Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords.

Apache-2.0Auto-check passedSecurity

Install Vuln Scan

skills CLI
$ npx skills add hashgraph-online/awesome-codex-plugins --skill vuln-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hashgraph-online/awesome-codex-plugins vuln-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hashgraph-online/awesome-codex-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/epicsagas/epic-harness/skills/vuln-scan .claude/skills/vuln-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vuln-scan
GitHub stars
1.3k
Token cost
~1.9k tokens
SKILL.md length
837 words
Files
1
Skills in repo
714
Repo updated
First seen
Licence
Apache-2.0

At a glance

Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords.

  • Works in 8 steps: Load Engagement Context → Map Entry Points to Trust Boundaries → Trace Data Flow to Sinks → …
  • Scanning for vulnerabilities
  • SKILL.md covers Iron Law, Process, Anti-Rationalization and Evidence Required, plus 1 more section
  • Calls cargo and npm

What it does

Vuln Scan is an agent skill from hashgraph-online/awesome-codex-plugins. Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords. Use when scanning for vulnerabilities, reviewing security, or validating threat models.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Threat modeling. The repository describes itself as: A curated list of awesome OpenAI Codex / ChatGPT plugins, skills, and resources. The 1 Codex Marketplace. See live plugins at: https://hol.org/plugins/best-codex-plugins. The licence is Apache-2.0.

When your agent uses it

  • Scanning for vulnerabilities
  • Reviewing security
  • Validating threat models

Example prompts

  • “/vuln-scan”

Requirements

  • Node.js

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Load Engagement Context
  2. Map Entry Points to Trust Boundaries
  3. Trace Data Flow to Sinks
  4. Reason About Encoding and Context at Each Sink
  5. Auth & Data-Exposure Pass
  6. Dependency Pass
  7. Produce Output
  8. Feed into Triage

What it can do on your machine

Read from SKILL.md and the folder at commit 9e7b281. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vuln Scan loads about 1.9k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 837 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hashgraph-online/awesome-codex-plugins at commit 9e7b281, republished under its Apache-2.0 licence (© hashgraph-online). 837 words, ~1,942 tokens.

Download SKILL.mdSave it as .claude/skills/vuln-scan/SKILL.md (or your agent's skills folder).
name
vuln-scan
description
Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords. Use when scanning for vulnerabilities, reviewing security, or validating threat models.

Vuln Scan — Systematic Vulnerability Scanner

Iron Law

Code you haven't traced from input to sink has vulnerabilities you haven't found. A grep hit is a lead, not a finding.

Process

Step 0: Load Engagement Context

Check for .harness/engagement.md. If present, load scope constraints — only scan in-scope paths and respect exclusions.

Check for THREAT_MODEL.md from a previous /threat-model run. If present, use its threat scenarios as scan targets. If absent, run full-surface scan.

Step 1: Map Entry Points to Trust Boundaries

Enumerate every place untrusted data enters the system, by reading the code:

  • External → app: HTTP handlers/routers, GraphQL resolvers, webhooks, file uploads, form fields, query params, headers
  • Process boundary: CLI args, environment variables, IPC, deserialization of stored data (cache, DB rows written earlier, config files)
  • Client-supplied state: cookies, JWT claims, API keys, referer/origin

For each entry point, note: what validation exists (yes/no/partial), and where the data flows next. This list is the scan's backbone — a scan that cannot name its entry points has not started.

Step 2: Trace Data Flow to Sinks

From each entry point, follow the data by reading code until it reaches a dangerous operation, or dies (validated, parameterized, dropped). Dangerous sink classes:

Sink classExamples (non-exhaustive)
Command/code executionshell invocation, eval-family, template engines with code modes, deserialization to live objects
Query constructionstring-built SQL, raw-query escapes in any ORM (Knex raw, Prisma $queryRaw, SQLAlchemy text(), Sequelize literal, Django extra/raw, Rails where("...") with interpolation)
Filesystempath joins with user input, upload destinations, archive extraction (zip-slip), file reads driven by request params
Web outputtemplate rendering with non-auto-escaping engines, innerHTML-family, redirect targets, header values (CRLF)
Auth decisionsIDOR — object lookups keyed only on user-supplied ids without ownership checks; role checks done client-side or per-endpoint instead of per-object

Read the surrounding code for every candidate sink. A sink that only receives validated/parameterized data is not a finding; a sink reachable from an entry point with no validation is.

Step 3: Reason About Encoding and Context at Each Sink

For each reachable sink, ask what context the data lands in and whether the encoding matches:

  • Interpolated into a SQL string? → parameterize, don't escape
  • Interpolated into a shell string? → arg-array execution, don't quote
  • Rendered into HTML/JS/CSS/URL? → each needs context-specific output encoding; auto-escaping templates cover HTML only when actually enabled for that template
  • Joined into a path? → canonicalize, then verify containment inside the intended root
  • Deserialized? → prefer format + type that cannot instantiate attacker-chosen types
Step 4: Auth & Data-Exposure Pass
  • Default-deny: routes/actions missing an auth middleware or check entirely — enumerate handlers and look for the gaps, not the checks
  • Object-level authorization: for each handler that reads/writes a user-owned object, is ownership verified on THIS request?
  • Secrets: hardcoded credentials vs. config/env references; secrets in logs, error messages, client bundles, API responses
  • Error leakage: verbose errors/stack traces/config in production paths; error messages that distinguish "no such user" from "wrong password"
Step 5: Dependency Pass
bash
cargo audit 2>/dev/null || echo "cargo-audit not installed"   # Rust
npm audit 2>/dev/null || echo "npm audit not available"       # Node.js

For each advisory: is a fix available, and is the vulnerable code path actually reachable from this codebase's usage? Unreachable advisories are LOW/INFO, not silent drops. Also flag actively-used dependencies that are unmaintained (no release in ~2+ years, archived repo) even without a CVE.

Show full SKILL.md (315 more words)Show less
Grep as Accelerator, Not Oracle

Grep is fine for candidate sink locations (raw(, exec, innerHTML, eval, secret-ish identifiers) — use it to shortlist where to read. It misses framework-specific sinks, aliases, and data built across files. Never report a finding from a grep hit alone; never conclude "clean" because grep found nothing.

Step 6: Produce Output

Write VULN-FINDINGS.json:

json
{
  "scan_date": "ISO-8601",
  "scope": "full | incremental",
  "threat_model_ref": "THREAT_MODEL.md | null",
  "entry_points_traced": ["list every entry point examined — required for clean scans"],
  "findings": [
    {
      "id": "V1",
      "dimension": "injection | auth | exposure | dependency",
      "severity": "CRITICAL | HIGH | MEDIUM | LOW | INFO",
      "file": "path/to/file",
      "line": 42,
      "source": "untrusted-input origin (entry point)",
      "sink_chain": ["entry function", "...", "sink function"],
      "description": "what was found",
      "validated": true,
      "false_positive": false,
      "reachable": true,
      "mitigated": false,
      "threat_scenario": "T1 | null",
      "remediation": "one-line fix hint"
    }
  ],
  "summary": {
    "total": 10,
    "critical": 1,
    "high": 3,
    "medium": 4,
    "low": 2,
    "false_positives": 0
  }
}
Step 7: Feed into Triage

After producing findings, suggest: "Run /triage to validate findings with adversarial review."

Anti-Rationalization

ExcuseRebuttalWhat to do instead
"It's an internal tool / not user-facing"Internal boundaries are attack surfaces — lateral movement starts inside.Trace internal entry points with the same rigor.
"The framework sanitizes automatically"Auto-escaping and parameterization have opt-outs, raw escapes, and edges; business logic is framework-agnostic.Find the raw/dangerous escapes and read them.
"We'll add validation later"Later never arrives for paths that already work.Finding = now; remediation line goes in the output.
"Grep found nothing, so we're clean"Grep misses aliased and framework-specific sinks by construction.A clean claim requires traced entry points, not an empty grep.
"Dependencies are vetted"Transitive dependencies aren't.Run the dependency pass every time the lockfile changes.

Evidence Required

  • Every finding cites file:line + the untrusted-input origin + the sink call chain
  • Each finding validated: reachable, not mitigated, severity confirmed
  • A clean (or low-finding) scan lists entry_points_traced — absence of evidence is not evidence of absence
  • All 4 dimensions completed (injection, auth, exposure, dependency)
  • VULN-FINDINGS.json written with summary
  • If THREAT_MODEL.md exists: each threat scenario mapped to findings
  • No CRITICAL/HIGH finding dismissed without explicit justification

Red Flags

  • Reporting grep hits without reading the surrounding code
  • Skipping framework-specific sink types (ORM raw escapes, non-auto-escaping templates)
  • Claiming clean without naming which entry points were traced
  • Scanning only changed files when full-surface scan was requested
  • Marking findings as false positives without a traced reason
  • VULN-FINDINGS.json with zero findings on a non-trivial codebase — the scan was likely incomplete, not the codebase clean

© hashgraph-online, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/epicsagas/epic-harness/skills/vuln-scan of hashgraph-online/awesome-codex-plugins.

Open the folder on GitHubat commit 9e7b281

Compare with similar skills

Vuln Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vuln Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vuln Scan this skillhashgraph-online/awesome-codex-plugins1.3k—~1.9kAutomated safety check: PassApache-2.0
Exa Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT
Lucidchart Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
Ramp Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.3kAutomated safety check: PassMIT
Serpapi Security Basicsjeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: PassMIT
Warden Threatjeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: NotesMIT

Similar skills

  • Exa Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Threat-model Exa credentials, query intent, retrieved web content, generated output, and retained operational evidence as separate trust boundaries.

    2.8k GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check passed
  • Lucidchart Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Threat-model and harden Lucid API, Standard Import, editor extension, and data connector integrations.

    2.8k GitHub stars~1k tokensUpdated today
    SecurityAuto-check passed
  • Ramp Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Establish least-privilege OAuth, secret, webhook, data, card, and financial-write controls for a Ramp integration.

    2.8k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Serpapi Security Basics

    jeremylongshore/tons-of-skills-marketplace

    Threat-model SerpAPI credentials, query data, result retention, browser exposure, logs, and ZeroTrace tradeoffs.

    2.8k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Warden Threat

    jeremylongshore/tons-of-skills-marketplace

    Produce a threat model — assets, ranked threats, mitigations, accepted risks.

    2.8k GitHub stars~1.6k tokensUpdated today
    SecurityAuto-check: notes
  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes

More from hashgraph-online/awesome-codex-plugins

All 714 skills in this repo
  • Anime Reaction Gif

    hashgraph-online/awesome-codex-plugins

    Create original anime-style reaction stickers as looping GIFs and MP4 previews, using generated character pose sheets and timed key poses.

    1.3k GitHub stars~922 tokensUpdated today
    Auto-check passed
  • Calibredb

    hashgraph-online/awesome-codex-plugins

    Manage and query Calibre libraries with the calibredb CLI (local paths or Calibre Content server URLs).

    1.3k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Rust API Test Harness

    hashgraph-online/awesome-codex-plugins

    A skill your agent uses when adding, changing, testing, or debugging Rust HTTP APIs and services, especially when Codex needs black-box integration tests, random-port app startup, real database test…

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Art

    hashgraph-online/awesome-codex-plugins

    Make a studio's game look like something at build time — a cover from a real frame of the game (free), painted covers, backdrops, textures and character plates from image models through the…

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Calle

    hashgraph-online/awesome-codex-plugins

    Use CALL-E from Codex through the calle CLI. An agent skill from hashgraph-online/awesome-codex-plugins.

    1.3k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Game Balance Economy

    hashgraph-online/awesome-codex-plugins

    Balance game difficulty, resources, rewards, probability, progression, economies, and dominant strategies.

    1.3k GitHub stars~618 tokensUpdated today
    Auto-check passed

Questions about Vuln Scan

What does Vuln Scan do?

Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords. Vuln Scan is an agent skill from hashgraph-online/awesome-codex-plugins. Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords.

When should I use Vuln Scan?

Vuln Scan fits situations like: scanning for vulnerabilities; reviewing security; validating threat models.

How do I install Vuln Scan in Claude Code?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill vuln-scan -a claude-code`. Or copy the skill folder (plugins/epicsagas/epic-harness/skills/vuln-scan in hashgraph-online/awesome-codex-plugins) into .claude/skills/vuln-scan in your project. Claude Code loads it when a task matches its description.

How do I install Vuln Scan in Codex?

Run `npx skills add hashgraph-online/awesome-codex-plugins --skill vuln-scan -a codex`. Or copy the skill folder (plugins/epicsagas/epic-harness/skills/vuln-scan in hashgraph-online/awesome-codex-plugins) into .agents/skills/vuln-scan in your project. Codex loads it when a task matches its description.

Can I use Vuln Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hashgraph-online/awesome-codex-plugins --skill vuln-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vuln-scan, .gemini/skills/vuln-scan, .github/skills/vuln-scan and .opencode/skills/vuln-scan in your project.

What does Vuln Scan need to run?

Going by SKILL.md and its folder, Vuln Scan needs the command-line tools its instructions call (cargo and npm). Our summary lists: Node.js.

Does Vuln Scan access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vuln Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vuln Scan use?

Vuln Scan is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vuln Scan use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vuln Scan?

Skills that share tags, products or a category with Vuln Scan: Exa Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Lucidchart Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Ramp Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Serpapi Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vuln Scan?

hashgraph-online (a GitHub organization) maintains it in hashgraph-online/awesome-codex-plugins, which has 1,255 GitHub stars. The repository holds 714 skills in this directory. The repository was last updated on October 9, 2026.

Source: hashgraph-online/awesome-codex-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.