Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace.

MITAuto-check: notesSecurity

Install Warden Scan

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-scan .claude/skills/warden-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
warden-scan
GitHub stars
2.8k
Token cost
~750 tokens
SKILL.md length
267 words
Files
1
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace.

  • Works in 5 steps: Locate the scanner → Determine target → Run the scan → …
  • Asked to scan for vulnerabilities
  • SKILL.md covers Step 1: Locate the scanner, Step 2: Determine target, Step 3: Run the scan and Step 4: Display results, plus 1 more section
  • Calls python, pip and semgrep

What it does

Warden Scan is an agent skill from jeremylongshore/tons-of-skills-marketplace. Automated SAST + dependency vulnerability scan. Runs Semgrep (code vulnerabilities) and pip-audit (CVE-matched dependencies) and writes a structured JSON report. Use when asked to "scan for vulnerabilities", "run a security scan", "check for CVEs", or "audit dependencies".

Its SKILL.md is about 750 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning, Static analysis and SAST and Security review. It works with Semgrep. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Asked to scan for vulnerabilities
  • Run a security scan
  • Audit dependencies

Example prompts

  • “scan for vulnerabilities”
  • “run a security scan”
  • “check for CVEs”
  • “/warden-scan”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Bash, Read, Glob

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Locate the scanner
  2. Determine target
  3. Run the scan
  4. Display results
  5. Exit guidance

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • pip
    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Warden Scan loads about 750 tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 267 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~750

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 267 words, ~750 tokens.

Download SKILL.mdSave it as .claude/skills/warden-scan/SKILL.md (or your agent's skills folder).
name
warden-scan
description
Automated SAST + dependency vulnerability scan. Runs Semgrep (code vulnerabilities) and pip-audit (CVE-matched dependencies) and writes a structured JSON report. Use when asked to "scan for vulnerabilities", "run a security scan", "check for CVEs", or "audit dependencies".
allowed-tools
Bash, Read, Glob
version
0.9.7
author
tonone-ai <hello@tonone.ai>
license
MIT

Warden Scan — Automated SAST + Dependency Audit

You are Warden. Run a real security scan using Semgrep and pip-audit, then display the findings.

Step 1: Locate the scanner

Find the scan.py entry point:

bash
find . -path "*/warden_agent/scan.py" -not -path "*/__pycache__/*" 2>/dev/null | head -3

If not found, tell the user:

scan.py not found. Run pip install semgrep pip-audit and ensure the tonone plugin is installed.

Step 2: Determine target

If the user specified a path, use it. Otherwise use . (current directory).

Step 3: Run the scan

bash
python <path-to-scan.py> <target> --out .reports/warden-latest.json

The script:

  • Runs Semgrep SAST (semgrep --config auto)
  • Runs pip-audit on requirements*.txt files (falls back to current env)
  • Writes a JSON report and prints a summary line

Capture stdout + stderr. If the script exits with code 2, that means critical/high findings were found (expected, not an error).

Step 4: Display results

Parse and render the report using the tonone output kit format (40-line CLI budget, box-drawing skeleton):

┌─────────────────────────────────────────────┐
│ warden-scan  <target>                       │
└─────────────────────────────────────────────┘

CRITICAL  <N>   HIGH  <N>   MEDIUM  <N>   LOW  <N>

── SAST Findings ───────────────────────────────
[C] <title>  <location>
    <detail — 1 line>
    Fix: <recommendation>

[H] <title>  <location>
    <detail — 1 line>
    Fix: <recommendation>

── Dependency Findings ─────────────────────────
[H] <CVE-ID> in <pkg>==<ver>  <requirements-file>
    Fix: <recommendation>

── Summary ─────────────────────────────────────
Report: .reports/warden-latest.json

Severity indicators: [C] critical, [H] high, [M] medium, [L] low.

Show all CRITICAL and HIGH findings. Collapse MEDIUM/LOW into a count if there are more than 5.

If 0 findings: show a clean pass banner.

Step 5: Exit guidance

If critical or high findings exist, end with:

Action required. Review findings above. Run /warden-harden for remediation steps or /warden-threat for a full threat model.

If only medium/low:

Passed with warnings. No critical issues found. Consider /warden-audit for a broader manual review.

If clean:

Clean scan. No issues found by Semgrep or pip-audit.

Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose. If findings exceed 40 lines, emit a summary table and invoke /atlas-report to write the full report.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/ai-agency/tonone/skills/warden-scan of jeremylongshore/tons-of-skills-marketplace.

Open the folder on GitHubat commit cfae287

Compare with similar skills

Warden Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Warden Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Warden Scan this skilljeremylongshore/tons-of-skills-marketplace2.8k—~750Automated safety check: NotesMIT
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
CodeCrucible Security Scansblock/codecrucible117—~1.2kAutomated safety check: PassApache-2.0
Code Auditzhaoxuya520/reverse-skill41k2 repos~374Automated safety check: WarnMIT
Building Devsecops Pipeline With GitLab CImukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • CodeCrucible Security Scans

    block/codecrucible

    Official

    Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

    117 GitHub stars~1.2k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Code Audit

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

    41k GitHub starsUsed in 2 repos~374 tokens
    SecurityAuto-check: warnings
  • Building Devsecops Pipeline With GitLab CI

    mukul975/Anthropic-Cybersecurity-Skills

    Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated 4 days ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Warden Scan

What does Warden Scan do?

Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace. Warden Scan is an agent skill from jeremylongshore/tons-of-skills-marketplace. Automated SAST + dependency vulnerability scan.

When should I use Warden Scan?

Warden Scan fits situations like: asked to scan for vulnerabilities; run a security scan; audit dependencies.

How do I install Warden Scan in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-scan -a claude-code`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-scan in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/warden-scan in your project. Claude Code loads it when a task matches its description.

How do I install Warden Scan in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-scan -a codex`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-scan in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/warden-scan in your project. Codex loads it when a task matches its description.

Can I use Warden Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/warden-scan, .gemini/skills/warden-scan, .github/skills/warden-scan and .opencode/skills/warden-scan in your project.

What does Warden Scan need to run?

Going by SKILL.md and its folder, Warden Scan needs the command-line tools its instructions call (python, pip and semgrep). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Bash, Read, Glob.

Does Warden Scan access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Warden Scan safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Warden Scan use?

Warden Scan is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Warden Scan use?

About 750 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Warden Scan?

Skills that share tags, products or a category with Warden Scan: Security Reviewer (Jeffallan/claude-skills, 12k stars), Semgrep Security Scan (trailofbits/skills, 7.5k stars), CodeCrucible Security Scans (block/codecrucible, 117 stars) and Code Audit (zhaoxuya520/reverse-skill, 41k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Warden Scan?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.