Agent skill

Sca Security

by hardw00t in hardw00t/ai-security-arsenal

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…

No licenceAuto-check passedSecurity

Install Sca Security

skills CLI
$ npx skills add hardw00t/ai-security-arsenal --skill sca-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hardw00t/ai-security-arsenal sca-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hardw00t/ai-security-arsenal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sca-security .claude/skills/sca-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sca-security
GitHub stars
104
Token cost
~3k tokens
SKILL.md length
1,093 words
Files
20 (incl. references)
Skills in repo
7
Repo updated
First seen
Licence
None found

At a glance

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…

  • Works in 5 steps: Patch-level bump if fix is in a patch… → Minor bump if patch unavailable → test +… → Major bump or fork → extended thinking;… → …
  • Scanning package dependencies (npm
  • SKILL.md covers When to Use, Trigger Phrases, When NOT to Use This Skill and Decision Tree, plus 12 more sections
  • Calls npm, brew and cargo

What it does

Sca Security is an agent skill from hardw00t/ai-security-arsenal. Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 23 other files, including reference files (for example `references/bounty_patterns_2024_2026.md`, `references/cargo.md` and `references/go_modules.md`).

It sits in Security, covering Supply chain security, Regulatory compliance and Vulnerability scanning. It works with npm and Ruby. The repository describes itself as: A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools.

When your agent uses it

  • Scanning package dependencies (npm
  • Reviewing PR lockfile diffs
  • Generating SBOMs
  • Auditing licenses

Example prompts

  • “/sca-security”

Requirements

  • Python 3
  • Node.js

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Patch-level bump if fix is in a patch release → low risk.
  2. Minor bump if patch unavailable → test + ship.
  3. Major bump or fork → extended thinking; coordinate with owning team.
  4. Virtual patch / WAF rule if upgrade blocked → record in finding's exploitability_notes + set an expiry.
  5. Accept risk → only for is_reachable: "unreachable" + kev: false + epss < 0.2; document + set review date.

What it can do on your machine

Read from SKILL.md and the folder at commit a1a68f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • brew
    • cargo
    • go
    • pipx
    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sca Security loads about 3k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 161 tokens; SKILL.md has 1,093 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~161
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 1,093 words (~2,992 tokens).

“Router skill for dependency security: SBOM generation, multi-source vuln correlation, license compliance, supply chain review, and reachability-driven triage. Optimized for polyglot repositories and PR-time lockfile review. Load the relevant workflow + ecosystem reference on demand — do not read the…”

— opening of SKILL.md by hardw00t
name
sca-security

Read the full SKILL.md on GitHub

Files

SKILL.md and 19 other files (references) in skills/sca-security of hardw00t/ai-security-arsenal.

  • SKILL.md
  • references/bounty_patterns_2024_2026.md
  • references/cargo.md
  • references/go_modules.md
  • references/malicious_package_indicators.md
  • references/maven_gradle.md
  • references/npm_yarn_pnpm.md
  • references/php_composer.md
  • references/python_pip_poetry.md
  • references/ruby_gems.md
  • references/sbom_formats.md
  • references/vuln_databases.md
  • schemas/finding.json
  • templates/sca_report.md
  • workflows/license_audit.md
  • workflows/lockfile_diff.md
  • workflows/reachability_analysis.md
  • … and 3 more

Open the folder on GitHubat commit a1a68f7

Compare with similar skills

Sca Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sca Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sca Security this skillhardw00t/ai-security-arsenal104—~3kAutomated safety check: PassNone
Dependency Auditoralirezarezvani/claude-skills28k—~1.1kAutomated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT
npm Supply Chain Checkmajiayu000/spellbook287—~1.5kAutomated safety check: PassMIT
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence

Similar skills

  • Dependency Auditor

    alirezarezvani/claude-skills

    Audit and manage dependencies across multi-language projects.

    28k GitHub stars~1.1k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • npm Supply Chain Check

    majiayu000/spellbook

    Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.

    287 GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check: notes
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Tracing Transitive Vulnerabilities

    jeremylongshore/tons-of-skills-marketplace

    Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.

    2.8k GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check: notes

More from hardw00t/ai-security-arsenal

  • Dast Automation

    hardw00t/ai-security-arsenal

    Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

    104 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check passed
  • Sast Orchestration

    hardw00t/ai-security-arsenal

    Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by…

    104 GitHub stars~2.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Iac Security

    hardw00t/ai-security-arsenal

    Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.

    104 GitHub stars~2.4k tokensUpdated 5 mo ago
    Auto-check passed
  • LLM Security

    hardw00t/ai-security-arsenal

    LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Threat Modeling

    hardw00t/ai-security-arsenal

    Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE.

    104 GitHub stars~2.6k tokensUpdated 5 mo ago
    Auto-check passed

Works with

Categories

Questions about Sca Security

What does Sca Security do?

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…. Sca Security is an agent skill from hardw00t/ai-security-arsenal. Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings.

When should I use Sca Security?

Sca Security fits situations like: scanning package dependencies (npm; reviewing PR lockfile diffs; generating SBOMs; auditing licenses.

How do I install Sca Security in Claude Code?

Run `npx skills add hardw00t/ai-security-arsenal --skill sca-security -a claude-code`. Or copy the skill folder (skills/sca-security in hardw00t/ai-security-arsenal) into .claude/skills/sca-security in your project. Claude Code loads it when a task matches its description.

How do I install Sca Security in Codex?

Run `npx skills add hardw00t/ai-security-arsenal --skill sca-security -a codex`. Or copy the skill folder (skills/sca-security in hardw00t/ai-security-arsenal) into .agents/skills/sca-security in your project. Codex loads it when a task matches its description.

Can I use Sca Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hardw00t/ai-security-arsenal --skill sca-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sca-security, .gemini/skills/sca-security, .github/skills/sca-security and .opencode/skills/sca-security in your project.

What does Sca Security need to run?

Going by SKILL.md and its folder, Sca Security needs the command-line tools its instructions call (npm, brew, cargo, go, pipx and mvn). Our summary lists: Python 3; Node.js.

Does Sca Security access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Sca Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sca Security use?

No licence was found for Sca Security or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Sca Security use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Sca Security?

Skills that share tags, products or a category with Sca Security: Dependency Auditor (alirezarezvani/claude-skills, 28k stars), Cyber Neo (Hainrixz/cyber-neo, 283 stars), npm Supply Chain Check (majiayu000/spellbook, 287 stars) and Cve Scan (softspark/ai-toolkit, 179 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sca Security?

hardw00t (a GitHub user) maintains it in hardw00t/ai-security-arsenal, which has 104 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on April 19, 2026.

Source: hardw00t/ai-security-arsenal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.