Agent skill

Nuclei Scan

by MigoXLab in MigoXLab/webqa-agent

Run a Nuclei security scan against the target URL and report findings by severity.

Apache-2.0Auto-check passedSecurity

Install Nuclei Scan

skills CLI
$ npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MigoXLab/webqa-agent nuclei-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MigoXLab/webqa-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/webqa_agent/executor/flash/skills/nuclei-scan .claude/skills/nuclei-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nuclei-scan
GitHub stars
232
Token cost
~846 tokens
SKILL.md length
378 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run a Nuclei security scan against the target URL and report findings by severity.

  • Works in 2 steps: Run the Scan → Report
  • Tasks that involve Security review
  • SKILL.md covers Prerequisites, Phase 1: Run the Scan, Phase 2: Report and Troubleshooting: [FTL] no…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nuclei Scan is an agent skill from MigoXLab/webqa-agent. Run a Nuclei security scan against the target URL and report findings by severity.

Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Security review. The repository describes itself as: Autonomous web browser agent that audits performance, functionality & UX for engineers and vibe-coding creators. 网站自主评估测试 Agent,支持 GUI/CLI 一键完成性能、功能使用与交互体验的测试评估. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/nuclei-scan”

Requirements

  • Docker

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Run the Scan
  2. Report

What it can do on your machine

Read from SKILL.md and the folder at commit aa156d4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nuclei Scan loads about 846 tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 378 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~846

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MigoXLab/webqa-agent at commit aa156d4, republished under its Apache-2.0 licence (© MigoXLab). 378 words, ~846 tokens.

Download SKILL.mdSave it as .claude/skills/nuclei-scan/SKILL.md (or your agent's skills folder).
name
nuclei-scan
description
Run a Nuclei security scan against the target URL and report findings by severity.
when_to_use
When the task requires security scanning, vulnerability detection, or CVE checks.

Nuclei Scan Skill

Run a security vulnerability scan against the target URL using the built-in execute_nuclei_scan tool, and produce a structured security report.

Important: Before each tool call, output a short one-line description of what you are about to do (e.g. "Running smoke security scan on target URL"). This helps generate readable step-by-step reports.

Task wording: If the user asks for 基础 / 初步 / 基础安全漏洞 / 快速 / 冒烟 / CI 门禁-style coverage, assume they want time over breadth and use mode="smoke" (and state in the report that coverage is intentionally reduced). Only use mode="deep" when they ask for 全面 / 深度 / 穷尽 scans or comparable wording.

Prerequisites

  • execute_nuclei_scan tool must be available (check the tool list).
  • If it is missing, report: "安全扫描不可用:execute_nuclei_scan 工具未加载。"

Phase 1: Run the Scan

Call execute_nuclei_scan with the target URL. You do not need to write raw shell commands; the tool automatically handles nuclei subprocess execution, JSONL parsing, and result summarization.

Choose a smoke or deep mode based on the user's prompt.

Example:

json
{
  "url": "https://example.com",
  "scan_types": "xss,sqli,cve",
  "mode": "smoke"
}

Parameter notes:

  • url — the exact target URL.
  • scan_types — Comma-separated classes of vulnerabilities (cve,xss,sqli,misconfig,exposure).
  • mode — "smoke" for a fast scan (omits OAST templates, shorter timeouts), "deep" for a comprehensive scan (slower).

Do not run a second full Nuclei scan against the same URL and the same (or broader) -tags just to “confirm how many hits there are” or to “see if there was only one finding.” The first scan's output is the source of truth.

Show full SKILL.md (141 more words)Show less

Phase 2: Report

The execute_nuclei_scan tool returns a pre-formatted, translated text summary grouped by severity (Critical, High, Medium, Low, Info), including template IDs, names, and affected URLs.

Structure your final step response to the user by echoing this formatted text. For example:

安全扫描完成(Nuclei):共发现 N 个问题。

● Critical (1个):
  - Log4j RCE (CVE-2021-44228) — https://example.com/api/login

● High (2个):
  - SQL Injection (sqli-detect) — https://example.com/search?q=
  - Reflected XSS (xss-detect) — https://example.com/error?msg=

● Medium (1个):
  - Missing X-Frame-Options header (x-frame-options) — https://example.com/

扫描模式:smoke
扫描范围:tags=xss,sqli,cve

If no findings:

安全扫描完成(Nuclei):未发现已知漏洞。
扫描模式:smoke
扫描范围:tags=xss,sqli,cve

Set your overall test status to:

  • failed if any Critical or High findings.
  • warning if only Medium/Low findings.
  • passed if no findings.

Troubleshooting: [FTL] no templates provided for scan

If the tool returns a warning that nuclei failed because there were no templates provided, it means the running environment (Docker container or local host) has an empty template library. There is no in-agent fix for this; the environment administrator must ensure nuclei -update-templates succeeds during image build or initialization. In this case, report the failure as a [warning] and explain that the environment lacks nuclei templates.

© MigoXLab, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in webqa_agent/executor/flash/skills/nuclei-scan of MigoXLab/webqa-agent.

Open the folder on GitHubat commit aa156d4

Compare with similar skills

Nuclei Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nuclei Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nuclei Scan this skillMigoXLab/webqa-agent232—~846Automated safety check: PassApache-2.0
Audit Prepccashwell/evm-cortex131—~1.4kAutomated safety check: PassMIT
Generate Report Headermaslennikov-ig/claude-code-orchestrator-kit260—~1.2kAutomated safety check: PassCustom licence
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT

Similar skills

  • Audit Prep

    ccashwell/evm-cortex

    A skill your agent uses when preparing a codebase for security audit.

    131 GitHub stars~1.4k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Generate Report Header

    maslennikov-ig/claude-code-orchestrator-kit

    Create standardized report headers with metadata for all agent-generated reports.

    260 GitHub stars~1.2k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 2 days ago
    SecurityAuto-check: notes

More from MigoXLab/webqa-agent

  • UI Audit

    MigoXLab/webqa-agent

    UI audit for hierarchy, accessibility, and UX. An agent skill from MigoXLab/webqa-agent.

    232 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Button Check

    MigoXLab/webqa-agent

    Traverse all interactive elements on the page — click clickables, fill inputs — and verify no errors.

    232 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Plan

    MigoXLab/webqa-agent

    Decompose a task into steps with completion checkpoints. An agent skill from MigoXLab/webqa-agent.

    232 GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Recovery

    MigoXLab/webqa-agent

    Structured error recovery for failed or ineffective browser actions.

    232 GitHub stars~1.1k tokensUpdated 3 mo ago
    Auto-check passed
  • Webqa

    MigoXLab/webqa-agent

    Use WebQA to test websites, web pages, URLs, login flows, search flows, forms, navigation, and core user journeys with an AI browser QA agent.

    232 GitHub stars~394 tokensUpdated 3 mo ago
    Auto-check passed

Questions about Nuclei Scan

What does Nuclei Scan do?

Run a Nuclei security scan against the target URL and report findings by severity. Nuclei Scan is an agent skill from MigoXLab/webqa-agent. Run a Nuclei security scan against the target URL and report findings by severity.

When should I use Nuclei Scan?

Nuclei Scan fits situations like: tasks that involve Security review.

How do I install Nuclei Scan in Claude Code?

Run `npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a claude-code`. Or copy the skill folder (webqa_agent/executor/flash/skills/nuclei-scan in MigoXLab/webqa-agent) into .claude/skills/nuclei-scan in your project. Claude Code loads it when a task matches its description.

How do I install Nuclei Scan in Codex?

Run `npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a codex`. Or copy the skill folder (webqa_agent/executor/flash/skills/nuclei-scan in MigoXLab/webqa-agent) into .agents/skills/nuclei-scan in your project. Codex loads it when a task matches its description.

Can I use Nuclei Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuclei-scan, .gemini/skills/nuclei-scan, .github/skills/nuclei-scan and .opencode/skills/nuclei-scan in your project.

What does Nuclei Scan need to run?

SKILL.md names no scripts, command-line tools or credentials: Nuclei Scan is instructions for the agent only. Our summary lists: Docker.

Does Nuclei Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nuclei Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nuclei Scan use?

Nuclei Scan is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nuclei Scan use?

About 846 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nuclei Scan?

Skills that share tags, products or a category with Nuclei Scan: Audit Prep (ccashwell/evm-cortex, 131 stars), Generate Report Header (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars) and Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nuclei Scan?

MigoXLab (a GitHub organization) maintains it in MigoXLab/webqa-agent, which has 232 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 2, 2026.

Source: MigoXLab/webqa-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.