Agent skill

Sca Audit

by OWASP in OWASP/secure-agent-playbook

Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

CC-BY-4.0Auto-check passedSecurity

Install Sca Audit

skills CLI
$ npx skills add OWASP/secure-agent-playbook --skill sca-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OWASP/secure-agent-playbook sca-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OWASP/secure-agent-playbook.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/code-security-skills/skills/sca-audit .claude/skills/sca-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sca-audit
GitHub stars
187
Token cost
~494 tokens
SKILL.md length
198 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook.

  • Works in 4 steps: Identify Dependency Manifests — Scan for… → Run Vulnerability Scan — Use available… → Analyze Results — For each… → …
  • Reviewing dependency files (package.json
  • SKILL.md covers Steps, Output and OWASP References
  • Calls npm, trivy and brew

What it does

Sca Audit is an agent skill from OWASP/secure-agent-playbook. Scan project dependencies for known vulnerabilities (CVEs). Use when reviewing dependency files (package.json, requirements.txt, go.mod, pom.xml, Gemfile, Cargo.toml, etc.), triaging Dependabot/Renovate alerts, or performing pre-deployment security checks.

Its SKILL.md is about 490 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Dependency management, Vulnerability scanning and Web application vulnerabilities. It works with Ruby, Rust, npm and Go. The repository describes itself as: OWASP Secure Agent Playbook Project. The licence is CC-BY-4.0.

When your agent uses it

  • Reviewing dependency files (package.json
  • Requirements.txt
  • Triaging Dependabot/Renovate alerts
  • Performing pre-deployment security checks

Example prompts

  • “/sca-audit”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify Dependency Manifests — Scan for all dependency files and lockfiles across ecosystems (Node.js, Python, Go, Java, Ruby, Rust…
  2. Run Vulnerability Scan — Use available tools in preference order
  3. Analyze Results — For each vulnerability: determine reachability (is the vulnerable code path used?), check exploitability context…
  4. Dependency Health — Beyond CVEs, flag unmaintained packages (2+ years inactive), typosquatting risks, license concerns, and version…

What it can do on your machine

Read from SKILL.md and the folder at commit 1b5fd4c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • trivy
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • osv.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sca Audit loads about 494 tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 198 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~494

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from OWASP/secure-agent-playbook at commit 1b5fd4c, republished under its CC-BY-4.0 licence (© OWASP). 198 words, ~494 tokens.

Download SKILL.mdSave it as .claude/skills/sca-audit/SKILL.md (or your agent's skills folder).
name
sca-audit
description
Scan project dependencies for known vulnerabilities (CVEs). Use when reviewing dependency files (package.json, requirements.txt, go.mod, pom.xml, Gemfile, Cargo.toml, etc.), triaging Dependabot/Renovate alerts, or performing pre-deployment security checks.
license
CC-BY-4.0

Software Composition Analysis Audit

Scan dependencies for known CVEs by following the full procedure in plays/sca-audit.md.

Steps

  1. Identify Dependency Manifests — Scan for all dependency files and lockfiles across ecosystems (Node.js, Python, Go, Java, Ruby, Rust, .NET, PHP). Prefer lockfiles for exact resolved versions.

  2. Run Vulnerability Scan — Use available tools in preference order:

    • osv-scanner --lockfile=<path> --format=json (recommended, multi-ecosystem)
    • npm audit --json (Node.js)
    • pip-audit -r requirements.txt --format=json (Python)
    • govulncheck ./... (Go)
    • trivy fs --format json --scanners vuln <path> (multi-ecosystem)
    • If no scanner is installed, stop and ask the user to install one (e.g., brew install osv-scanner). Manual analysis is not viable — even small projects have 50+ dependencies. For individual package triage, point the user to OSV.dev.
  3. Analyze Results — For each vulnerability: determine reachability (is the vulnerable code path used?), check exploitability context (deployment matters), and identify fix availability (patch vs major version bump).

  4. Dependency Health — Beyond CVEs, flag unmaintained packages (2+ years inactive), typosquatting risks, license concerns, and version pinning issues.

Output

Scan summary (ecosystems, dependency count, scanner used), findings sorted by severity using templates/finding.md, condensed table for medium/low, dependency health flags, and exact remediation commands.

OWASP References

  • A06:2021: Vulnerable and Outdated Components
  • OWASP Dependency-Check
  • OWASP SCVS

© OWASP, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/code-security-skills/skills/sca-audit of OWASP/secure-agent-playbook.

Open the folder on GitHubat commit 1b5fd4c

Compare with similar skills

Sca Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sca Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sca Audit this skillOWASP/secure-agent-playbook187—~494Automated safety check: PassCC-BY-4.0
Dep Auditorlaolaoshiren/claude-code-skills-zh878—~895Automated safety check: PassMIT
Ghost Scan Depsghostsecurity/skills408—~1.3kAutomated safety check: NotesApache-2.0
Interlinked Supply ChainQuentinCody/interlinked-cli178—~2.8kAutomated safety check: PassMIT
Cve Scansoftspark/ai-toolkit179—~1.3kAutomated safety check: NotesApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT

Similar skills

  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    878 GitHub stars~895 tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Ghost Scan Deps

    ghostsecurity/skills

    Ghost Security - Software Composition Analysis (SCA) scanner.

    408 GitHub stars~1.3k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Interlinked Supply Chain

    QuentinCody/interlinked-cli

    Respond to blocked package installs and manage the Interlinked supply-chain allowlist.

    178 GitHub stars~2.8k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Cve Scan

    softspark/ai-toolkit

    Scans deps for known CVEs via native audit (npm, pip, composer, cargo, go, bundler, dart).

    179 GitHub stars~1.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

    241 GitHub starsUsed in 2 repos~3.6k tokens
    SecurityAuto-check passed

More from OWASP/secure-agent-playbook

All 14 skills in this repo
  • Prd Securability Enhancement

    OWASP/secure-agent-playbook

    Enhance PRDs, feature specs, user stories, or product briefs with explicit OWASP ASVS coverage and FIASSE v1.0.4 SSEM implementation guidance — before code is written.

    187 GitHub stars~4.6k tokensUpdated 13 days ago
    Auto-check passed
  • Securability Engineering Review

    OWASP/secure-agent-playbook

    Score a codebase, file, or merge request against the FIASSE v1.0.4 SSEM model — 0-10 per attribute, equal-weighted pillars, evidence-backed strengths and weaknesses, prioritized recommendations…

    187 GitHub stars~4.6k tokensUpdated 13 days ago
    Auto-check passed
  • Securability Engineering

    OWASP/secure-agent-playbook

    Generate, scaffold, or refactor code so it embodies FIASSE v1.0.4 SSEM qualities by default — 10 attributes, Transparency and Least-Astonishment principles, ASVS-aligned controls, defensive boundary…

    187 GitHub stars~5.8k tokensUpdated 13 days ago
    Auto-check passed
  • Agent Security Audit

    OWASP/secure-agent-playbook

    Audit AI agent configurations for security risks — excessive permissions, prompt injection surfaces, data exfiltration paths, and missing guardrails.

    187 GitHub stars~542 tokensUpdated 13 days ago
    Auto-check passed
  • AI Security Verification

    OWASP/secure-agent-playbook

    Comprehensive AI security verification using OWASP AI Security Verification Standard (AISVS) framework.

    187 GitHub stars~876 tokensUpdated 13 days ago
    Auto-check passed
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    187 GitHub stars~744 tokensUpdated 13 days ago
    Auto-check passed

Works with

Categories

Questions about Sca Audit

What does Sca Audit do?

Scan project dependencies for known vulnerabilities (CVEs). An agent skill from OWASP/secure-agent-playbook. Sca Audit is an agent skill from OWASP/secure-agent-playbook. Scan project dependencies for known vulnerabilities (CVEs).

When should I use Sca Audit?

Sca Audit fits situations like: reviewing dependency files (package.json; requirements.txt; triaging Dependabot/Renovate alerts; performing pre-deployment security checks.

How do I install Sca Audit in Claude Code?

Run `npx skills add OWASP/secure-agent-playbook --skill sca-audit -a claude-code`. Or copy the skill folder (plugins/code-security-skills/skills/sca-audit in OWASP/secure-agent-playbook) into .claude/skills/sca-audit in your project. Claude Code loads it when a task matches its description.

How do I install Sca Audit in Codex?

Run `npx skills add OWASP/secure-agent-playbook --skill sca-audit -a codex`. Or copy the skill folder (plugins/code-security-skills/skills/sca-audit in OWASP/secure-agent-playbook) into .agents/skills/sca-audit in your project. Codex loads it when a task matches its description.

Can I use Sca Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OWASP/secure-agent-playbook --skill sca-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sca-audit, .gemini/skills/sca-audit, .github/skills/sca-audit and .opencode/skills/sca-audit in your project.

What does Sca Audit need to run?

Going by SKILL.md and its folder, Sca Audit needs the command-line tools its instructions call (npm, trivy and brew). Our summary lists: Node.js.

Does Sca Audit access the network?

SKILL.md names 1 domain. As links in the text: osv.dev. This is read from the text; nothing was executed.

Is Sca Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sca Audit use?

Sca Audit is published under the CC-BY-4.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sca Audit use?

About 494 tokens (SKILL.md is roughly 2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sca Audit?

Skills that share tags, products or a category with Sca Audit: Dep Auditor (laolaoshiren/claude-code-skills-zh, 878 stars), Ghost Scan Deps (ghostsecurity/skills, 408 stars), Interlinked Supply Chain (QuentinCody/interlinked-cli, 178 stars) and Cve Scan (softspark/ai-toolkit, 179 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sca Audit?

OWASP (a GitHub organization) maintains it in OWASP/secure-agent-playbook, which has 187 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 25, 2026.

Source: OWASP/secure-agent-playbook on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.