Audit Prep
ccashwell/evm-cortex
A skill your agent uses when preparing a codebase for security audit.
Run a Nuclei security scan against the target URL and report findings by severity.
$ npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install MigoXLab/webqa-agent nuclei-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/MigoXLab/webqa-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/webqa_agent/executor/flash/skills/nuclei-scan .claude/skills/nuclei-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nuclei-scan" agent skill from https://github.com/MigoXLab/webqa-agent/tree/main/webqa_agent/executor/flash/skills/nuclei-scan into .claude/skills/nuclei-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuclei-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/MigoXLab/webqa-agent/tree/main/webqa_agent/executor/flash/skills/nuclei-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install MigoXLab/webqa-agent nuclei-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MigoXLab/webqa-agent.git skills-src && mkdir -p .agents/skills && cp -r skills-src/webqa_agent/executor/flash/skills/nuclei-scan .agents/skills/nuclei-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nuclei-scan" agent skill from https://github.com/MigoXLab/webqa-agent/tree/main/webqa_agent/executor/flash/skills/nuclei-scan into .agents/skills/nuclei-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuclei-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install MigoXLab/webqa-agent nuclei-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MigoXLab/webqa-agent.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/webqa_agent/executor/flash/skills/nuclei-scan .cursor/skills/nuclei-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nuclei-scan" agent skill from https://github.com/MigoXLab/webqa-agent/tree/main/webqa_agent/executor/flash/skills/nuclei-scan into .cursor/skills/nuclei-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuclei-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/MigoXLab/webqa-agent.git --path webqa_agent/executor/flash/skills/nuclei-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install MigoXLab/webqa-agent nuclei-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MigoXLab/webqa-agent.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/webqa_agent/executor/flash/skills/nuclei-scan .gemini/skills/nuclei-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nuclei-scan" agent skill from https://github.com/MigoXLab/webqa-agent/tree/main/webqa_agent/executor/flash/skills/nuclei-scan into .gemini/skills/nuclei-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuclei-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install MigoXLab/webqa-agent nuclei-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/MigoXLab/webqa-agent.git skills-src && mkdir -p .github/skills && cp -r skills-src/webqa_agent/executor/flash/skills/nuclei-scan .github/skills/nuclei-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nuclei-scan" agent skill from https://github.com/MigoXLab/webqa-agent/tree/main/webqa_agent/executor/flash/skills/nuclei-scan into .github/skills/nuclei-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuclei-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install MigoXLab/webqa-agent nuclei-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MigoXLab/webqa-agent.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/webqa_agent/executor/flash/skills/nuclei-scan .opencode/skills/nuclei-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nuclei-scan" agent skill from https://github.com/MigoXLab/webqa-agent/tree/main/webqa_agent/executor/flash/skills/nuclei-scan into .opencode/skills/nuclei-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nuclei-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nuclei-scanRun a Nuclei security scan against the target URL and report findings by severity.
Nuclei Scan is an agent skill from MigoXLab/webqa-agent. Run a Nuclei security scan against the target URL and report findings by severity.
Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review. The repository describes itself as: Autonomous web browser agent that audits performance, functionality & UX for engineers and vibe-coding creators. 网站自主评估测试 Agent,支持 GUI/CLI 一键完成性能、功能使用与交互体验的测试评估. The licence is Apache-2.0.
2 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aa156d4. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nuclei Scan loads about 846 tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 378 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from MigoXLab/webqa-agent at commit aa156d4, republished under its Apache-2.0 licence (© MigoXLab). 378 words, ~846 tokens.
.claude/skills/nuclei-scan/SKILL.md (or your agent's skills folder).Run a security vulnerability scan against the target URL using the built-in execute_nuclei_scan tool, and produce a structured security report.
Important: Before each tool call, output a short one-line description of what you are about to do (e.g. "Running smoke security scan on target URL"). This helps generate readable step-by-step reports.
Task wording: If the user asks for 基础 / 初步 / 基础安全漏洞 / 快速 / 冒烟 / CI 门禁-style coverage, assume they want time over breadth and use mode="smoke" (and state in the report that coverage is intentionally reduced). Only use mode="deep" when they ask for 全面 / 深度 / 穷尽 scans or comparable wording.
execute_nuclei_scan tool must be available (check the tool list).Call execute_nuclei_scan with the target URL. You do not need to write raw shell commands; the tool automatically handles nuclei subprocess execution, JSONL parsing, and result summarization.
Choose a smoke or deep mode based on the user's prompt.
Example:
{
"url": "https://example.com",
"scan_types": "xss,sqli,cve",
"mode": "smoke"
}Parameter notes:
url — the exact target URL.scan_types — Comma-separated classes of vulnerabilities (cve,xss,sqli,misconfig,exposure).mode — "smoke" for a fast scan (omits OAST templates, shorter timeouts), "deep" for a comprehensive scan (slower).Do not run a second full Nuclei scan against the same URL and the same (or broader) -tags just to “confirm how many hits there are” or to “see if there was only one finding.” The first scan's output is the source of truth.
The execute_nuclei_scan tool returns a pre-formatted, translated text summary grouped by severity (Critical, High, Medium, Low, Info), including template IDs, names, and affected URLs.
Structure your final step response to the user by echoing this formatted text. For example:
安全扫描完成(Nuclei):共发现 N 个问题。
● Critical (1个):
- Log4j RCE (CVE-2021-44228) — https://example.com/api/login
● High (2个):
- SQL Injection (sqli-detect) — https://example.com/search?q=
- Reflected XSS (xss-detect) — https://example.com/error?msg=
● Medium (1个):
- Missing X-Frame-Options header (x-frame-options) — https://example.com/
扫描模式:smoke
扫描范围:tags=xss,sqli,cveIf no findings:
安全扫描完成(Nuclei):未发现已知漏洞。
扫描模式:smoke
扫描范围:tags=xss,sqli,cveSet your overall test status to:
failed if any Critical or High findings.warning if only Medium/Low findings.passed if no findings.[FTL] no templates provided for scanIf the tool returns a warning that nuclei failed because there were no templates provided, it means the running environment (Docker container or local host) has an empty template library.
There is no in-agent fix for this; the environment administrator must ensure nuclei -update-templates succeeds during image build or initialization. In this case, report the failure as a [warning] and explain that the environment lacks nuclei templates.
© MigoXLab, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in webqa_agent/executor/flash/skills/nuclei-scan of MigoXLab/webqa-agent.
Open the folder on GitHubat commit aa156d4
Nuclei Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nuclei Scan this skillMigoXLab/webqa-agent | 232 | — | ~846 | Automated safety check: Pass | Apache-2.0 | |
| Audit Prepccashwell/evm-cortex | 131 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Generate Report Headermaslennikov-ig/claude-code-orchestrator-kit | 260 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Kubernetes Network Security Auditkubeshark/kubeshark | 12k | — | ~7.3k | Automated safety check: Notes | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT |
ccashwell/evm-cortex
A skill your agent uses when preparing a codebase for security audit.
maslennikov-ig/claude-code-orchestrator-kit
Create standardized report headers with metadata for all agent-generated reports.
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
kubeshark/kubeshark
Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
MigoXLab/webqa-agent
UI audit for hierarchy, accessibility, and UX. An agent skill from MigoXLab/webqa-agent.
MigoXLab/webqa-agent
Traverse all interactive elements on the page — click clickables, fill inputs — and verify no errors.
MigoXLab/webqa-agent
Decompose a task into steps with completion checkpoints. An agent skill from MigoXLab/webqa-agent.
MigoXLab/webqa-agent
Structured error recovery for failed or ineffective browser actions.
MigoXLab/webqa-agent
Use WebQA to test websites, web pages, URLs, login flows, search flows, forms, navigation, and core user journeys with an AI browser QA agent.
Categories
Run a Nuclei security scan against the target URL and report findings by severity. Nuclei Scan is an agent skill from MigoXLab/webqa-agent. Run a Nuclei security scan against the target URL and report findings by severity.
Nuclei Scan fits situations like: tasks that involve Security review.
Run `npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a claude-code`. Or copy the skill folder (webqa_agent/executor/flash/skills/nuclei-scan in MigoXLab/webqa-agent) into .claude/skills/nuclei-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a codex`. Or copy the skill folder (webqa_agent/executor/flash/skills/nuclei-scan in MigoXLab/webqa-agent) into .agents/skills/nuclei-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MigoXLab/webqa-agent --skill nuclei-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nuclei-scan, .gemini/skills/nuclei-scan, .github/skills/nuclei-scan and .opencode/skills/nuclei-scan in your project.
SKILL.md names no scripts, command-line tools or credentials: Nuclei Scan is instructions for the agent only. Our summary lists: Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nuclei Scan is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 846 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nuclei Scan: Audit Prep (ccashwell/evm-cortex, 131 stars), Generate Report Header (maslennikov-ig/claude-code-orchestrator-kit, 260 stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars) and Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
MigoXLab (a GitHub organization) maintains it in MigoXLab/webqa-agent, which has 232 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on July 2, 2026.
Source: MigoXLab/webqa-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.