Agent skill

Security Scan

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

MITAuto-check: notesSecurity

Install Security Scan

skills CLI
$ npx skills add ericrisco/rsc-harness --skill security-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness security-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-scan .claude/skills/security-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scan
GitHub stars
156
Token cost
~2.8k tokens
SKILL.md length
1,099 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

  • Works in 4 steps: Merge + dedupe. Cross-tool overlap is… → Normalize severity. SARIF level and… → Rank by exploitability, not by count. A… → …
  • Automated scanners drive a security sweep of a repo
  • SKILL.md covers Scan classes and tool selection, Run recipes, Triage — turn noise into a… and The gate artifact, plus 4 more sections
  • Runs Shell scripts from its folder; calls npm, semgrep and gitleaks

What it does

Security Scan is an agent skill from ericrisco/rsc-harness. Use when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on. NOT threat-modeling, OWASP design reasoning, or hand-authoring the fix (that is secure-coding).

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/tools.md`).

It sits in Security, covering Static analysis and SAST, Security review and Dependency management. It works with Trivy and Semgrep. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Automated scanners drive a security sweep of a repo
  • Dependency/lockfile CVEs
  • Secrets in the tree
  • IaC misconfig — and the raw output has to become one deduped

Example prompts

  • “/security-scan”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Merge + dedupe. Cross-tool overlap is real (osv-scanner and Trivy both
  2. Normalize severity. SARIF level and tool-native severities disagree;
  3. Rank by exploitability, not by count. A finding scores higher when it is
  4. Suppress with a written justification, never a blanket ignore. Each

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • semgrep
    • gitleaks
    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Scan loads about 2.8k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,099 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:132
    VERIFIED live Stripe sk_live_… in config/.env (history) → ROTATE NOW

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,099 words, ~2,776 tokens.

Download SKILL.mdSave it as .claude/skills/security-scan/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
security-scan
description
Use when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on. NOT threat-modeling, OWASP design reasoning, or hand-authoring the fix (that is `secure-coding`).
tags
security, sast, sca, secrets, scanning, owasp
recommends
secure-coding, github-actions, verify
origin
risco

Security scan — orchestrate scanners, triage the noise, emit a gate

A machine-first vulnerability sweep. Point automated scanners at a codebase, collect SARIF/JSON, then do the work that has actual value: dedupe cross-tool overlap, rank by exploitability, and emit one gate artifact CI can act on. The finding comes from a tool run, not a hunch — if you are reasoning about a design or hand-writing a fix, that is secure-coding, not this skill.

Your job is orchestration + triage: every finding traces to a scanner run with a ruleId and a source location, so the output is reproducible. Not eyeballing code, not authoring patches.

Read-only by default. Scan, triage, report. Apply fixes (version bumps, rotation, .gitignore edits) only when the user asks — a security sweep that silently mutates the tree destroys the evidence and the trust.

Pin and verify your scanners. Exact versions, verified checksums/SHAs, never @latest GitHub Actions. In March 2026 Trivy was supply-chain compromised — malicious releases v0.69.4/0.69.5/0.69.6 and a hijacked aquasecurity/trivy-action exfiltrated CI secrets. Your scanner runs with repo + CI-secret access; an unpinned scanner is itself the attack surface.

Scan classes and tool selection

Four classes: SAST (injection, XSS, path traversal in first-party code), SCA / deps (known CVEs in dependency manifests + lockfiles), Secrets (credentials in the tree or git history), Misconfig / IaC (Dockerfile, k8s, Terraform, exposed config). Pick tools by what is in the repo. This is the real branch point — match the tool to the manifest, do not run everything everywhere.

Repo containsSASTSCASecretsMisconfig
Node (package-lock.json/pnpm-lock.yaml)Semgreposv-scanner + npm audit (fast)gitleaks → TruffleHogTrivy
Python (poetry.lock/requirements.txt)Semgreposv-scanner + pip-audit (fast)gitleaks → TruffleHogTrivy
Go (go.mod/go.sum)Semgreposv-scanner (+ govulncheck for reachability)gitleaksTrivy
Containers (Dockerfile, images)—Trivy fs/imageTrivy --scanners secretTrivy config
IaC (Terraform/k8s/Helm)Semgrep (IaC rules)—gitleaksTrivy config, Semgrep rulesets
Monorepo (mixed)Semgrep autoosv-scanner (multi-ecosystem)gitleaks → TruffleHogTrivy

Full install (pinned), flag matrix, and suppression syntax: references/tools.md.

Run recipes

All recipes emit SARIF (or JSON you normalize to it) — a common schema is what lets you merge four tools, dedupe, and feed one artifact into CI instead of four incompatible logs. Pin the version shown; the placeholders below mark where to lock an exact tag/digest.

SAST — Semgrep

Free OSS edition (latest 1.164.0, 2026-05-27): 30+ languages, ~2,000 community rules. SCA + Secrets rulesets are gated behind the hosted platform — use the dedicated tools below for those, not Semgrep.

bash
# Pin via the CLI version, not @latest. OWASP ruleset, SARIF out.
semgrep scan --config p/owasp-top-ten --sarif --output sast.sarif .
# Broader local sweep (community rules), no telemetry:
semgrep scan --config auto --sarif --output sast.sarif --metrics off .
SCA — osv-scanner (primary), native auditors (fast pass)

osv-scanner (OpenSSF/Google) checks lockfiles against OSV.dev across ecosystems and catches transitive CVEs the native auditors miss. Run native first for speed, osv-scanner for coverage — never native alone.

bash
# Primary: lockfile-aware, multi-ecosystem, SARIF.
osv-scanner scan source --format sarif --output sca.sarif .
# Fast first pass (ecosystem-native, weaker on transitive):
npm audit --omit=dev --audit-level=high --json > npm-audit.json   # Node
pip-audit --format json --output pip-audit.json                   # Python
Secrets — gitleaks (tree + history), TruffleHog (verified)

gitleaks (~150+ patterns, sub-second on diffs) is the pre-commit/CI workhorse. TruffleHog (800+ types) adds live credential verification — it auth-tests a hit to tell a real leaked key from a sample. Scan history, not just the tree: a key deleted in HEAD is still in the pack files and still rotatable.

bash
# gitleaks: redacted SARIF over the working tree AND full git history.
gitleaks detect --redact --report-format sarif --report-path secrets.sarif
# TruffleHog: only verified (live) secrets across history.
trufflehog git file://. --only-verified --json > trufflehog.json
Misconfig / IaC — Trivy (PINNED — see the caveat above)

Trivy scans filesystems, images, and IaC and finds transitive CVEs npm audit misses.

bash
# Pin the EXACT version (NOT v0.69.4/.5/.6 — those were the malicious releases).
# Verify the checksum/cosign signature before first use. See references/tools.md.
trivy fs --scanners vuln,secret,misconfig --format sarif --output trivy.sarif .

Triage — turn noise into a ranked report

The deliverable is not the four SARIF files. It is a deduped, ranked report.

  1. Merge + dedupe. Cross-tool overlap is real (osv-scanner and Trivy both flag the same CVE; gitleaks and TruffleHog both flag the same key). Key on (class, normalized-id, path, line) and keep the richest record — prefer the one with verification (TruffleHog) or reachability (govulncheck).
  2. Normalize severity. SARIF level and tool-native severities disagree; map them all to one critical/high/medium/low scale (references/triage.md).
  3. Rank by exploitability, not by count. A finding scores higher when it is reachable (called, not just present) + exposed (on an untrusted path) + a sensitive sink (auth, money, PII, RCE). A verified live secret or a reachable RCE CVE outranks a theoretical lib finding behind a feature flag.
  4. Suppress with a written justification, never a blanket ignore. Each suppression records who, why, and an expiry — not a silent .semgrepignore that hides the next real bug too.
text
BAD  — dump 412 raw findings from four tools, sorted alphabetically, no ranking.
GOOD — 3 unsuppressed criticals first:
       1. [secrets] VERIFIED live Stripe sk_live_… in config/.env (history) → ROTATE NOW
       2. [sca] CVE-2024-… lodash 4.17.20 transitive, reachable in src/api/parse.ts → bump 4.17.21
       3. [sast] SQL built from req.query in routes/search.js:48 → parameterize
       + 7 mediums summarized, + 18 suppressed (each with justification + expiry).

Full ranking rubric, dedupe keying, and severity-normalization map: references/triage.md.

Show full SKILL.md (427 more words)Show less

The gate artifact

Emit one security-scan-report.json — the machine-checkable contract CI gates on.

json
{
  "schemaVersion": "1.0",
  "scannedAt": "2026-06-02T10:00:00Z",
  "target": ".",
  "tools": [{ "name": "osv-scanner", "version": "2.0.2" }],
  "summary": { "critical": 1, "high": 2, "medium": 7, "low": 14, "suppressed": 18 },
  "findings": [
    {
      "class": "sca",
      "ruleId": "CVE-2024-XXXXX",
      "path": "package-lock.json",
      "line": 0,
      "severity": "critical",
      "status": "open",
      "tool": "osv-scanner",
      "exploitability": "reachable",
      "title": "Prototype pollution in lodash <4.17.21"
    }
  ]
}
  • status is one of open | suppressed | fixed; severity one of critical | high | medium | low. Schema in full: references/triage.md.
  • Gate rule: any open finding at critical (and, on a strict gate, high) → fail. suppressed never fails. scripts/verify.sh enforces exactly this and exits 0 on a clean/empty report (no false failure).

CI wiring (brief)

  • Pin actions to a full commit SHA, not a tag, never @latest — the hijacked aquasecurity/trivy-action was pulled by tag.
yaml
# .github/workflows/security-scan.yml — pin the SHA, verify before bumping.
- uses: aquasecurity/trivy-action@<full-40-char-sha>  # NEVER @latest / @master
  with: { scan-type: fs, format: sarif, output: trivy.sarif }
- run: ./scripts/verify.sh   # gate on security-scan-report.json
  • Upload SARIF to code scanning; gate the merge on verify.sh, not on a human reading logs. See github-actions for the pipeline shell and verify for the broader green gate this feeds.

Anti-patterns

Anti-patternDo instead
Pulling aquasecurity/trivy-action@latest because it is the official actionMarch 2026: a hijacked tag stole CI secrets. Pin a full SHA, verify provenance.
Treating every scanner finding as a bug to fixMost are noise. Rank by reachable + exposed + sensitive sink; report the few that matter.
Calling the repo clean after scanning only the working treeHistory holds the deleted keys. Scan git history; a removed-in-HEAD key is still leaked and live.
Declaring deps fine because npm audit is cleanNative auditors miss transitive CVEs. Run osv-scanner/Trivy too; native is the fast pass, not the only pass.
Committing a blanket .semgrepignore to quiet CIA blanket ignore hides the next real bug. Suppress per-finding with a written justification + expiry.
Deleting a verified key from the file and moving onDeleting ≠ safe. Rotate the credential first, then scrub history. The committed value is already compromised.
Taking the SARIF level as the severityTools disagree. Normalize to one scale before you rank or gate.
Dumping all four tool outputs in the PR for the reviewer to sortThe reviewer won't. Merge, dedupe, rank, and emit one report.
Letting the scan auto-fix the deps it findsRead-only by default. Propose bumps; apply only when asked — never mutate during a sweep.

Project grounding (02-DOCS + CLAUDE.md)

In a project with a 02-DOCS/ layer (the harness Karpathy wiki), record the scanner choices, pinned versions, gate thresholds, and any accepted-risk suppressions in 02-DOCS/wiki/stack/security-scan.md, and index it in 02-DOCS/wiki/index.md (the Knowledge map; root CLAUDE.md keeps only a short pointer to it). Read it first on every run so the next agent inherits the pinned tools and thresholds instead of re-deriving them. No 02-DOCS/? Skip silently. Conventions are recorded, not gated — never block the scan on this.

See Also

Reviewing a diff rather than scanning a repo: code-review for correctness and quality, review for adversarial review against a spec.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/security-scan of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/tools.md
  • references/triage.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Scan this skillericrisco/rsc-harness156—~2.8kAutomated safety check: NotesMIT
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Golang Securityunxed/f42402 repos~3.6kAutomated safety check: PassMIT
Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Detection Breadthdeonmenezes/mantishack505—~510Automated safety check: PassApache-2.0

Similar skills

  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    240 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed
  • Implementing Devsecops Security Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    505 GitHub stars~510 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Security Audit

    Aedelon/claude-code-blueprint

    Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

    120 GitHub stars~1.6k tokensUpdated 7 mo ago
    SecurityAuto-check: notes

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Security Scan

What does Security Scan do?

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…. Security Scan is an agent skill from ericrisco/rsc-harness. Use when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on.

When should I use Security Scan?

Security Scan fits situations like: automated scanners drive a security sweep of a repo; dependency/lockfile CVEs; secrets in the tree; iaC misconfig — and the raw output has to become one deduped.

How do I install Security Scan in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill security-scan -a claude-code`. Or copy the skill folder (skills/security-scan in ericrisco/rsc-harness) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.

How do I install Security Scan in Codex?

Run `npx skills add ericrisco/rsc-harness --skill security-scan -a codex`. Or copy the skill folder (skills/security-scan in ericrisco/rsc-harness) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.

Can I use Security Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.

What does Security Scan need to run?

Going by SKILL.md and its folder, Security Scan needs a shell for the scripts in its folder and the command-line tools its instructions call (npm, semgrep, gitleaks and trivy). Our summary lists: Python 3; A Bash shell.

Does Security Scan access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Scan safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Scan use?

Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Scan use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Security Scan?

Skills that share tags, products or a category with Security Scan: Security Reviewer (Jeffallan/claude-skills, 12k stars), Golang Security (unxed/f4, 240 stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Scan?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.