Security Reviewer
Jeffallan/claude-skills
Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.
A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…
$ npx skills add ericrisco/rsc-harness --skill security-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness security-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-scan .claude/skills/security-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-scan" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/security-scan into .claude/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/security-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill security-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness security-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-scan .agents/skills/security-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-scan" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/security-scan into .agents/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill security-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness security-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-scan .cursor/skills/security-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-scan" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/security-scan into .cursor/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/security-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill security-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness security-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-scan .gemini/skills/security-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/security-scan into .gemini/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness security-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill security-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-scan .github/skills/security-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/security-scan into .github/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill security-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness security-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-scan .opencode/skills/security-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/security-scan into .opencode/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-scanA skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…
Security Scan is an agent skill from ericrisco/rsc-harness. Use when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on. NOT threat-modeling, OWASP design reasoning, or hand-authoring the fix (that is secure-coding).
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/tools.md`).
It sits in Security, covering Static analysis and SAST, Security review and Dependency management. It works with Trivy and Semgrep. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
npmsemgrepgitleakstrivyFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Scan loads about 2.8k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,099 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
VERIFIED live Stripe sk_live_… in config/.env (history) → ROTATE NOWAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,099 words, ~2,776 tokens.
.claude/skills/security-scan/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.A machine-first vulnerability sweep. Point automated scanners at a codebase,
collect SARIF/JSON, then do the work that has actual value: dedupe cross-tool
overlap, rank by exploitability, and emit one gate artifact CI can act on. The
finding comes from a tool run, not a hunch — if you are reasoning about a
design or hand-writing a fix, that is secure-coding,
not this skill.
Your job is orchestration + triage: every finding traces to a scanner run with a
ruleId and a source location, so the output is reproducible. Not eyeballing
code, not authoring patches.
Read-only by default. Scan, triage, report. Apply fixes (version bumps,
rotation, .gitignore edits) only when the user asks — a security sweep that
silently mutates the tree destroys the evidence and the trust.
Pin and verify your scanners. Exact versions, verified checksums/SHAs, never
@latest GitHub Actions. In March 2026 Trivy was supply-chain compromised —
malicious releases v0.69.4/0.69.5/0.69.6 and a hijacked
aquasecurity/trivy-action exfiltrated CI secrets. Your scanner runs with repo +
CI-secret access; an unpinned scanner is itself the attack surface.
Four classes: SAST (injection, XSS, path traversal in first-party code), SCA / deps (known CVEs in dependency manifests + lockfiles), Secrets (credentials in the tree or git history), Misconfig / IaC (Dockerfile, k8s, Terraform, exposed config). Pick tools by what is in the repo. This is the real branch point — match the tool to the manifest, do not run everything everywhere.
| Repo contains | SAST | SCA | Secrets | Misconfig |
|---|---|---|---|---|
Node (package-lock.json/pnpm-lock.yaml) | Semgrep | osv-scanner + npm audit (fast) | gitleaks → TruffleHog | Trivy |
Python (poetry.lock/requirements.txt) | Semgrep | osv-scanner + pip-audit (fast) | gitleaks → TruffleHog | Trivy |
Go (go.mod/go.sum) | Semgrep | osv-scanner (+ govulncheck for reachability) | gitleaks | Trivy |
Containers (Dockerfile, images) | — | Trivy fs/image | Trivy --scanners secret | Trivy config |
| IaC (Terraform/k8s/Helm) | Semgrep (IaC rules) | — | gitleaks | Trivy config, Semgrep rulesets |
| Monorepo (mixed) | Semgrep auto | osv-scanner (multi-ecosystem) | gitleaks → TruffleHog | Trivy |
Full install (pinned), flag matrix, and suppression syntax: references/tools.md.
All recipes emit SARIF (or JSON you normalize to it) — a common schema is what lets you merge four tools, dedupe, and feed one artifact into CI instead of four incompatible logs. Pin the version shown; the placeholders below mark where to lock an exact tag/digest.
Free OSS edition (latest 1.164.0, 2026-05-27): 30+ languages, ~2,000 community
rules. SCA + Secrets rulesets are gated behind the hosted platform — use the
dedicated tools below for those, not Semgrep.
# Pin via the CLI version, not @latest. OWASP ruleset, SARIF out.
semgrep scan --config p/owasp-top-ten --sarif --output sast.sarif .
# Broader local sweep (community rules), no telemetry:
semgrep scan --config auto --sarif --output sast.sarif --metrics off .osv-scanner (OpenSSF/Google) checks lockfiles against OSV.dev across ecosystems and catches transitive CVEs the native auditors miss. Run native first for speed, osv-scanner for coverage — never native alone.
# Primary: lockfile-aware, multi-ecosystem, SARIF.
osv-scanner scan source --format sarif --output sca.sarif .
# Fast first pass (ecosystem-native, weaker on transitive):
npm audit --omit=dev --audit-level=high --json > npm-audit.json # Node
pip-audit --format json --output pip-audit.json # Pythongitleaks (~150+ patterns, sub-second on diffs) is the pre-commit/CI workhorse. TruffleHog (800+ types) adds live credential verification — it auth-tests a hit to tell a real leaked key from a sample. Scan history, not just the tree: a key deleted in HEAD is still in the pack files and still rotatable.
# gitleaks: redacted SARIF over the working tree AND full git history.
gitleaks detect --redact --report-format sarif --report-path secrets.sarif
# TruffleHog: only verified (live) secrets across history.
trufflehog git file://. --only-verified --json > trufflehog.jsonTrivy scans filesystems, images, and IaC and finds transitive CVEs npm audit
misses.
# Pin the EXACT version (NOT v0.69.4/.5/.6 — those were the malicious releases).
# Verify the checksum/cosign signature before first use. See references/tools.md.
trivy fs --scanners vuln,secret,misconfig --format sarif --output trivy.sarif .The deliverable is not the four SARIF files. It is a deduped, ranked report.
(class, normalized-id, path, line) and keep the richest record — prefer the
one with verification (TruffleHog) or reachability (govulncheck).level and tool-native severities disagree;
map them all to one critical/high/medium/low scale (references/triage.md)..semgrepignore
that hides the next real bug too.BAD — dump 412 raw findings from four tools, sorted alphabetically, no ranking.
GOOD — 3 unsuppressed criticals first:
1. [secrets] VERIFIED live Stripe sk_live_… in config/.env (history) → ROTATE NOW
2. [sca] CVE-2024-… lodash 4.17.20 transitive, reachable in src/api/parse.ts → bump 4.17.21
3. [sast] SQL built from req.query in routes/search.js:48 → parameterize
+ 7 mediums summarized, + 18 suppressed (each with justification + expiry).Full ranking rubric, dedupe keying, and severity-normalization map:
references/triage.md.
Emit one security-scan-report.json — the machine-checkable contract CI gates on.
{
"schemaVersion": "1.0",
"scannedAt": "2026-06-02T10:00:00Z",
"target": ".",
"tools": [{ "name": "osv-scanner", "version": "2.0.2" }],
"summary": { "critical": 1, "high": 2, "medium": 7, "low": 14, "suppressed": 18 },
"findings": [
{
"class": "sca",
"ruleId": "CVE-2024-XXXXX",
"path": "package-lock.json",
"line": 0,
"severity": "critical",
"status": "open",
"tool": "osv-scanner",
"exploitability": "reachable",
"title": "Prototype pollution in lodash <4.17.21"
}
]
}status is one of open | suppressed | fixed; severity one of
critical | high | medium | low. Schema in full: references/triage.md.open finding at critical (and, on a strict gate, high)
→ fail. suppressed never fails. scripts/verify.sh enforces exactly this and
exits 0 on a clean/empty report (no false failure).@latest — the hijacked
aquasecurity/trivy-action was pulled by tag.# .github/workflows/security-scan.yml — pin the SHA, verify before bumping.
- uses: aquasecurity/trivy-action@<full-40-char-sha> # NEVER @latest / @master
with: { scan-type: fs, format: sarif, output: trivy.sarif }
- run: ./scripts/verify.sh # gate on security-scan-report.jsonverify.sh, not on a human
reading logs. See github-actions for the
pipeline shell and verify for the broader green gate
this feeds.| Anti-pattern | Do instead |
|---|---|
Pulling aquasecurity/trivy-action@latest because it is the official action | March 2026: a hijacked tag stole CI secrets. Pin a full SHA, verify provenance. |
| Treating every scanner finding as a bug to fix | Most are noise. Rank by reachable + exposed + sensitive sink; report the few that matter. |
| Calling the repo clean after scanning only the working tree | History holds the deleted keys. Scan git history; a removed-in-HEAD key is still leaked and live. |
Declaring deps fine because npm audit is clean | Native auditors miss transitive CVEs. Run osv-scanner/Trivy too; native is the fast pass, not the only pass. |
Committing a blanket .semgrepignore to quiet CI | A blanket ignore hides the next real bug. Suppress per-finding with a written justification + expiry. |
| Deleting a verified key from the file and moving on | Deleting ≠ safe. Rotate the credential first, then scrub history. The committed value is already compromised. |
Taking the SARIF level as the severity | Tools disagree. Normalize to one scale before you rank or gate. |
| Dumping all four tool outputs in the PR for the reviewer to sort | The reviewer won't. Merge, dedupe, rank, and emit one report. |
| Letting the scan auto-fix the deps it finds | Read-only by default. Propose bumps; apply only when asked — never mutate during a sweep. |
In a project with a 02-DOCS/ layer (the harness
Karpathy wiki), record the scanner choices, pinned versions, gate thresholds, and
any accepted-risk suppressions in 02-DOCS/wiki/stack/security-scan.md, and index
it in 02-DOCS/wiki/index.md (the Knowledge map; root CLAUDE.md keeps only a short
pointer to it). Read it first on every run so the next agent inherits the pinned
tools and thresholds instead of re-deriving them. No 02-DOCS/? Skip silently.
Conventions are recorded, not gated — never block the scan on this.
Reviewing a diff rather than scanning a repo: code-review
for correctness and quality, review for adversarial review
against a spec.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in skills/security-scan of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Scan this skillericrisco/rsc-harness | 156 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Security ReviewerJeffallan/claude-skills | 12k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Golang Securityunxed/f4 | 240 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Detection Breadthdeonmenezes/mantishack | 505 | — | ~510 | Automated safety check: Pass | Apache-2.0 |
Jeffallan/claude-skills
Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.
unxed/f4
Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…
mukul975/Anthropic-Cybersecurity-Skills
Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
deonmenezes/mantishack
When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain
Aedelon/claude-code-blueprint
Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…. Security Scan is an agent skill from ericrisco/rsc-harness. Use when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on.
Security Scan fits situations like: automated scanners drive a security sweep of a repo; dependency/lockfile CVEs; secrets in the tree; iaC misconfig — and the raw output has to become one deduped.
Run `npx skills add ericrisco/rsc-harness --skill security-scan -a claude-code`. Or copy the skill folder (skills/security-scan in ericrisco/rsc-harness) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill security-scan -a codex`. Or copy the skill folder (skills/security-scan in ericrisco/rsc-harness) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.
Going by SKILL.md and its folder, Security Scan needs a shell for the scripts in its folder and the command-line tools its instructions call (npm, semgrep, gitleaks and trivy). Our summary lists: Python 3; A Bash shell.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Scan: Security Reviewer (Jeffallan/claude-skills, 12k stars), Golang Security (unxed/f4, 240 stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Security Audit Scanner (ruvnet/ruflo, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.