in xenitV1/Antigravity-Workflows, which has 130 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on January 14, 2026.
Source: xenitV1/Antigravity-Workflows on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.