Agent skill

Ghost Scan Deps

by ghostsecurity in ghostsecurity/skills

Ghost Security - Software Composition Analysis (SCA) scanner.

Apache-2.0Auto-check: notesSecurity

Install Ghost Scan Deps

skills CLI
$ npx skills add ghostsecurity/skills --skill ghost-scan-deps -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ghostsecurity/skills ghost-scan-deps --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ghostsecurity/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ghost/skills/scan-deps .claude/skills/ghost-scan-deps && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ghost-scan-deps
GitHub stars
408
Token cost
~1.3k tokens
SKILL.md length
375 words
Files
10
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Ghost Security - Software Composition Analysis (SCA) scanner.

  • Works in 6 steps: Setup → Initialize Wraith → Discover Lockfiles → …
  • The user asks about dependency vulnerabilities
  • SKILL.md covers Defaults, Execution and Error Handling
  • Calls git

What it does

Ghost Scan Deps is an agent skill from ghostsecurity/skills. Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and remediation guidance. Use when the user asks about dependency vulnerabilities, vulnerable packages, CVE checks, security audits of dependencies, or wants to scan lockfiles like package-lock.json, yarn.lock, go.mod, or Gemfile.lock.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 15 other files (for example `README.md`, `agents/analyze/agent.md` and `agents/analyze/analyzer.md`).

It sits in Security, covering Vulnerability scanning, Dependency management and Security review. It works with Go and Ruby. The repository describes itself as: Ghost Security's collection of AppSec skills for AI coding agents. The licence is Apache-2.0.

When your agent uses it

  • The user asks about dependency vulnerabilities
  • Vulnerable packages
  • Security audits of dependencies
  • Wants to scan lockfiles like package-lock.json

Example prompts

  • “/ghost-scan-deps”

Requirements

  • Pre-approved tools (allowed-tools): Read, Glob, Grep, Bash, Task, TodoRead, TodoWrite

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Setup
  2. Initialize Wraith
  3. Discover Lockfiles
  4. Scan for Vulnerabilities
  5. Analyze Candidates
  6. Summarize Results

What it can do on your machine

Read from SKILL.md and the folder at commit 25fdf06. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Glob
    • Grep
    • Bash
    • Task
    • TodoRead
    • TodoWrite

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ghost Scan Deps loads about 1.3k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 375 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Glob, Grep, Bash, Task, TodoRead, TodoWrite

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ghostsecurity/skills at commit 25fdf06, republished under its Apache-2.0 licence (© ghostsecurity). 375 words, ~1,339 tokens.

Download SKILL.mdSave it as .claude/skills/ghost-scan-deps/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
ghost-scan-deps
description
Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings with severity levels and remediation guidance. Use when the user asks about dependency vulnerabilities, vulnerable packages, CVE checks, security audits of dependencies, or wants to scan lockfiles like package-lock.json, yarn.lock, go.mod, or Gemfile.lock.
allowed-tools
Read, Glob, Grep, Bash, Task, TodoRead, TodoWrite
argument-hint
[path-to-scan]
license
apache-2.0
metadata.version
1.1.0

Ghost Security SCA Scanner — Orchestrator

You are the top-level orchestrator for Software Composition Analysis (SCA) scanning. Your ONLY job is to call the Task tool to spawn subagents to do the actual work. Each step below gives you the exact Task tool parameters to use. Do not do the work yourself.

Defaults

  • repo_path: the current working directory
  • scan_dir: ~/.ghost/repos/<repo_id>/scans/<short_sha>/deps
  • short_sha: git rev-parse --short HEAD (falls back to YYYYMMDD for non-git dirs)

$ARGUMENTS

Any values provided above override the defaults.


Execution

  1. Setup — compute paths and create output directories
  2. Initialize Wraith — install the wraith binary
  3. Discover Lockfiles — find all dependency lockfiles in the repo
  4. Scan for Vulnerabilities — run wraith against each lockfile
  5. Analyze Candidates — assess exploitability of each candidate
  6. Summarize Results — generate the final scan report
Step 0: Setup

Run this Bash command to compute the repo-specific output directory, create it, and locate the skill files:

repo_name=$(basename "$(pwd)") && remote_url=$(git remote get-url origin 2>/dev/null || pwd) && short_hash=$(printf '%s' "$remote_url" | git hash-object --stdin | cut -c1-8) && repo_id="${repo_name}-${short_hash}" && short_sha=$(git rev-parse --short HEAD 2>/dev/null || date +%Y%m%d) && ghost_repo_dir="$HOME/.ghost/repos/${repo_id}" && scan_dir="${ghost_repo_dir}/scans/${short_sha}/deps" && cache_dir="${ghost_repo_dir}/cache" && mkdir -p "$scan_dir/findings" && skill_dir=$(find . -path '*skills/scan-deps/SKILL.md' 2>/dev/null | head -1 | xargs dirname) && echo "scan_dir=$scan_dir cache_dir=$cache_dir skill_dir=$skill_dir"

Store scan_dir (the absolute path under ~/.ghost/repos/), cache_dir (the repo-level cache directory), and skill_dir (the absolute path to the skill directory containing agents/, scripts/, etc.).

After this step, your only remaining tool is Task. Do not use Bash, Read, Grep, Glob, or any other tool for Steps 1–5.

Step 1: Initialize Wraith

Call the Task tool to initialize the wraith binary:

json
{
  "description": "Initialize wraith binary",
  "subagent_type": "general-purpose",
  "prompt": "You are the init agent. Read and follow the instructions in <skill_dir>/agents/init/agent.md.\n\n## Inputs\n- skill_dir: <skill_dir>"
}

The init agent installs wraith to ~/.ghost/bin/wraith (or wraith.exe on Windows).

Show full SKILL.md (153 more words)Show less
Step 2: Discover Lockfiles

Call the Task tool to discover lockfiles in the repository:

json
{
  "description": "Discover lockfiles",
  "subagent_type": "general-purpose",
  "prompt": "You are the discover agent. Read and follow the instructions in <skill_dir>/agents/discover/agent.md.\n\n## Inputs\n- repo_path: <repo_path>\n- scan_dir: <scan_dir>"
}

The discover agent finds all lockfiles (go.mod, package-lock.json, etc.) and writes <scan_dir>/lockfiles.json.

If lockfile count is 0: Skip to Step 5 (Summarize) with no lockfiles found.

Step 3: Scan for Vulnerabilities

Call the Task tool to run the wraith scanner:

json
{
  "description": "Scan for vulnerabilities",
  "subagent_type": "general-purpose",
  "prompt": "You are the scan agent. Read and follow the instructions in <skill_dir>/agents/scan/agent.md.\n\n## Inputs\n- repo_path: <repo_path>\n- scan_dir: <scan_dir>"
}

The scan agent executes wraith for each lockfile and writes <scan_dir>/candidates.json.

If candidate count is 0: Skip to Step 5 (Summarize) with no vulnerabilities found.

Step 4: Analyze Candidates

Call the Task tool to analyze the vulnerability candidates:

json
{
  "description": "Analyze vulnerability candidates",
  "subagent_type": "general-purpose",
  "prompt": "You are the analysis agent. Read and follow the instructions in <skill_dir>/agents/analyze/agent.md.\n\n## Inputs\n- repo_path: <repo_path>\n- scan_dir: <scan_dir>\n- skill_dir: <skill_dir>\n- cache_dir: <cache_dir>"
}

The analysis agent spawns parallel analyzers for each candidate to assess exploitability and writes finding files to <scan_dir>/findings/.

Step 5: Summarize Results

Call the Task tool to summarize the findings:

json
{
  "description": "Summarize scan results",
  "subagent_type": "general-purpose",
  "prompt": "You are the summarize agent. Read and follow the instructions in <skill_dir>/agents/summarize/agent.md.\n\n## Inputs\n- repo_path: <repo_path>\n- scan_dir: <scan_dir>\n- skill_dir: <skill_dir>\n- cache_dir: <cache_dir>"
}

After executing all the tasks, report the scan results to the user.


Error Handling

If any Task call fails, retry it once. If it fails again, stop and report the failure.

© ghostsecurity, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files in plugins/ghost/skills/scan-deps of ghostsecurity/skills.

  • SKILL.md
  • README.md
  • agents/analyze/agent.md
  • agents/analyze/analyzer.md
  • agents/analyze/template-finding.md
  • agents/discover/agent.md
  • agents/init/agent.md
  • agents/scan/agent.md
  • agents/summarize/agent.md
  • agents/summarize/template-report.md

Open the folder on GitHubat commit 25fdf06

Compare with similar skills

Ghost Scan Deps next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ghost Scan Deps compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ghost Scan Deps this skillghostsecurity/skills408—~1.3kAutomated safety check: NotesApache-2.0
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Sca AuditOWASP/secure-agent-playbook186—~494Automated safety check: PassCC-BY-4.0
Dependency Update BotVarnan-Tech/opendirectory672—~3kAutomated safety check: NotesMIT
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT

Similar skills

  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Sca Audit

    OWASP/secure-agent-playbook

    Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

    186 GitHub stars~494 tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Dependency Update Bot

    Varnan-Tech/opendirectory

    Scans your project for outdated npm, pip, Cargo, Go, or Ruby packages.

    672 GitHub stars~3k tokensUpdated 1 mo ago
    DevelopmentAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    106 GitHub stars~1k tokensUpdated 5 days ago
    SecurityAuto-check passed

More from ghostsecurity/skills

  • Ghost Exo

    ghostsecurity/skills

    The single interface for building, improving, and debugging exo workflows.

    408 GitHub stars~1.3k tokensUpdated 9 days ago
    Auto-check passed
  • Ghost Repo Context

    ghostsecurity/skills

    Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file.

    408 GitHub stars~786 tokensUpdated 9 days ago
    Auto-check: notes
  • Ghost Report

    ghostsecurity/skills

    Ghost Security — combined security report. An agent skill from ghostsecurity/skills.

    408 GitHub stars~1.4k tokensUpdated 9 days ago
    Auto-check: notes
  • Ghost Scan Secrets

    ghostsecurity/skills

    Ghost Security - Secrets and credentials scanner. An agent skill from ghostsecurity/skills.

    408 GitHub stars~1.2k tokensUpdated 9 days ago
    Auto-check: notes

Works with

Categories

Questions about Ghost Scan Deps

What does Ghost Scan Deps do?

Ghost Security - Software Composition Analysis (SCA) scanner. Ghost Scan Deps is an agent skill from ghostsecurity/skills. Ghost Security - Software Composition Analysis (SCA) scanner.

When should I use Ghost Scan Deps?

Ghost Scan Deps fits situations like: the user asks about dependency vulnerabilities; vulnerable packages; security audits of dependencies; wants to scan lockfiles like package-lock.json.

How do I install Ghost Scan Deps in Claude Code?

Run `npx skills add ghostsecurity/skills --skill ghost-scan-deps -a claude-code`. Or copy the skill folder (plugins/ghost/skills/scan-deps in ghostsecurity/skills) into .claude/skills/ghost-scan-deps in your project. Claude Code loads it when a task matches its description.

How do I install Ghost Scan Deps in Codex?

Run `npx skills add ghostsecurity/skills --skill ghost-scan-deps -a codex`. Or copy the skill folder (plugins/ghost/skills/scan-deps in ghostsecurity/skills) into .agents/skills/ghost-scan-deps in your project. Codex loads it when a task matches its description.

Can I use Ghost Scan Deps in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ghostsecurity/skills --skill ghost-scan-deps -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ghost-scan-deps, .gemini/skills/ghost-scan-deps, .github/skills/ghost-scan-deps and .opencode/skills/ghost-scan-deps in your project.

What does Ghost Scan Deps need to run?

Going by SKILL.md and its folder, Ghost Scan Deps needs the command-line tools its instructions call (git). Its frontmatter pre-approves these tools: Read, Glob, Grep, Bash, Task, TodoRead, TodoWrite.

Does Ghost Scan Deps access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ghost Scan Deps safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ghost Scan Deps use?

Ghost Scan Deps is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ghost Scan Deps use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ghost Scan Deps?

Skills that share tags, products or a category with Ghost Scan Deps: Cyberowlai (karimhabush/cyberowl, 263 stars), Sca Audit (OWASP/secure-agent-playbook, 186 stars), Dependency Update Bot (Varnan-Tech/opendirectory, 672 stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ghost Scan Deps?

ghostsecurity (a GitHub organization) maintains it in ghostsecurity/skills, which has 408 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 28, 2026.

Source: ghostsecurity/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.