CodeQL Security Scan
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
$ npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ParzivalHack/PySpector pyspector-security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pyspector-security-audit" agent skill from https://github.com/ParzivalHack/PySpector/tree/main into .claude/skills/pyspector-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyspector-security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ParzivalHack/PySpector pyspector-security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pyspector-security-audit" agent skill from https://github.com/ParzivalHack/PySpector/tree/main into .agents/skills/pyspector-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyspector-security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ParzivalHack/PySpector pyspector-security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pyspector-security-audit" agent skill from https://github.com/ParzivalHack/PySpector/tree/main into .cursor/skills/pyspector-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyspector-security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ParzivalHack/PySpector pyspector-security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pyspector-security-audit" agent skill from https://github.com/ParzivalHack/PySpector/tree/main into .gemini/skills/pyspector-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyspector-security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ParzivalHack/PySpector pyspector-security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pyspector-security-audit" agent skill from https://github.com/ParzivalHack/PySpector/tree/main into .github/skills/pyspector-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyspector-security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ParzivalHack/PySpector pyspector-security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pyspector-security-audit" agent skill from https://github.com/ParzivalHack/PySpector/tree/main into .opencode/skills/pyspector-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pyspector-security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pyspector-security-auditRun a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
Pyspector Security Audit is an agent skill from ParzivalHack/PySpector. Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. Use this skill whenever the user asks for a security audit, vulnerability scan, SAST scan, code security review, or dependency/CVE check of a Python codebase or repository, including phrasing like "check this repo for vulnerabilities," "is my code secure," "audit my project," "scan for CVEs," or "find security issues." Also trigger if the user mentions PySpector by name for any reason…
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 85 other files, including scripts (for example `.github/SECURITY.md`, `.pre-commit-config.yaml` and `.pre-commit-hooks.yaml`).
It sits in Security, covering Security review, Static analysis and SAST and Vulnerability scanning. It works with Python, Rust and GitHub. The repository describes itself as: PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. It leverages a powerful Rust core to deliver high-speed… The licence is Apache-2.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a971f1f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
pipcargopython3curlshrustcgitollamaFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
sh.rustup.rsAlso links to:
rustup.rsFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pyspector Security Audit loads about 3.5k tokens when it runs. Until then it costs about 261 tokens; SKILL.md has 1,855 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
cargo --version || (curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && source "$HOME/.cargo/env"Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ParzivalHack/PySpector at commit a971f1f, republished under its Apache-2.0 licence (© ParzivalHack). 1,855 words, ~3,477 tokens.
.claude/skills/pyspector-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 82 other files; get the full folder from GitHub.Drive an end-to-end Python codebase security audit with PySpector: install, verify, learn the CLI, recon the codebase, scan with the right flags, verify, report.
PySpector is a Rust-core, Python-CLI SAST tool with a flow-sensitive, inter-procedural taint engine. Its ruleset spans regex (secrets/config), AST (anti-patterns), and graph/taint (data-flow vulnerability chains), plus optional AI/LLM-specific rules and dependency CVE checks. Full project context: https://github.com/ParzivalHack/PySpector
pyspector --help and pyspector scan --help to get the real, current flag set. Never assume flags from this document aloneTreat steps 3 and 4 as mandatory even if you already "know" PySpector's flags from a previous run. The tool evolves, and --help output is ground truth. Never fabricate a flag that didn't show up in --help.
Check first:
pyspector --version || pip show pyspectorIf it's missing, PySpector's own docs say the supported path is PyPI, not manual OS-specific binary downloads. There's no separate per-OS release artifact to fetch; pip install pyspector builds/pulls the right thing for the current platform. So "install it based on the OS the agent is running on" in practice means: pick the right shell/venv invocation for the OS, not a different download URL.
Rust toolchain (hard requirement). PySpector's Rust core means rustc and cargo must be present, the project's own FAQ states this explicitly. Check first, install only if missing.
On Linux/macOS:
cargo --version || (curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y && source "$HOME/.cargo/env")On Windows: first check whether rustc/cargo are already available. If not, check whether a rustup-init.exe installer is already present on the system (e.g. in the user's Downloads folder or a known path); if it is, run it. If no installer is present and you don't have shell access to the user's machine to download and run one yourself, don't try to fetch and execute an installer silently: direct the user to https://rustup.rs/ and ask them to download and run it themselves, then confirm back with you once it's done so you can proceed to verification.
Python. PySpector supports Python 3.9 to 3.14. The project recommends a dedicated venv (3.14 if available, but any supported version works):
python3 -m venv venv
source venv/bin/activate # Windows: .\venv\Scripts\Activate.ps1
pip install --upgrade pip
pip install pyspectorIf a venv isn't appropriate for the environment you're in (e.g. an ephemeral agent sandbox), a plain pip install pyspector --break-system-packages (Linux) or pip install pyspector is fine. The venv is a recommendation for the human workflow, not a functional requirement for the scan itself.
Don't proceed on faith. Confirm all of:
rustc --version
cargo --version
python3 --version
pyspector --versionIf any of these fail, stop and fix it before scanning. A broken Rust toolchain in particular will surface as a cryptic scan failure later rather than a clean error at install time.
Always run these before scanning, even if you recall the flags from a previous session, and treat their output as the only source of truth for what flags exist and what they do:
pyspector --help
pyspector scan --helpDo not hardcode or assume a flag list. Parse whatever the live output actually shows: available options, their exact spelling, defaults, and descriptions. If something in this skill (like the decision rules below referencing --ai or --supply-chain) doesn't match what --help shows, trust --help.
Two commands surfaced by pyspector --help are interactive-only and out of scope for this skill's autonomous workflow:
pyspector triage <report.json>: an interactive TUI for a human to mark findings as false positives and save a .pyspector_baseline.json. Don't invoke this yourself; if the user wants to triage findings interactively, tell them to run it themselves in their own terminal. If a baseline file already exists in the repo root from a prior human triage session, subsequent scans will pick it up automatically and suppress previously dismissed findings.pyspector watch <path>: continuous re-scan on file change, meant for a human to run in their own terminal during active development. Don't invoke this yourself; if relevant, tell the user they can run it themselves.Before scanning, spend a short pass understanding what you're actually looking at, then pick flags accordingly using whatever flags Step 3 actually confirmed exist. Don't just run a bare default scan.
Checks to run:
# Age / maturity signals
git log -1 --format=%cd 2>/dev/null # last commit date, if it's a git repo
find . -name "requirements*.txt" -o -name "pyproject.toml" -o -name "Pipfile*" -o -name "poetry.lock" | head
# Dependency pinning style (unpinned or very old pins : higher supply-chain risk)
cat requirements.txt 2>/dev/null || cat pyproject.toml 2>/dev/null
# AI/LLM usage signals
grep -RIl -E "openai|anthropic|langchain|llama[_-]index|transformers|litellm|ollama|cohere|google\.generativeai|vertexai" --include="*.py" . 2>/dev/null | headDecision rules (apply these, and combine flags freely, they're not mutually exclusive):
Set severity threshold based on intent: for a genuine security audit, use the lowest severity threshold (see what --help shows as the default/lowest option) to see everything, then let the verification step (Step 6) do the filtering. Don't pre-filter by raising the severity threshold, since that would hide true positives from your own verification pass, not just noise.
Always emit JSON as the primary artifact, you need structured output to parse and verify findings programmatically. Generate HTML at the end for the human, from the same run or a parallel run with identical flags.
For a remote repository instead of a local path, PySpector's --url option works only with public GitHub and GitLab repositories. It cannot pull from private repos or other git hosts, so confirm the repo is public before relying on this path; if it's private, ask the user for local access to the code instead (a local clone or an uploaded copy).
Don't default to SARIF output for this workflow. SARIF exists for CI/CD ingestion into platforms like GitHub Code Scanning, which isn't the context here (per PySpector's own docs on SARIF). If the user says the output specifically needs to feed a downstream tool that expects SARIF, honor that instead, but default to JSON and HTML.
This is the step that turns "a scanner ran" into "a security audit." Do not hand the user PySpector's raw output as-is. SAST tools, PySpector included, will produce some false positives, especially on complex taint chains or when a sanitizer isn't recognized.
For every finding at MEDIUM severity or above (adjust the threshold down if the codebase is small enough to review everything):
Only "Confirmed true positive" and "Needs human judgement" findings go in the final report to the user. Silently dropping false positives without explanation is fine for the summary, but keep your reasoning available if the user asks why a raw PySpector finding didn't make the cut.
Do not attempt to actually exploit anything (no live PoC execution, no reaching out to external services, no running injected payloads). This is a static re-read and reasoning pass only, not a penetration test.
Default to HTML when the deliverable is for the user to read, PySpector's own HTML report is fine to hand over directly, or you can write your own summary. Use JSON instead only if the user says the output needs to be consumed by another tool or script.
Your own summary to the user (in addition to, or instead of, PySpector's raw report) should include:
openai and langchain")If findings exist, offer to help fix them as a natural next step, but that's a separate task from the audit itself; don't start patching without the user asking.
pyspector --help / pyspector scan --help output over anything written in this document~/.cargo/env, do that before retrying pyspector commands in the same session.pyspector_baseline.json in the repo root from a prior human triage session will suppress previously-dismissed findings automatically. Mention this to the user if the finding count looks lower than expectedpyspector watch and pyspector triage are interactive tools for the user to run themselves, never invoke them on the user's behalf--url only works for public GitHub/GitLab repos; for private repos, work from a local copy instead© ParzivalHack, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 82 other files (scripts) in the repository root of ParzivalHack/PySpector.
Open the folder on GitHubat commit a971f1f
Pyspector Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pyspector Security Audit this skillParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Security AuditTheDecipherist/claude-code-mastery | 550 | — | ~1.3k | Automated safety check: Notes | MIT | |
| SkepticRaoFoundation/subtensor | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT |
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
RaoFoundation/subtensor
Run the security-focused Skeptic persona on the local working tree's diff against a base branch.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
Categories
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. Pyspector Security Audit is an agent skill from ParzivalHack/PySpector.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
Pyspector Security Audit fits situations like: the user asks for a security audit; vulnerability scan; code security review; dependency/CVE check of a Python codebase.
Run `npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a claude-code`. Or copy the skill folder (the ParzivalHack/PySpector repository) into .claude/skills/pyspector-security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a codex`. Or copy the skill folder (the ParzivalHack/PySpector repository) into .agents/skills/pyspector-security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ParzivalHack/PySpector --skill pyspector-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pyspector-security-audit, .gemini/skills/pyspector-security-audit, .github/skills/pyspector-security-audit and .opencode/skills/pyspector-security-audit in your project.
Going by SKILL.md and its folder, Pyspector Security Audit needs a shell for the scripts in its folder and the command-line tools its instructions call (pip, cargo, python3, curl, sh and rustc). Our summary lists: Python 3; A Bash shell.
SKILL.md names 2 domains. In commands or code: sh.rustup.rs; the agent is likely to contact it when it follows the instructions. As links in the text: rustup.rs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pipes a well-known installer script into a shell), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Pyspector Security Audit is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pyspector Security Audit: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Kedro Security Review (kedro-org/kedro, 11k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars) and Skeptic (RaoFoundation/subtensor, 389 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ParzivalHack (a GitHub user) maintains it in ParzivalHack/PySpector, which has 151 GitHub stars. The repository was last updated on October 7, 2026.
Source: ParzivalHack/PySpector on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.