Agent skill

Vulnerability Scanning

by secondsky in secondsky/claude-skills

Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

MITAuto-check passedSecurity

Install Vulnerability Scanning

skills CLI
$ npx skills add secondsky/claude-skills --skill vulnerability-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install secondsky/claude-skills vulnerability-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/secondsky/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/vulnerability-scanning/skills/vulnerability-scanning .claude/skills/vulnerability-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnerability-scanning
GitHub stars
227
Token cost
~799 tokens
SKILL.md length
65 words
Files
1
Skills in repo
169
Repo updated
First seen
Licence
MIT

At a glance

Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

  • CI/CD security gates
  • SKILL.md covers Dependency Scanning, Container Scanning (Trivy), GitHub Actions Integration and Code Analysis (Bandit for…, plus 3 more sections
  • Calls trivy and npm; needs SNYK_TOKEN
  • Pre-deployment audits

What it does

Vulnerability Scanning is an agent skill from secondsky/claude-skills. Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit. Use for CI/CD security gates, pre-deployment audits, compliance requirements, or encountering CVE detection, outdated packages, license compliance, SBOM generation errors.

Its SKILL.md is about 800 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Vulnerability scanning, CI/CD and Dependency management. It works with Trivy and Snyk. The repository describes itself as: Production-ready skills for Claude Code CLI - Cloudflare, React, Tailwind v4, and AI integrations. The licence is MIT.

When your agent uses it

  • CI/CD security gates
  • Pre-deployment audits
  • Compliance requirements
  • Encountering CVE detection

Example prompts

  • “/vulnerability-scanning”

Requirements

  • Node.js
  • Docker
  • A credential in SNYK_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 8837836. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • trivy
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SNYK_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnerability Scanning loads about 799 tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 65 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~799

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from secondsky/claude-skills at commit 8837836, republished under its MIT licence (© secondsky). 65 words, ~799 tokens.

Download SKILL.mdSave it as .claude/skills/vulnerability-scanning/SKILL.md (or your agent's skills folder).
name
vulnerability-scanning
description
Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit. Use for CI/CD security gates, pre-deployment audits, compliance requirements, or encountering CVE detection, outdated packages, license compliance, SBOM generation errors.
license
MIT
metadata.keywords
Trivy, Snyk, npm-audit, OWASP, dependency-scanning, CVE, security-vulnerabilities, outdated-packages, license-compliance, SCA, SBOM, container-scanning…

Vulnerability Scanning

Automate security vulnerability detection across code, dependencies, and containers.

Dependency Scanning

bash
# npm audit
npm audit --audit-level=high

# Snyk
snyk test --severity-threshold=high

# Safety (Python)
safety check --full-report

Container Scanning (Trivy)

bash
# Scan container image
trivy image myapp:latest --severity HIGH,CRITICAL

# Scan filesystem
trivy fs --scanners vuln,secret .

GitHub Actions Integration

yaml
name: Security Scan

on: [push, pull_request]

jobs:
  security:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Run Trivy vulnerability scanner
        uses: aquasecurity/trivy-action@0.28.0
        with:
          scan-type: 'fs'
          severity: 'CRITICAL,HIGH'
          exit-code: '1'

      - name: Run Snyk
        uses: snyk/actions/node@v3
        env:
          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
        with:
          args: --severity-threshold=high

      - name: npm audit
        run: npm audit --audit-level=high

Code Analysis (Bandit for Python)

bash
bandit -r src/ -ll -ii

Node.js Scanner

javascript
const { execSync } = require('child_process');

function runScan(command) {
  try {
    return JSON.parse(execSync(command, { stdio: ['pipe', 'pipe', 'ignore'] }).toString());
  } catch (err) {
    // A tool may be missing, exit non-zero, or print non-JSON output (e.g.
    // trivy progress text when not on a TTY). Treat that as "no parseable
    // result" rather than crashing the scanner.
    console.warn(`Scan command failed or returned non-JSON: ${command}`);
    return null;
  }
}

function runSecurityScan() {
  const results = {
    npm: runScan('npm audit --json'),
    trivy: runScan('trivy fs --quiet --format json .')
  };

  if (!results.npm || !results.npm.metadata) {
    console.warn('npm audit produced no metadata; skipping npm checks');
  } else {
    const critical = results.npm.metadata?.vulnerabilities?.critical || 0;
    if (critical > 0) {
      console.error(`Found ${critical} critical vulnerabilities`);
      process.exit(1);
    }
  }
}

Best Practices

  • Integrate scanning in CI/CD pipeline
  • Fail builds on high/critical findings
  • Scan dependencies and containers
  • Track vulnerabilities over time
  • Document accepted false positives

Tools

  • Trivy (containers, filesystem)
  • Snyk (dependencies, code)
  • npm audit / yarn audit
  • Bandit (Python)
  • OWASP Dependency-Check

© secondsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in plugins/vulnerability-scanning/skills/vulnerability-scanning of secondsky/claude-skills.

Open the folder on GitHubat commit 8837836

Compare with similar skills

Vulnerability Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnerability Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnerability Scanning this skillsecondsky/claude-skills227—~799Automated safety check: PassMIT
Sca TrivyAgentSecOps/SecOpsAgentKit2202 repos~3.7kAutomated safety check: PassCustom licence
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Performing Sca Dependency Scanning With Snykmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0
Managing Vulnerabilitiesancoleman/ai-design-components526—~3.8kAutomated safety check: PassMIT
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0

Similar skills

  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Performing Sca Dependency Scanning With Snyk

    mukul975/Anthropic-Cybersecurity-Skills

    This skill covers implementing Software Composition Analysis (SCA) using Snyk to detect vulnerable open-source dependencies in CI/CD pipelines.

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Managing Vulnerabilities

    ancoleman/ai-design-components

    Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

    526 GitHub stars~3.8k tokensUpdated 10 mo ago
    SecurityAuto-check passed
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Supply Chain Security

    zhaoxuya520/reverse-skill

    A skill your agent uses for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

    40k GitHub starsUsed in 4 repos~953 tokens
    SecurityAuto-check: warnings

More from secondsky/claude-skills

All 169 skills in this repo
  • Tanstack AI

    secondsky/claude-skills

    TanStack AI (alpha) provider-agnostic type-safe chat with streaming for OpenAI, Anthropic, Gemini, Ollama.

    227 GitHub starsUsed in 1 repo~3.6k tokens
    Auto-check: notes
  • Auto Animate

    secondsky/claude-skills

    AutoAnimate (@formkit/auto-animate) zero-config animations for React.

    227 GitHub stars~2.9k tokensUpdated 10 days ago
    Auto-check passed
  • Base UI React

    secondsky/claude-skills

    MUI Base UI unstyled React components with Floating UI. An agent skill from secondsky/claude-skills.

    227 GitHub stars~1.9k tokensUpdated 10 days ago
    Auto-check passed
  • Cloudflare Images

    secondsky/claude-skills

    This skill should be used when the user asks to "upload images to Cloudflare", "implement direct creator upload", "configure image transformations", "optimize WebP/AVIF", "create image variants"…

    227 GitHub stars~3.6k tokensUpdated 10 days ago
    Auto-check: notes
  • Cloudflare Nextjs

    secondsky/claude-skills

    Deploy Next.js to Cloudflare Workers via the OpenNext adapter (@opennextjs/cloudflare).

    227 GitHub stars~5.3k tokensUpdated 10 days ago
    Auto-check: notes
  • Cloudflare Sandbox

    secondsky/claude-skills

    Cloudflare Sandboxes SDK for secure code execution in Linux containers at edge.

    227 GitHub stars~4.5k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Vulnerability Scanning

What does Vulnerability Scanning do?

Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit. Vulnerability Scanning is an agent skill from secondsky/claude-skills. Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit.

When should I use Vulnerability Scanning?

Vulnerability Scanning fits situations like: CI/CD security gates; pre-deployment audits; compliance requirements; encountering CVE detection.

How do I install Vulnerability Scanning in Claude Code?

Run `npx skills add secondsky/claude-skills --skill vulnerability-scanning -a claude-code`. Or copy the skill folder (plugins/vulnerability-scanning/skills/vulnerability-scanning in secondsky/claude-skills) into .claude/skills/vulnerability-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Vulnerability Scanning in Codex?

Run `npx skills add secondsky/claude-skills --skill vulnerability-scanning -a codex`. Or copy the skill folder (plugins/vulnerability-scanning/skills/vulnerability-scanning in secondsky/claude-skills) into .agents/skills/vulnerability-scanning in your project. Codex loads it when a task matches its description.

Can I use Vulnerability Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add secondsky/claude-skills --skill vulnerability-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-scanning, .gemini/skills/vulnerability-scanning, .github/skills/vulnerability-scanning and .opencode/skills/vulnerability-scanning in your project.

What does Vulnerability Scanning need to run?

Going by SKILL.md and its folder, Vulnerability Scanning needs the command-line tools its instructions call (trivy and npm) and credentials named SNYK_TOKEN. Our summary lists: Node.js; Docker; A credential in SNYK_TOKEN.

Does Vulnerability Scanning access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Vulnerability Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vulnerability Scanning use?

Vulnerability Scanning is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulnerability Scanning use?

About 799 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vulnerability Scanning?

Skills that share tags, products or a category with Vulnerability Scanning: Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Performing Sca Dependency Scanning With Snyk (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Managing Vulnerabilities (ancoleman/ai-design-components, 526 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnerability Scanning?

secondsky (a GitHub user) maintains it in secondsky/claude-skills, which has 227 GitHub stars. The repository holds 169 skills in this directory. The repository was last updated on September 28, 2026.

Source: secondsky/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.