Agent skill

Vbs Scan Security

by tanviet12 in tanviet12/vbsec

A skill your agent uses when scanning code for security vulnerabilities.

MITAuto-check: notesSecurity

Install Vbs Scan Security

skills CLI
$ npx skills add tanviet12/vbsec --skill vbs-scan-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tanviet12/vbsec vbs-scan-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tanviet12/vbsec.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/codex/vbs-scan-security .claude/skills/vbs-scan-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vbs-scan-security
GitHub stars
289
Token cost
~5.3k tokens
SKILL.md length
1,932 words
Files
84 (incl. references)
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when scanning code for security vulnerabilities.

  • Works in 6 steps: Parse Arguments → Load i18n Strings → Detect Primary Code Language → …
  • Scanning code for security vulnerabilities
  • SKILL.md covers Invocation, CRITICAL: Cách dùng skill này…, Workflow and Step 0: Parse Arguments, plus 10 more sections
  • Runs Shell and Python scripts from its folder; calls git, gh and go; reaches api.osv.dev

What it does

Vbs Scan Security is an agent skill from tanviet12/vbsec. Use when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes /vbs-scan-security. For large scans (20 main-language files OR 30 total OR 14 days) processes chunks sequentially. Outputs bilingual reports (vi/en). Optional --auto-fix (agentic patch + verify loop) and --sca (live CVE lookup via OSV.dev).

Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 88 other files, including reference files (for example `agents/openai.yaml`, `references/chunking-strategy.md` and `references/data-flow-classification.md`).

It sits in Security, covering Vulnerability scanning, Translation and Security review. The repository describes itself as: Security scanning skill for Claude Code, Codex and Antigravity. Finds the 21 most common vulnerabilities in AI-written code and shows how to fix each one. The licence is MIT.

When your agent uses it

  • Scanning code for security vulnerabilities
  • User says scan security
  • Kiểm tra bảo mật
  • Review security

Example prompts

  • “scan security”
  • “kiểm tra bảo mật”
  • “security audit”
  • “/vbs-scan-security”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse Arguments
  2. Load i18n Strings
  3. Detect Primary Code Language
  4. Route by Size
  5. Apply Rules
  6. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 1b86c27. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell and Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • gh
    • go
    • dotnet
    • bash
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.osv.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vbs Scan Security loads about 5.3k tokens when it runs, and up to ~29k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 1,932 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~106
When it runs · the whole SKILL.md, loaded when a task matches
~5.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~29k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:46
    đụng hệ thống thật** (DB, dịch vụ trong `.env`) — chỉ bật khi test an toàn. Không bật → bump dependency chỉ là gợi ý pat

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tanviet12/vbsec at commit 1b86c27, republished under its MIT licence (© tanviet12). 1,932 words, ~5,257 tokens.

Download SKILL.mdSave it as .claude/skills/vbs-scan-security/SKILL.md (or your agent's skills folder). This skill also uses 83 other files; get the full folder from GitHub.
name
vbs-scan-security
description
Use when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes `/vbs-scan-security`. For large scans (>20 main-language files OR >30 total OR >14 days) processes chunks sequentially. Outputs bilingual reports (vi/en). Optional `--auto-fix` (agentic patch + verify loop) and `--sca` (live CVE lookup via OSV.dev).
license
MIT

vbsec — Security Scanner cho Vibe Coders (Codex CLI variant)

Quét lỗ hổng bảo mật cho code do AI sinh ra (vibe code). Bộ skill này check 21 lỗi bảo mật phổ biến nhất của vibe code, kế thừa kiến trúc SMALL/LARGE mode, tổng quát hóa cross-language + chuyên sâu cho Go/PHP/Python/TypeScript/.NET.

Public repo: https://github.com/tanviet12/vbsec License: MIT Platform: OpenAI Codex CLI. Phiên bản Claude Code spawn parallel sub-agents; phiên bản này dùng sequential chunking để giữ portability — chậm hơn ~3× nhưng output identical.

Invocation

Trong Codex CLI:

/skills              # mở skill picker, chọn vbs-scan-security
$vbs-scan-security   # invoke trực tiếp qua $-prefix

Hoặc nói tự nhiên: "scan security cho repo này" / "kiểm tra bảo mật" — Codex tự match description.

ArgumentScopeMô tả
(không args)Toàn repoMặc định — quét toàn bộ repo
allToàn repoAlias explicit
uncommitted / diffUncommitted changesStaged + unstaged
stagedStaged files onlyPre-commit scan
commit within XdaysRecent commitsQuét commit X ngày gần đây
commit id <sha>Specific commitQuét 1 commit
pr id <number>Pull requestQuét PR diff (cần gh CLI)

Lựa chọn ngôn ngữ output (thêm vào bất kỳ scope nào):

  • lang=vi hoặc --vi → Tiếng Việt (mặc định)
  • lang=en hoặc --en → English

Cờ tùy chọn (v0.7+, mặc định TẮT):

FlagAliasMô tả
--scascaTra cứu CVE live qua OSV.dev cho dependency (NuGet/Go/npm/Composer/PyPI). Xem references/dependency-scan.md. Cần network.
--auto-fixauto-fixTự sinh patch, verify bằng build command, revert nếu fail. Xem workflows/auto-fix.md. Ghi đè file nguồn — cần git repo.
--run-tests—Chỉ có tác dụng cùng --auto-fix: cho phép chạy test của project (go test ./..., dotnet test) để verify bản nâng version dependency. Test có thể đụng hệ thống thật (DB, dịch vụ trong .env) — chỉ bật khi test an toàn. Không bật → bump dependency chỉ là gợi ý patch.

Ví dụ:

$vbs-scan-security pr id 42 lang=en
$vbs-scan-security staged --vi
$vbs-scan-security commit within 7days
$vbs-scan-security all --sca
$vbs-scan-security uncommitted --auto-fix

CRITICAL: Cách dùng skill này (cho LLM agent)

Các pattern bash/grep trong rule files là VÍ DỤ minh họa, KHÔNG phải lệnh chạy literal.

Nguyên tắc
  1. Lý luận, không pattern-match thuần — Hiểu intent bảo mật đằng sau mỗi check, không chỉ tìm chuỗi
  2. Dùng tool phù hợp — file-read và grep tool của Codex (tên có thể là read_file, grep, shell) thay vì chạy bash grep/find thô
  3. Đọc context đầy đủ — Khi gặp pattern, đọc hàm xung quanh để hiểu đây có thực sự là lỗ hổng không
  4. Phân loại trust level — Một query có format chuỗi chỉ nguy hiểm nếu data ghép vào là L1 (untrusted)
Phân loại nguồn dữ liệu (L1–L4)
LevelNguồnTin cậyVí dụ
L1Input người dùngKHÔNG tinreq.body, $_GET, request.params, HTTP header, file upload
L2DatabaseBán tinGiá trị từ DB nhưng nguồn gốc là user input
L3Code nội bộTinHardcoded strings, config keys, computed values
L4Hệ thốngTinEnv vars, file paths nội bộ, framework constants

Key insight: f"SELECT ... {x}" SAFE nếu x là L3+. CRITICAL nếu x là L1 không qua parameterization.

Tham khảo chi tiết: references/data-flow-classification.md.


Workflow

┌─────────────────────────────────────────────────────────────────────┐
│            vbsec SCAN WORKFLOW (Codex — Sequential)                  │
├─────────────────────────────────────────────────────────────────────┤
│  [Step 0] Parse args → scope + lang                                  │
│  [Step 1] Gather files (git)                                         │
│  [Step 2] Detect primary code language                               │
│  [Step 3] Route by size:                                             │
│           SMALL (≤20 main, ≤30 total, ≤14d) → inline                 │
│           LARGE (vượt ngưỡng)                → sequential chunking   │
│  [Step 4] Apply 21 rules (generic + lang overlay)                    │
│  [Step 4b] SCA scan (optional, --sca) → rule 22 VULNERABLE-DEPENDENCY│
│  [Step 4c] Auto-fix (optional, --auto-fix) → patch/verify/retry loop │
│  [Step 5] Generate bilingual report + save to vbsec-reports/         │
└─────────────────────────────────────────────────────────────────────┘

Step 0: Parse Arguments

Dùng shell tool ĐÚNG MỘT LẦN cho step này.

bash
ARGS="${ARGUMENTS:-$1}"

# 0) Detect git availability (KHÔNG bắt buộc có git — v0.5.1+)
IS_GIT_REPO=true
git rev-parse --is-inside-work-tree >/dev/null 2>&1 || IS_GIT_REPO=false

# 1) Extract lang flag (default vi)
LANG="vi"
if echo "$ARGS" | grep -qE 'lang=en|--en|\ben\b'; then LANG="en"; fi
if echo "$ARGS" | grep -qE 'lang=vi|--vi'; then LANG="vi"; fi

# 1b) Extract --auto-fix / --sca flags (v0.7+, default off) + scope.
#     Duyệt từng từ thay vì sed \b — BSD sed trên macOS không hỗ trợ \b.
AUTO_FIX=false
SCA=false
RUN_TESTS=false
SCOPE_WORDS=""
set -f  # không expand glob khi tách từ
for w in $ARGS; do
  case "$w" in
    --auto-fix|auto-fix)       AUTO_FIX=true ;;
    --sca|sca)                 SCA=true ;;
    --run-tests)               RUN_TESTS=true ;;
    lang=vi|lang=en|--vi|--en) ;;
    *)                         SCOPE_WORDS="$SCOPE_WORDS $w" ;;
  esac
done
set +f

# 2) Scope = các từ còn lại (đã bỏ lang + auto-fix/sca)
SCOPE=$(echo "$SCOPE_WORDS" | xargs)

# 3) Gather files
NO_GIT_NOTE=""
SCAN_REF=""
SCAN_ROOT="."
case "$SCOPE" in
  "staged"|"uncommitted"|"diff"|"commit within "*|"commit id "*|"pr id "*)
    if [ "$IS_GIT_REPO" = false ]; then
      echo "{msg_scope_needs_git}"
      exit 1
    fi
    case "$SCOPE" in
      "staged")             FILES=$(git diff --cached --name-only --diff-filter=d) ;;
      "uncommitted"|"diff")
        # staged + unstaged (so với HEAD) + file mới chưa `git add`; bỏ file đã xoá
        FILES=$( { git diff --name-only --diff-filter=d HEAD 2>/dev/null || git diff --cached --name-only --diff-filter=d; git ls-files --others --exclude-standard; } | sort -u | grep -v '^$' || true) ;;
      "commit within "*)
        DAYS=$(echo "$SCOPE" | grep -oE '[0-9]+')
        # Đọc bản hiện tại trên đĩa → bỏ file đã bị xoá sau đó
        FILES=$(git log --since="${DAYS} days ago" --name-only --pretty=format: | sort -u | grep -v '^$' | while IFS= read -r f; do [ -f "$f" ] && echo "$f"; done || true) ;;
      "commit id "*)
        SHA=$(echo "$SCOPE" | sed 's/commit id //')
        git cat-file -e "${SHA}^{commit}" 2>/dev/null || { echo "Unknown commit: $SHA"; exit 1; }
        FILES=$(git diff-tree --root --no-commit-id --name-only -r --diff-filter=d "$SHA")
        SCAN_REF="$SHA" ;;
      "pr id "*)
        PR=$(echo "$SCOPE" | sed 's/pr id //')
        FILES=$(gh pr diff "$PR" --name-only) || exit 1
        git fetch -q origin "pull/${PR}/head" 2>/dev/null || git fetch -q "$(gh repo view --json url -q .url)" "pull/${PR}/head" || { echo "Cannot fetch PR #$PR"; exit 1; }
        SCAN_REF=$(git rev-parse FETCH_HEAD)
        # Bỏ file PR đã xoá (không còn ở head của PR)
        FILES=$(echo "$FILES" | while IFS= read -r f; do git cat-file -e "${SCAN_REF}:$f" 2>/dev/null && echo "$f"; done || true) ;;
    esac
    ;;
  "all"|"")
    if [ "$IS_GIT_REPO" = true ]; then
      FILES=$(git ls-files)
    else
      # Non-git folder — walk filesystem, exclude folder system + vendored
      FILES=$(find . -type f \
        -not -path '*/.git/*' \
        -not -path '*/.next/*' \
        -not -path '*/.nuxt/*' \
        -not -path '*/.venv/*' \
        -not -path '*/.idea/*' \
        -not -path '*/.vscode/*' \
        -not -path '*/node_modules/*' \
        -not -path '*/vendor/*' \
        -not -path '*/dist/*' \
        -not -path '*/build/*' \
        -not -path '*/target/*' \
        -not -path '*/__pycache__/*' \
        -not -path '*/vbsec-reports/*' \
        2>/dev/null | sed 's|^\./||')
      NO_GIT_NOTE="true"
    fi
    ;;
  *)
    echo "Unknown scope: $SCOPE"
    exit 1
    ;;
esac

# 3b) Scope theo commit/PR: extract snapshot đúng ref ra thư mục tạm.
#     Thư mục hiện tại có thể đang ở branch khác → đọc ở đó sẽ quét sai code.
if [ -n "$SCAN_REF" ]; then
  TMP_BASE="${TMPDIR:-/tmp}"; SCAN_ROOT=$(mktemp -d "${TMP_BASE%/}/vbsec-scan.XXXXXX")
  git archive "$SCAN_REF" | tar -x -C "$SCAN_ROOT"
fi

# 4) Strip noise (double-protect)
FILES=$(echo "$FILES" | grep -vE '(^|/)(node_modules|vendor|dist|build|\.next|\.nuxt|target|\.venv|__pycache__|\.git|vbsec-reports)/' || true)

# 5) Prepare save location
TIMESTAMP=$(date +"%Y-%m-%d-%H%M%S")
REPORT_DIR="vbsec-reports"
REPORT_FILE="${REPORT_DIR}/scan-${TIMESTAMP}.md"
mkdir -p "${REPORT_DIR}"

# 6) Check .gitignore (chỉ relevant nếu là git repo)
GITIGNORE_WARNING=""
if [ "$IS_GIT_REPO" = true ]; then
  if [ -f .gitignore ]; then
    grep -qE '^vbsec-reports/?$' .gitignore || GITIGNORE_WARNING="missing"
  else
    GITIGNORE_WARNING="missing"
  fi
fi

echo "Scope: ${SCOPE:-all (default)}"
echo "Lang: $LANG"
echo "Git repo: $IS_GIT_REPO"
echo "Files: $(echo "$FILES" | wc -l)"
echo "Report file: $REPORT_FILE"
echo "Scan root: $SCAN_ROOT"
echo "SCA (live OSV lookup): $SCA"
echo "Auto-fix: $AUTO_FIX (run tests: $RUN_TESTS)"
[ "$NO_GIT_NOTE" = "true" ] && echo "Note: non-git folder — scanning all files via find"

Lưu ý (v0.5.1+): Skill chạy được trên cả non-git folder. Default scope (all) dùng find thay git ls-files. Các scope dựa vào git (staged, uncommitted, commit within, commit id, pr id) BẮT BUỘC git — báo msg_scope_needs_git rồi exit. Nếu NO_GIT_NOTE=true, report header in {msg_no_git_note}.

Scan root: nếu Scan root khác . (scope commit id, pr id), mọi lần đọc/grep file phải đọc tại $SCAN_ROOT/<path>. Đó là snapshot đúng commit/PR; KHÔNG đọc bản trong thư mục hiện tại (có thể đang ở branch khác). Report vẫn ghi path gốc <path>, không kèm prefix $SCAN_ROOT. LARGE mode cũng đọc mọi chunk tại $SCAN_ROOT. Render report xong → rm -rf "$SCAN_ROOT".

v0.7+: $AUTO_FIX=true nhưng $IS_GIT_REPO=false → Step 4c tự skip và in {msg_autofix_needs_git} (scan/report vẫn chạy bình thường).

v0.7+: $AUTO_FIX=true và $SCAN_ROOT khác . (scope commit id, pr id) → file đang đọc là snapshot tạm, sửa ở đó không có tác dụng. Step 4c KHÔNG apply patch nào: mọi finding CRITICAL/HIGH chỉ ghi diff ra vbsec-reports/patches/, patch_status: "suggested_only", và in {msg_autofix_snapshot_scope} một lần.


Step 1: Load i18n Strings

Đọc file i18n tương ứng với $LANG:

File i18n chứa bảng key→text cho toàn bộ user-facing strings. Mọi text trong report final phải lấy từ i18n, KHÔNG hardcode.

Strings KHÔNG bao giờ dịch: rule ID, file path, code snippet, command name.


Step 2: Detect Primary Code Language

Đọc references/language-detection.md. Tóm tắt:

  1. Count extension trong file list: .go, .py, .php, .js, .ts, .jsx, .tsx, .rb, .java, .rs, .cs, .csproj, .sln
  2. Primary lang = lang chiếm ≥30% tổng files
  3. Có rules/languages/<lang>/ → load overlay; không có → chỉ dùng generic
  4. Multi-lang repo (Go backend + Vue frontend) → load cả 2 overlay

Hiện hỗ trợ chuyên sâu: go, php, typescript (gộp JS+TS), python, dotnet.


Step 3: Route by Size

Điều kiệnNgưỡngMode
Files ngôn ngữ chính≤20SMALL
Files ngôn ngữ chính>20LARGE
Tổng files≤30SMALL
Tổng files>30LARGE
Timespan (scope commit within)≤14 ngàySMALL
Timespan>14 ngàyLARGE

BẤT KỲ điều kiện nào sang LARGE → dùng LARGE mode.


Step 4: Apply Rules

Cho mỗi rule trong rules/generic/ (01-21):

  1. Nạp phần phát hiện của cả bộ rule qua script bash <skill-dir>/references/load-rules.sh --part N <lang...> (chạy đủ mọi phần, dòng cuối output cho biết tổng số phần). Chạy nguyên lệnh, KHÔNG thêm | head, | tail, | grep: mỗi phần đã < 20.000 ký tự, cắt output = bỏ sót rule (overlay đã thay generic) → hiểu intent, severity, search patterns gợi ý. Phần Examples/Fix recommendation chỉ Read khi rule có finding CRITICAL/HIGH (chi tiết trong workflow)
  2. Apply lên files trong scope (dùng grep + read tool của Codex)
  3. Với mỗi match: trace data flow (L1-L4), phân loại có phải vulnerability thật không
  4. Nếu có rule cùng id trong rules/languages/<detected-lang>/, rule chuyên sâu thắng generic.

21 rules generic (luôn chạy) + 1 rule optional (--sca):

#IDSeverity max
1HARDCODED-SECRETCRITICAL
2SQL-INJECTIONCRITICAL
3XSSHIGH
4IDORHIGH
5SLOPSQUATTINGCRITICAL
6BRUTE-FORCEHIGH
7MASS-ASSIGNMENTCRITICAL
8INSECURE-DESERIALIZATIONCRITICAL
9SSRFHIGH
10PATH-TRAVERSALHIGH
11CSRFHIGH
12BROKEN-ACCESS-CONTROLCRITICAL
13WEAK-PASSWORD-HASHINGCRITICAL
14JWT-NONE-ALGORITHMCRITICAL
15CORS-MISCONFIGHIGH
16UNRESTRICTED-FILE-UPLOADCRITICAL
17VERBOSE-ERROR-DEBUG-MODEHIGH
18MISSING-RATE-LIMITHIGH
19RACE-CONDITIONHIGH
20OUTDATED-DEPENDENCYHIGH
21COMMAND-INJECTIONCRITICAL
22VULNERABLE-DEPENDENCYCRITICAL

Rule 22 chỉ chạy khi $SCA=true — xem Step 4b.


Step 4b: SCA Scan (optional — --sca)

Chỉ chạy khi $SCA=true. Rule 22 KHÔNG được nạp qua load-rules.sh (frontmatter opt_in: --sca), nên Read rules/generic/22-vulnerable-dependency.md ở bước này. Đọc references/dependency-scan.md: parse manifest theo ecosystem (NuGet/.NET, Go, npm/TS, Composer/PHP, PyPI), query https://api.osv.dev/v1/querybatch rồi v1/vulns/{id}, lấy severity từ database_specific.severity (không tự tính điểm từ CVSS vector), tạo finding VULNERABLE-DEPENDENCY kèm cve_id/fixed_version. Network fail/không có manifest → note {msg_sca_unavailable}/{msg_sca_no_manifest}, KHÔNG fail scan, fallback rule 20. Đây là bước chạy 1 lần cho toàn repo (không chunk theo folder như LARGE mode).

Show full SKILL.md (773 more words)Show less

Step 4c: Auto-fix (optional — --auto-fix)

Chỉ chạy khi $AUTO_FIX=true, và cần $IS_GIT_REPO=true (không có → in {msg_autofix_needs_git}, skip). $SCAN_ROOT khác . hoặc scope staged → chỉ sinh patch, KHÔNG apply, mọi finding là suggested_only. Chạy TRƯỚC Step 5 để patch_status kịp vào report. Đọc workflows/auto-fix.md: preflight 1 lần (command -v build tool + build baseline; thiếu tool hoặc baseline fail → mọi finding suggested_only), rồi với mỗi finding CRITICAL/HIGH: harvest context → generate unified diff → git apply --check → snapshot file sắp bị ghi → git apply → build verify theo $PRIMARY_LANG → khôi phục từ snapshot + retry (tối đa 2 lần) nếu fail. KHÔNG revert bằng git checkout. Patch dependency chỉ applied khi có --run-tests và build + test của project pass (Go, dotnet); npm/Composer/PyPI luôn suggested_only.


Step 5: Generate Report

Tham khảo template trong references/output-format.md. Quy tắc cốt lõi:

Verbose level theo severity:

  • CRITICAL → bảng overview + full verbose block per finding (Mô tả ngắn + Tại sao nguy hiểm + Hacker khai thác + Code before/after + Đọc thêm)
  • HIGH → bảng overview + medium block per finding (Mô tả + Tác động + Code fix + Đọc thêm)
  • MEDIUM → chỉ bảng compact
  • LOW → chỉ bảng compact

Layout:

  1. Header block (scope, file count, primary lang, mode, date, lang code)
  2. VERDICT + 1-line description
  3. CRITICAL section (overview table → verbose blocks)
  4. HIGH section (overview table → medium blocks)
  5. MEDIUM section (compact table)
  6. LOW section (compact table)
  7. PASSED CHECKS (list) 7b. Hardening notes (tuỳ chọn, {header_hardening_title}) — gợi ý phòng thủ, KHÔNG phải finding
  8. Next steps 8b. Auto-fix summary (chỉ khi --auto-fix đã chạy ở Step 4c)
  9. Save notification (path file đã ghi)
  10. Gitignore warning (nếu cần)
  11. Footer + disclaimer
  12. JSON summary (canonical EN — không phụ thuộc lang) — đúng schema ở references/output-format.md mục 7

Save-to-file: ghi TOÀN BỘ report (identical với stdout) vào vbsec-reports/scan-<timestamp>.md dùng tool write/create file của Codex.

Sau đó in 1-2 dòng note ra stdout:

📄 {msg_report_saved}: vbsec-reports/scan-<timestamp>.md
⚠️ {msg_gitignore_warning_title}: {msg_gitignore_warning_text}

Mọi section header, severity label, verdict text lấy từ i18n file đã load ở Step 1.

Finding vs hardening note: chỉ tạo finding khi có đường khai thác cụ thể (input attacker điều khiển được tới sink, hoặc cấu hình sai khai thác được ngay). Reasoning kết luận "an toàn" / "không khai thác được" → KHÔNG tạo finding. Ngoại lệ: check/sanitizer viết sai (HasPrefix thiếu /, endsWith domain, algorithms lấy từ header...) LUÔN là finding dù hiện có yếu tố khác chặn — giữ finding, hạ severity, nêu điều kiện bypass. Vấn đề không thuộc 21 rule (token không hết hạn, thiếu header...) → KHÔNG gán rule gần nhất. "Endpoint không có auth" chỉ là finding khi repo có middleware auth mà route này bị bỏ sót, hoặc endpoint bản chất cần quyền (admin, xoá, tiền, dữ liệu người khác); không thêm BROKEN-ACCESS-CONTROL vào dòng đã có finding CRITICAL khác. Gợi ý phòng thủ thêm cho code đã an toàn (header, cờ cookie khi không có XSS, lockfile...) → hardening_notes[] + section {header_hardening_title}, không gán rule_id, không tính vào summary/verdict. Chi tiết: references/output-format.md mục "Finding vs hardening note".

Validate JSON trước khi kết thúc (bắt buộc): sau khi ghi report, chạy python3 <skill-dir>/references/validate-report.py <report-file> (<skill-dir> = thư mục chứa file SKILL.md này). Script báo lỗi → sửa JSON trong report, ghi lại, chạy lại (tối đa 2 lần). Lỗi hay gặp: dùng key id/rule thay vì rule_id, tự đặt rule ID ngoài 21 rule, severity viết thường, summary đếm lệch với findings, finding tự nhận "not reachable" / "không khai thác được" / "mapped to closest rule" (phải chuyển sang hardening_notes), 2 finding trùng file:line:rule_id. Không có python3 → tự đối chiếu với bảng schema ở output-format.md mục 7.


Verdict Logic

Điều kiệnVerdict
Có ≥1 CRITICALFAIL
Không CRITICAL, có ≥1 HIGHWARN
Không CRITICAL, không HIGHPASS

WARN ≠ approve. Báo cáo cần nêu rõ HIGH issues cần khắc phục trước production.


Khác biệt với Claude Code variant

AspectClaude CodeCodex (file này)
LARGE modeParallel sub-agents (3 cùng lúc)Sequential chunking (1 chunk/lần)
Resume on interruptTodoWrite tasks.vbsec-tmp/findings-*.md (re-run skip chunk đã có file)
FrontmatteruserInvocable: truelicense: MIT
Invocation/vbs-scan-security/skills → pick, hoặc $vbs-scan-security, hoặc auto-match

Toàn bộ rules, i18n, output format, language detection — identical với Claude Code variant. Khi update rule → sửa ở canonical (skills/vbs-scan-security/) → chạy ./scripts/sync-skills.sh để propagate.


Reasoning-First (cốt lõi)

DO:

  • Đọc full function khi gặp pattern, KHÔNG flag luôn
  • Trace nguồn dữ liệu: input → transformations → sink
  • Phân loại L1-L4 trước khi flag CRITICAL
  • Đọc rule file trước khi áp dụng

DON'T:

  • Copy bash example chạy thẳng (đó là minh họa)
  • Flag mọi fmt.Sprintf là SQLi (chỉ flag nếu data là L1 và không parameterize)
  • Bỏ qua "but" clauses (nhiều pattern legitimate)
  • Skip context (1 dòng grep không đủ để verdict)

Mục tiêu là hiểu bảo mật, không phải đếm pattern.

© tanviet12, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 83 other files (references) in skills/codex/vbs-scan-security of tanviet12/vbsec.

  • SKILL.md
  • agents/openai.yaml
  • references/chunking-strategy.md
  • references/data-flow-classification.md
  • references/dependency-scan.md
  • references/i18n/en.md
  • references/i18n/vi.md
  • references/language-detection.md
  • references/load-rules.sh
  • references/output-format.md
  • references/sub-agent-prompts.md
  • references/validate-report.py
  • rules/generic/01-hardcoded-secret.md
  • rules/generic/02-sql-injection.md
  • rules/generic/03-xss.md
  • rules/generic/04-idor.md
  • … and 68 more

Open the folder on GitHubat commit 1b86c27

Compare with similar skills

Vbs Scan Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vbs Scan Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vbs Scan Security this skilltanviet12/vbsec289—~5.3kAutomated safety check: NotesMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Security AuditTheDecipherist/claude-code-mastery551—~1.3kAutomated safety check: NotesMIT
Cyberowlaikarimhabush/cyberowl263—~2.5kAutomated safety check: PassMIT
Pre-Commit Security Scanzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT

Similar skills

  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 11 days ago
    SecurityAuto-check passed
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    551 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Cyberowlai

    karimhabush/cyberowl

    Check if recent cybersecurity alerts from 10 international CERTs affect your current project.

    263 GitHub stars~2.5k tokensUpdated today
    SecurityAuto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    SecurityAuto-check: notes
  • CodeCrucible Security Scans

    block/codecrucible

    Official

    Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

    117 GitHub stars~1.2k tokensUpdated 3 days ago
    SecurityAuto-check passed

More from tanviet12/vbsec

  • Vbs Scan Security

    tanviet12/vbsec

    A skill your agent uses when scanning code for security vulnerabilities.

    289 GitHub stars~6.8k tokensUpdated 12 days ago
    Auto-check: notes

Categories

Questions about Vbs Scan Security

What does Vbs Scan Security do?

A skill your agent uses when scanning code for security vulnerabilities. Vbs Scan Security is an agent skill from tanviet12/vbsec. Use when scanning code for security vulnerabilities.

When should I use Vbs Scan Security?

Vbs Scan Security fits situations like: scanning code for security vulnerabilities; user says scan security; kiểm tra bảo mật; review security.

How do I install Vbs Scan Security in Claude Code?

Run `npx skills add tanviet12/vbsec --skill vbs-scan-security -a claude-code`. Or copy the skill folder (skills/codex/vbs-scan-security in tanviet12/vbsec) into .claude/skills/vbs-scan-security in your project. Claude Code loads it when a task matches its description.

How do I install Vbs Scan Security in Codex?

Run `npx skills add tanviet12/vbsec --skill vbs-scan-security -a codex`. Or copy the skill folder (skills/codex/vbs-scan-security in tanviet12/vbsec) into .agents/skills/vbs-scan-security in your project. Codex loads it when a task matches its description.

Can I use Vbs Scan Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tanviet12/vbsec --skill vbs-scan-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vbs-scan-security, .gemini/skills/vbs-scan-security, .github/skills/vbs-scan-security and .opencode/skills/vbs-scan-security in your project.

What does Vbs Scan Security need to run?

Going by SKILL.md and its folder, Vbs Scan Security needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (git, gh, go, dotnet, bash and python3). Our summary lists: Python 3; A Bash shell.

Does Vbs Scan Security access the network?

SKILL.md names 1 domain. In commands or code: api.osv.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Vbs Scan Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Vbs Scan Security use?

Vbs Scan Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vbs Scan Security use?

About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.

What are the alternatives to Vbs Scan Security?

Skills that share tags, products or a category with Vbs Scan Security: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vbs Scan Security?

tanviet12 (a GitHub user) maintains it in tanviet12/vbsec, which has 289 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 28, 2026.

Source: tanviet12/vbsec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.