A skill your agent uses when checking code for vulnerabilities, linting shell scripts, scanning containers or IaC for security issues, or managing encrypted secrets

MITAuto-check passedDevelopment

Install Security Scanning

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill security-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace security-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/productivity/cli-power-skills/skills/security-scanning .claude/skills/security-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scanning
GitHub stars
2.8k
Token cost
~1k tokens
SKILL.md length
329 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when checking code for vulnerabilities, linting shell scripts, scanning containers or IaC for security issues, or managing encrypted secrets

  • Checking code for vulnerabilities
  • SKILL.md covers When to Use, Tools, Patterns and Pipelines, plus 2 more sections
  • Calls trivy, shellcheck and jq
  • Linting shell scripts

What it does

Security Scanning is an agent skill from jeremylongshore/tons-of-skills-marketplace. Use when checking code for vulnerabilities, linting shell scripts, scanning containers or IaC for security issues, or managing encrypted secrets

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Linting and formatting, Shell scripting and Infrastructure as code. It works with Trivy. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Checking code for vulnerabilities
  • Linting shell scripts
  • Scanning containers
  • IaC for security issues

Example prompts

  • “/security-scanning”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Bash(trivy*), Bash(shellcheck*), Bash(sops*), Read, Glob

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(trivy*)
    • Bash(shellcheck*)
    • Bash(sops*)
    • Read
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • trivy
    • shellcheck
    • jq
    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Scanning loads about 1k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 329 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 329 words, ~1,006 tokens.

Download SKILL.mdSave it as .claude/skills/security-scanning/SKILL.md (or your agent's skills folder).
name
security-scanning
description
Use when checking code for vulnerabilities, linting shell scripts, scanning containers or IaC for security issues, or managing encrypted secrets
allowed-tools
Bash(trivy*), Bash(shellcheck*), Bash(sops*), Read, Glob
version
1.0.0
author
ykotik
license
MIT

Security Scanning

When to Use

  • Scanning a project directory for known vulnerabilities (CVEs)
  • Scanning a container image before deployment
  • Scanning Infrastructure-as-Code (Terraform, CloudFormation) for misconfigurations
  • Linting shell scripts for bugs, pitfalls, and unsafe patterns
  • Encrypting or decrypting secrets stored in YAML/JSON config files
  • Checking dependencies for known security issues

Tools

ToolPurposeStructured output
TrivyVulnerability scanner for filesystems, containers, IaC--format json or --format sarif
ShellCheckStatic analysis and linting for shell scripts-f json for JSON output
sopsEncrypt/decrypt secrets in YAML, JSON, ENV filesOutputs decrypted file to stdout

Patterns

Scan project directory for vulnerabilities
bash
trivy fs --format json --output results.json .
Scan project and show results in terminal
bash
trivy fs --severity HIGH,CRITICAL .
Scan a container image
bash
trivy image --format json --output scan.json nginx:latest
Scan Terraform files for misconfigurations
bash
trivy config --format json .
Scan a lockfile (package-lock.json, requirements.txt, etc.)
bash
trivy fs --scanners vuln --format json package-lock.json
Generate SARIF report for CI integration
bash
trivy fs --format sarif --output report.sarif .
Lint a shell script with JSON output
bash
shellcheck -f json script.sh
Lint all shell scripts in a directory
bash
shellcheck -f json *.sh scripts/*.sh
Lint with specific severity threshold
bash
shellcheck -S warning -f json script.sh
Encrypt a secrets file with sops (using age key)
bash
sops --encrypt --age $(cat ~/.config/sops/age/keys.txt | grep "public key:" | awk '{print $NF}') secrets.yaml > secrets.enc.yaml
Decrypt a secrets file to stdout
bash
sops --decrypt secrets.enc.yaml
Edit encrypted file in-place
bash
sops secrets.enc.yaml
Decrypt a single value
bash
sops --decrypt --extract '["database"]["password"]' secrets.enc.yaml

Pipelines

Scan and summarize critical findings
bash
trivy fs --format json . | jq '[.Results[] | .Vulnerabilities[]? | select(.Severity == "CRITICAL") | {id: .VulnerabilityID, pkg: .PkgName, title: .Title}]'

Each stage: Trivy scans and outputs JSON, jq filters to critical vulnerabilities and extracts key fields.

Lint all shell scripts and count issues by severity
bash
shellcheck -f json scripts/*.sh | jq 'group_by(.level) | map({level: .[0].level, count: length})'

Each stage: ShellCheck lints all scripts to JSON, jq groups and counts by severity level.

Scan image and fail if critical vulns found
bash
trivy image --format json myapp:latest | jq -e '[.Results[] | .Vulnerabilities[]? | select(.Severity == "CRITICAL")] | length == 0'

Each stage: Trivy scans image, jq checks for critical vulns and exits non-zero if any found.

Prefer Over

  • Prefer Trivy over manual npm audit / pip audit — scans all ecosystems in one pass
  • Prefer ShellCheck over manual review for shell scripts — catches subtle quoting, globbing, and portability bugs
  • Prefer sops over storing plaintext secrets — encryption at rest with version control compatibility

Do NOT Use When

  • Reviewing business logic or application design flaws — these tools find known CVEs and script bugs, not logic errors
  • Linting Python code — use Ruff (python-tooling skill) instead
  • Linting JavaScript/TypeScript — use ESLint or Biome directly
  • Managing runtime secrets (use Vault or environment variables for that)

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/productivity/cli-power-skills/skills/security-scanning of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Security Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Scanning this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: PassMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Configuration GeneratorArabelaTso/Skills-4-SE253—~2.8kAutomated safety check: NotesApache-2.0
Building Glamorous TuisDicklesworthstone/meta_skill205—~3.4kAutomated safety check: PassCustom licence
Atmos Lintcloudposse/atmos1.4k—~1.1kAutomated safety check: PassApache-2.0
Cosa Devcoreos/coreos-assembler395—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Configuration Generator

    ArabelaTso/Skills-4-SE

    Generate configuration files for applications, services, and infrastructure.

    253 GitHub stars~2.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Building Glamorous Tuis

    Dicklesworthstone/meta_skill

    Build terminal UIs with Charmbracelet (Bubble Tea, Lip Gloss, Gum).

    205 GitHub stars~3.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Atmos Lint

    cloudposse/atmos

    Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

    1.4k GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Cosa Dev

    coreos/coreos-assembler

    Develop and test changes to coreos-assembler itself -- build mantle Go binaries (kola, ore, plume), iterate on Python/shell scripts, or do full container rebuilds

    395 GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Debug CI

    web-infra-dev/rslint

    Reproduce Linux CI failures locally using Docker when the same tests pass on the host, especially Go platform differences and VS Code extension tests requiring xvfb.

    461 GitHub stars~2.8k tokensUpdated today
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Security Scanning

What does Security Scanning do?

A skill your agent uses when checking code for vulnerabilities, linting shell scripts, scanning containers or IaC for security issues, or managing encrypted secrets. Security Scanning is an agent skill from jeremylongshore/tons-of-skills-marketplace.

When should I use Security Scanning?

Security Scanning fits situations like: checking code for vulnerabilities; linting shell scripts; scanning containers; iaC for security issues.

How do I install Security Scanning in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill security-scanning -a claude-code`. Or copy the skill folder (plugins/productivity/cli-power-skills/skills/security-scanning in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/security-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Security Scanning in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill security-scanning -a codex`. Or copy the skill folder (plugins/productivity/cli-power-skills/skills/security-scanning in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/security-scanning in your project. Codex loads it when a task matches its description.

Can I use Security Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill security-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scanning, .gemini/skills/security-scanning, .github/skills/security-scanning and .opencode/skills/security-scanning in your project.

What does Security Scanning need to run?

Going by SKILL.md and its folder, Security Scanning needs the command-line tools its instructions call (trivy, shellcheck, jq, npm and pip). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash(trivy*), Bash(shellcheck*), Bash(sops*), Read, Glob.

Does Security Scanning access the network?

SKILL.md contains no URLs. Its commands use npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Scanning use?

Security Scanning is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Scanning use?

About 1k tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Scanning?

Skills that share tags, products or a category with Security Scanning: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Configuration Generator (ArabelaTso/Skills-4-SE, 253 stars), Building Glamorous Tuis (Dicklesworthstone/meta_skill, 205 stars) and Atmos Lint (cloudposse/atmos, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Scanning?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.