Deepsec Documentation Guide
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
A skill your agent uses when scanning code for security vulnerabilities.
$ npx skills add tanviet12/vbsec --skill vbs-scan-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install tanviet12/vbsec vbs-scan-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/tanviet12/vbsec.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/vbs-scan-security .claude/skills/vbs-scan-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "vbs-scan-security" agent skill from https://github.com/tanviet12/vbsec/tree/main/skills/vbs-scan-security into .claude/skills/vbs-scan-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vbs-scan-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/tanviet12/vbsec/tree/main/skills/vbs-scan-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add tanviet12/vbsec --skill vbs-scan-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install tanviet12/vbsec vbs-scan-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tanviet12/vbsec.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/vbs-scan-security .agents/skills/vbs-scan-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "vbs-scan-security" agent skill from https://github.com/tanviet12/vbsec/tree/main/skills/vbs-scan-security into .agents/skills/vbs-scan-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vbs-scan-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tanviet12/vbsec --skill vbs-scan-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install tanviet12/vbsec vbs-scan-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tanviet12/vbsec.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/vbs-scan-security .cursor/skills/vbs-scan-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "vbs-scan-security" agent skill from https://github.com/tanviet12/vbsec/tree/main/skills/vbs-scan-security into .cursor/skills/vbs-scan-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vbs-scan-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/tanviet12/vbsec.git --path skills/vbs-scan-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add tanviet12/vbsec --skill vbs-scan-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install tanviet12/vbsec vbs-scan-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tanviet12/vbsec.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/vbs-scan-security .gemini/skills/vbs-scan-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "vbs-scan-security" agent skill from https://github.com/tanviet12/vbsec/tree/main/skills/vbs-scan-security into .gemini/skills/vbs-scan-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vbs-scan-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install tanviet12/vbsec vbs-scan-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add tanviet12/vbsec --skill vbs-scan-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/tanviet12/vbsec.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/vbs-scan-security .github/skills/vbs-scan-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "vbs-scan-security" agent skill from https://github.com/tanviet12/vbsec/tree/main/skills/vbs-scan-security into .github/skills/vbs-scan-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vbs-scan-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add tanviet12/vbsec --skill vbs-scan-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install tanviet12/vbsec vbs-scan-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/tanviet12/vbsec.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/vbs-scan-security .opencode/skills/vbs-scan-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "vbs-scan-security" agent skill from https://github.com/tanviet12/vbsec/tree/main/skills/vbs-scan-security into .opencode/skills/vbs-scan-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "vbs-scan-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
vbs-scan-securityA skill your agent uses when scanning code for security vulnerabilities.
Vbs Scan Security is an agent skill from tanviet12/vbsec. Use when scanning code for security vulnerabilities. Use when user says "scan security", "kiểm tra bảo mật", "security audit", "review security", or invokes /vbs-scan-security. Auto-delegates to sub-agents for large scans (20 main-language files OR 30 total OR 14 days). Outputs bilingual reports (vi/en). Optional --auto-fix (agentic patch + verify loop) and --sca (live CVE lookup via OSV.dev).
Its SKILL.md is about 6.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 86 other files, including reference files (for example `references/chunking-strategy.md`, `references/data-flow-classification.md` and `references/dependency-scan.md`).
It sits in Security, covering Vulnerability scanning, Subagents and Translation. The repository describes itself as: Security scanning skill for Claude Code, Codex and Antigravity. Finds the 21 most common vulnerabilities in AI-written code and shows how to fix each one. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1b86c27. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Shell and Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
gitghgodotnetbashpython3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.osv.devFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Vbs Scan Security loads about 6.8k tokens when it runs, and up to ~31k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 2,300 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
đụng hệ thống thật** (DB, dịch vụ trong `.env`) — chỉ bật khi test an toàn. Không bật → bump dependency chỉ là gợi ý pat# như .env (để scan secrets), .htaccess, .gitignore (file thường, không phải folder).Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from tanviet12/vbsec at commit 1b86c27, republished under its MIT licence (© tanviet12). 2,300 words, ~6,778 tokens.
.claude/skills/vbs-scan-security/SKILL.md (or your agent's skills folder). This skill also uses 82 other files; get the full folder from GitHub.Quét lỗ hổng bảo mật cho code do AI sinh ra (vibe code). Bộ skill này check 21 lỗi bảo mật phổ biến nhất của vibe code, kế thừa kiến trúc SMALL/LARGE mode từ bộ rule production của SePay, tổng quát hóa cross-language (mặc định) + chuyên sâu cho Go/PHP (phase 1).
Public repo: https://github.com/tanviet12/vbsec License: MIT (sẽ chốt khi public)
| Command | Scope | Mô tả |
|---|---|---|
/vbs-scan-security | Toàn repo (default từ v0.3) | Mặc định — quét toàn bộ repo |
/vbs-scan-security all | Toàn repo | Alias explicit của default |
/vbs-scan-security uncommitted | Uncommitted changes | Quét staged + unstaged (cần explicit từ v0.3) |
/vbs-scan-security diff | Uncommitted changes | Alias intuitive cho uncommitted |
/vbs-scan-security staged | Staged files only | Pre-commit scan |
/vbs-scan-security commit within Xdays | Recent commits | Quét commit X ngày gần đây |
/vbs-scan-security commit id <sha> | Specific commit | Quét 1 commit |
/vbs-scan-security pr id <number> | Pull request | Quét PR diff (cần gh CLI) |
v0.3 change: Default scope đổi từ uncommitted → all. Non-tech user lần đầu chạy không bị confused bởi report rỗng. Để giữ behavior cũ, dùng uncommitted hoặc diff explicit.
Lựa chọn ngôn ngữ output (thêm vào bất kỳ scope nào):
lang=vi hoặc --vi → Tiếng Việt (mặc định)lang=en hoặc --en → EnglishCờ tùy chọn (v0.7+, mặc định TẮT — thêm vào bất kỳ scope nào):
| Flag | Alias | Mô tả |
|---|---|---|
--sca | sca | Tra cứu CVE live qua OSV.dev cho dependency (5 ecosystem: NuGet/Go/npm/Composer/PyPI). Xem references/dependency-scan.md. Cần network. |
--auto-fix | auto-fix | Tự sinh patch (unified diff) cho finding CRITICAL/HIGH, verify bằng build command, revert nếu fail. Xem workflows/auto-fix.md. Ghi đè file nguồn — cần git repo, khuyến nghị working tree sạch trước khi chạy. |
--run-tests | — | Chỉ có tác dụng cùng --auto-fix: cho phép chạy test của project (go test ./..., dotnet test) để verify bản nâng version dependency. Test có thể đụng hệ thống thật (DB, dịch vụ trong .env) — chỉ bật khi test an toàn. Không bật → bump dependency chỉ là gợi ý patch. |
Ví dụ:
/vbs-scan-security pr id 42 lang=en
/vbs-scan-security staged --vi
/vbs-scan-security commit within 7days
/vbs-scan-security all --sca
/vbs-scan-security uncommitted --auto-fix
/vbs-scan-security all --sca --auto-fixCác pattern bash/grep trong rule files là VÍ DỤ minh họa, KHÔNG phải lệnh chạy literal.
Grep, Read, Glob thay vì bash grep/find| Level | Nguồn | Tin cậy | Ví dụ |
|---|---|---|---|
| L1 | Input người dùng | KHÔNG tin | req.body, $_GET, request.params, HTTP header, file upload |
| L2 | Database | Bán tin | Giá trị từ DB nhưng nguồn gốc là user input |
| L3 | Code nội bộ | Tin | Hardcoded strings, config keys, computed values |
| L4 | Hệ thống | Tin | Env vars, file paths nội bộ, framework constants |
Key insight: f"SELECT ... {x}" SAFE nếu x là L3+. CRITICAL nếu x là L1 không qua parameterization.
Tham khảo chi tiết: references/data-flow-classification.md.
┌─────────────────────────────────────────────────────────────────────┐
│ vbsec SCAN WORKFLOW │
├─────────────────────────────────────────────────────────────────────┤
│ │
│ [Step 0] Parse args │
│ ├─ Scope (uncommitted/staged/commit/pr/all) │
│ └─ Output lang (vi default | en) │
│ ↓ │
│ [Step 1] Gather files (git) │
│ ↓ │
│ [Step 2] Detect primary code language │
│ └─ Đọc references/language-detection.md │
│ ↓ │
│ [Step 3] Route by size │
│ ┌──────────────────┬──────────────────┐ │
│ │ SMALL (inline) │ LARGE (delegate)│ │
│ │ ≤20 main+≤30tot │ >20 OR >30 OR │ │
│ │ AND ≤14d │ >14 ngày │ │
│ └─────┬────────────┴─────────┬────────┘ │
│ ↓ ↓ │
│ workflows/small- workflows/large- │
│ review.md review.md │
│ │
│ Both apply: │
│ - rules/generic/*.md (21 rules cross-language, luôn chạy) │
│ - rules/languages/<detected>/*.md (override nếu trùng tên) │
│ ↓ │
│ [Step 4b] SCA scan (optional — cần $SCA=true) │
│ └─ references/dependency-scan.md → rule 22 VULNERABLE-DEPENDENCY │
│ ↓ │
│ [Step 4c] Auto-fix (optional — cần $AUTO_FIX=true) │
│ └─ workflows/auto-fix.md → patch + verify + retry loop │
│ (chạy TRƯỚC khi render report cuối, để patch_status kịp vào │
│ JSON summary + section Auto-fix trong report) │
│ ↓ │
│ [Step 5] Generate report │
│ ├─ Markdown report (theo lang chọn, gồm cả section Auto-fix) │
│ └─ JSON summary (canonical EN, ở cuối, gồm patch_status) │
│ │
└─────────────────────────────────────────────────────────────────────┘Dùng Bash tool ĐÚNG MỘT LẦN cho step này (gather files là việc của git, không phải reasoning).
ARGS="${ARGUMENTS:-}"
# 0) Detect git availability (KHÔNG bắt buộc có git — v0.5.1+)
IS_GIT_REPO=true
git rev-parse --is-inside-work-tree >/dev/null 2>&1 || IS_GIT_REPO=false
# 1) Extract lang flag (default vi)
LANG="vi"
if echo "$ARGS" | grep -qE 'lang=en|--en|\ben\b'; then LANG="en"; fi
if echo "$ARGS" | grep -qE 'lang=vi|--vi'; then LANG="vi"; fi
# 1b) Extract --auto-fix / --sca flags (v0.7+, default off) + scope.
# Duyệt từng từ thay vì sed \b — BSD sed trên macOS không hỗ trợ \b.
AUTO_FIX=false
SCA=false
RUN_TESTS=false
SCOPE_WORDS=""
set -f # không expand glob khi tách từ
for w in $ARGS; do
case "$w" in
--auto-fix|auto-fix) AUTO_FIX=true ;;
--sca|sca) SCA=true ;;
--run-tests) RUN_TESTS=true ;;
lang=vi|lang=en|--vi|--en) ;;
*) SCOPE_WORDS="$SCOPE_WORDS $w" ;;
esac
done
set +f
# 2) Scope = các từ còn lại (đã bỏ lang + auto-fix/sca)
SCOPE=$(echo "$SCOPE_WORDS" | xargs)
# 3) Gather files
NO_GIT_NOTE=""
SCAN_REF=""
SCAN_ROOT="."
case "$SCOPE" in
"staged"|"uncommitted"|"diff"|"commit within "*|"commit id "*|"pr id "*)
if [ "$IS_GIT_REPO" = false ]; then
echo "{msg_scope_needs_git}"
exit 1
fi
case "$SCOPE" in
"staged") FILES=$(git diff --cached --name-only --diff-filter=d) ;;
"uncommitted"|"diff")
# staged + unstaged (so với HEAD) + file mới chưa `git add`; bỏ file đã xoá
FILES=$( { git diff --name-only --diff-filter=d HEAD 2>/dev/null || git diff --cached --name-only --diff-filter=d; git ls-files --others --exclude-standard; } | sort -u | grep -v '^$' || true) ;;
"commit within "*)
DAYS=$(echo "$SCOPE" | grep -oE '[0-9]+')
# Đọc bản hiện tại trên đĩa → bỏ file đã bị xoá sau đó
FILES=$(git log --since="${DAYS} days ago" --name-only --pretty=format: | sort -u | grep -v '^$' | while IFS= read -r f; do [ -f "$f" ] && echo "$f"; done || true) ;;
"commit id "*)
SHA=$(echo "$SCOPE" | sed 's/commit id //')
git cat-file -e "${SHA}^{commit}" 2>/dev/null || { echo "Unknown commit: $SHA"; exit 1; }
FILES=$(git diff-tree --root --no-commit-id --name-only -r --diff-filter=d "$SHA")
SCAN_REF="$SHA" ;;
"pr id "*)
PR=$(echo "$SCOPE" | sed 's/pr id //')
FILES=$(gh pr diff "$PR" --name-only) || exit 1
git fetch -q origin "pull/${PR}/head" 2>/dev/null || git fetch -q "$(gh repo view --json url -q .url)" "pull/${PR}/head" || { echo "Cannot fetch PR #$PR"; exit 1; }
SCAN_REF=$(git rev-parse FETCH_HEAD)
# Bỏ file PR đã xoá (không còn ở head của PR)
FILES=$(echo "$FILES" | while IFS= read -r f; do git cat-file -e "${SCAN_REF}:$f" 2>/dev/null && echo "$f"; done || true) ;;
esac
;;
"all"|"")
if [ "$IS_GIT_REPO" = true ]; then
FILES=$(git ls-files)
else
# Non-git folder — walk filesystem. Exclude folder system + vendored, GIỮ dot-files
# như .env (để scan secrets), .htaccess, .gitignore (file thường, không phải folder).
FILES=$(find . -type f \
-not -path '*/.git/*' \
-not -path '*/.next/*' \
-not -path '*/.nuxt/*' \
-not -path '*/.venv/*' \
-not -path '*/.idea/*' \
-not -path '*/.vscode/*' \
-not -path '*/node_modules/*' \
-not -path '*/vendor/*' \
-not -path '*/dist/*' \
-not -path '*/build/*' \
-not -path '*/target/*' \
-not -path '*/__pycache__/*' \
-not -path '*/vbsec-reports/*' \
2>/dev/null | sed 's|^\./||')
NO_GIT_NOTE="true"
fi
;;
*)
echo "Unknown scope: $SCOPE"
exit 1
;;
esac
# 3b) Scope theo commit/PR: extract snapshot đúng ref ra thư mục tạm.
# Thư mục hiện tại có thể đang ở branch khác → đọc ở đó sẽ quét sai code.
if [ -n "$SCAN_REF" ]; then
TMP_BASE="${TMPDIR:-/tmp}"; SCAN_ROOT=$(mktemp -d "${TMP_BASE%/}/vbsec-scan.XXXXXX")
git archive "$SCAN_REF" | tar -x -C "$SCAN_ROOT"
fi
# 4) Strip noise (double-protect — vd git ls-files có thể trả file ở submodule vendored)
FILES=$(echo "$FILES" | grep -vE '(^|/)(node_modules|vendor|dist|build|\.next|\.nuxt|target|\.venv|__pycache__|\.git|vbsec-reports)/' || true)
# 5) Prepare save location (v0.3+)
TIMESTAMP=$(date +"%Y-%m-%d-%H%M%S")
REPORT_DIR="vbsec-reports"
REPORT_FILE="${REPORT_DIR}/scan-${TIMESTAMP}.md"
mkdir -p "${REPORT_DIR}"
# 6) Check .gitignore (chỉ relevant nếu là git repo)
GITIGNORE_WARNING=""
if [ "$IS_GIT_REPO" = true ]; then
if [ -f .gitignore ]; then
grep -qE '^vbsec-reports/?$' .gitignore || GITIGNORE_WARNING="missing"
else
GITIGNORE_WARNING="missing"
fi
fi
echo "Scope: ${SCOPE:-all (default)}"
echo "Lang: $LANG"
echo "Git repo: $IS_GIT_REPO"
echo "Files: $(echo "$FILES" | wc -l)"
echo "Report file: $REPORT_FILE"
echo "Scan root: $SCAN_ROOT"
echo "SCA (live OSV lookup): $SCA"
echo "Auto-fix: $AUTO_FIX (run tests: $RUN_TESTS)"
[ "$NO_GIT_NOTE" = "true" ] && echo "Note: non-git folder — scanning all files via find"
[ "$GITIGNORE_WARNING" = "missing" ] && echo "Note: vbsec-reports/ not in .gitignore — will warn user at end"Quan trọng:
vbsec-reports/ được excluded khỏi scan list — không scan chính báo cáo của mìnhScan root khác . (scope commit id, pr id), mọi Read/Grep phải đọc file tại $SCAN_ROOT/<path>. Đó là snapshot đúng commit/PR; KHÔNG đọc bản trong thư mục hiện tại (có thể đang ở branch khác). Report vẫn ghi path gốc <path>, không kèm prefix $SCAN_ROOT. LARGE mode: truyền $SCAN_ROOT làm {repo_path} cho từng chunk. Render report xong → rm -rf "$SCAN_ROOT".vbsec-reports/scan-<timestamp>.md cần được mkdir trước khi scan, để workflows save vàoall) dùng find thay git ls-files. Các scope dựa vào git (staged, uncommitted, commit within, commit id, pr id) BẮT BUỘC git — báo msg_scope_needs_git rồi exit.NO_GIT_NOTE=true, report header phải in {msg_no_git_note} để user biết folder không có git → không lọc theo .gitignore.$AUTO_FIX=true nhưng $IS_GIT_REPO=false → Step 4c (auto-fix) sẽ tự skip và in {msg_autofix_needs_git} (không exit toàn bộ scan, phần scan/report vẫn chạy bình thường).$AUTO_FIX=true và $SCAN_ROOT khác . (scope commit id, pr id) → file đang đọc là snapshot tạm, sửa ở đó không có tác dụng. Step 4c KHÔNG apply patch nào: mọi finding CRITICAL/HIGH chỉ ghi diff ra vbsec-reports/patches/, patch_status: "suggested_only", và in {msg_autofix_snapshot_scope} một lần.Đọc file i18n tương ứng với $LANG:
lang=vi → Read references/i18n/vi.mdlang=en → Read references/i18n/en.mdFile i18n chứa bảng key→text cho toàn bộ user-facing strings (section headers, severity labels, verdict, fix recommendations templates). Mọi text trong report final phải lấy từ i18n, KHÔNG hardcode.
Strings KHÔNG bao giờ dịch: rule ID (SQL-INJECTION, XSS, IDOR...), file path, code snippet, command name (/vbs-scan-security).
Đọc references/language-detection.md để biết cách detect. Tóm tắt:
.go, .py, .php, .js, .ts, .jsx, .tsx, .rb, .java, .rs, .cs, .csproj, .slnrules/languages/<lang>/ → load overlay; không có → chỉ dùng genericHiện hỗ trợ chuyên sâu: go, php, typescript (gộp JS+TS), python, dotnet. Các lang khác chỉ dùng generic rules.
| Điều kiện | Ngưỡng | Mode |
|---|---|---|
| Files ngôn ngữ chính | ≤20 | SMALL |
| Files ngôn ngữ chính | >20 | LARGE |
| Tổng files | ≤30 | SMALL |
| Tổng files | >30 | LARGE |
Timespan (chỉ với scope commit within) | ≤14 ngày | SMALL |
| Timespan | >14 ngày | LARGE |
BẤT KỲ điều kiện nào sang LARGE → dùng LARGE mode.
workflows/small-review.md và follow workflow đó (inline, không sub-agent)workflows/large-review.md, trở thành orchestrator only:references/chunking-strategy.md)references/sub-agent-prompts.md.vbsec-tmp/findings-<chunk>.md (luôn dùng EN canonical + rule ID)$LANG → final report.vbsec-tmp/ sau khi doneCho mỗi rule trong rules/generic/ (01-21):
bash <skill-dir>/references/load-rules.sh --part N <lang...> (chạy đủ mọi phần, dòng cuối output cho biết tổng số phần). Chạy nguyên lệnh, KHÔNG thêm | head, | tail, | grep: mỗi phần đã < 20.000 ký tự, cắt output = bỏ sót rule (overlay đã thay generic) → hiểu intent, severity, search patterns gợi ý. Phần Examples/Fix recommendation chỉ Read khi rule có finding CRITICAL/HIGH (chi tiết trong workflow)id) trong rules/languages/<detected-lang>/, rule chuyên sâu thắng generic (đè hoàn toàn pattern + reasoning steps cho lang đó).21 rules generic (luôn chạy) + 1 rule optional (--sca):
| # | ID | Severity max |
|---|---|---|
| 1 | HARDCODED-SECRET | CRITICAL |
| 2 | SQL-INJECTION | CRITICAL |
| 3 | XSS | HIGH |
| 4 | IDOR | HIGH |
| 5 | SLOPSQUATTING | CRITICAL |
| 6 | BRUTE-FORCE | HIGH |
| 7 | MASS-ASSIGNMENT | CRITICAL |
| 8 | INSECURE-DESERIALIZATION | CRITICAL |
| 9 | SSRF | HIGH |
| 10 | PATH-TRAVERSAL | HIGH |
| 11 | CSRF | HIGH |
| 12 | BROKEN-ACCESS-CONTROL | CRITICAL |
| 13 | WEAK-PASSWORD-HASHING | CRITICAL |
| 14 | JWT-NONE-ALGORITHM | CRITICAL |
| 15 | CORS-MISCONFIG | HIGH |
| 16 | UNRESTRICTED-FILE-UPLOAD | CRITICAL |
| 17 | VERBOSE-ERROR-DEBUG-MODE | HIGH |
| 18 | MISSING-RATE-LIMIT | HIGH |
| 19 | RACE-CONDITION | HIGH |
| 20 | OUTDATED-DEPENDENCY | HIGH |
| 21 | COMMAND-INJECTION | CRITICAL |
| 22 | VULNERABLE-DEPENDENCY | CRITICAL |
Rule 22 chỉ chạy khi $SCA=true — xem Step 4b dưới đây. 21 rules còn lại luôn chạy.
--sca)Chỉ chạy khi $SCA=true. Rule 22 KHÔNG được nạp qua load-rules.sh (frontmatter opt_in: --sca), nên Read rules/generic/22-vulnerable-dependency.md ở bước này. Đọc references/dependency-scan.md và follow:
$PRIMARY_LANG (NuGet/.NET, Go, npm/TypeScript, Composer/PHP, PyPI/Python) — có thể nhiều ecosystem nếu multi-lang repo.https://api.osv.dev/v1/querybatch rồi v1/vulns/{id} cho từng package (dùng Bash tool, đây là 1 trong 2 chỗ duy nhất trong skill được phép gọi network thật — chỗ còn lại là gh pr diff).database_specific.severity (không tự tính điểm từ CVSS vector), tạo finding rule_id: VULNERABLE-DEPENDENCY kèm cve_id/fixed_version.{msg_sca_unavailable}/{msg_sca_no_manifest}, KHÔNG fail scan, fallback sang rule 20 (đã chạy sẵn ở Step 4).references/sub-agent-prompts.md mục "Aggregate workflow".--auto-fix)Chỉ chạy khi $AUTO_FIX=true. Chạy TRƯỚC khi render report ở Step 5 (để patch_status kịp có mặt trong JSON summary và section Auto-fix render đúng vị trí). Đọc workflows/auto-fix.md và follow toàn bộ workflow đó:
$IS_GIT_REPO=true, nếu không → in {msg_autofix_needs_git}, skip toàn bộ bước này (report vẫn render bình thường ở Step 5, chỉ thiếu section Auto-fix).
Nếu $SCAN_ROOT khác . (scope commit id, pr id) hoặc scope là staged → chỉ sinh patch, KHÔNG git apply/build verify; mọi finding CRITICAL/HIGH là suggested_only (xem gate trong workflow).--sca).command -v build tool + build baseline. Thiếu tool hoặc baseline fail → không apply gì, mọi finding là suggested_only.git apply --check → snapshot các file sắp bị ghi → git apply → chạy build command theo $PRIMARY_LANG → khôi phục từ snapshot + retry (tối đa 2 lần) nếu fail. KHÔNG revert bằng git checkout (mất thay đổi chưa commit của user).applied khi user bật --run-tests và build + test của project pass trên version mới (Go, dotnet; project phải có test). npm/Composer/PyPI luôn là suggested_only.patch_status vào từng finding đã xử lý — dùng ở Step 5 khi render JSON + section Auto-fix.Tham khảo template trong references/output-format.md. Quy tắc cốt lõi:
Verbose level theo severity:
Layout:
{header_hardening_title}) — gợi ý phòng thủ, KHÔNG phải finding--auto-fix đã chạy ở Step 4c — xem workflows/auto-fix.md)references/output-format.md mục 7Save-to-file (v0.3+):
Sau khi render report:
# Workflow đã chuẩn bị $REPORT_FILE và $GITIGNORE_WARNING ở Step 0
# Ghi TOÀN BỘ report (identical với stdout) vào file:
cat > "$REPORT_FILE" <<'REPORT_EOF'
<full report content here>
REPORT_EOF
# In dòng cuối ra stdout:
echo ""
# LLM thay {key} bằng giá trị từ i18n file đã load ở Step 1 (KHÔNG có shell function tên `i18n`):
echo "📄 {msg_report_saved}: $REPORT_FILE"
[ "$GITIGNORE_WARNING" = "missing" ] && echo "⚠️ {msg_gitignore_warning_title}: {msg_gitignore_warning_text}"LLM agent thực thi bằng Write tool (NOT bash heredoc) để ghi file, sau đó in 1-2 dòng note ra stdout. Nội dung file PHẢI IDENTICAL với output trên stdout.
Mọi section header, severity label, verdict text lấy từ i18n file đã load ở Step 1.
Finding vs hardening note: chỉ tạo finding khi có đường khai thác cụ thể (input attacker điều khiển được tới sink, hoặc cấu hình sai khai thác được ngay). Reasoning kết luận "an toàn" / "không khai thác được" → KHÔNG tạo finding. Ngoại lệ: check/sanitizer viết sai (HasPrefix thiếu /, endsWith domain, algorithms lấy từ header...) LUÔN là finding dù hiện có yếu tố khác chặn — giữ finding, hạ severity, nêu điều kiện bypass. Vấn đề không thuộc 21 rule (token không hết hạn, thiếu header...) → KHÔNG gán rule gần nhất. "Endpoint không có auth" chỉ là finding khi repo có middleware auth mà route này bị bỏ sót, hoặc endpoint bản chất cần quyền (admin, xoá, tiền, dữ liệu người khác); không thêm BROKEN-ACCESS-CONTROL vào dòng đã có finding CRITICAL khác. Gợi ý phòng thủ thêm cho code đã an toàn (header, cờ cookie khi không có XSS, lockfile...) → hardening_notes[] + section {header_hardening_title}, không gán rule_id, không tính vào summary/verdict. Chi tiết: references/output-format.md mục "Finding vs hardening note".
Validate JSON trước khi kết thúc (bắt buộc): sau khi ghi report, chạy python3 <skill-dir>/references/validate-report.py <report-file> (<skill-dir> = thư mục chứa file SKILL.md này). Script báo lỗi → sửa JSON trong report, ghi lại, chạy lại (tối đa 2 lần). Lỗi hay gặp: dùng key id/rule thay vì rule_id, tự đặt rule ID ngoài 21 rule, severity viết thường, summary đếm lệch với findings, finding tự nhận "not reachable" / "không khai thác được" / "mapped to closest rule" (phải chuyển sang hardening_notes), 2 finding trùng file:line:rule_id. Không có python3 → tự đối chiếu với bảng schema ở output-format.md mục 7.
| Điều kiện | Verdict |
|---|---|
| Có ≥1 CRITICAL | FAIL |
| Không CRITICAL, có ≥1 HIGH | WARN |
| Không CRITICAL, không HIGH | PASS |
WARN ≠ approve. Báo cáo cần nêu rõ HIGH issues cần khắc phục trước production.
~/.claude/skills/vbs-scan-security/
├── SKILL.md # File này
├── workflows/
│ ├── small-review.md # Inline scan (default cho repo nhỏ-vừa)
│ ├── large-review.md # Sub-agent delegation
│ └── auto-fix.md # v0.7+: patch/verify/retry loop (--auto-fix)
├── rules/
│ ├── generic/ # 22 rules cross-language
│ │ ├── 01-hardcoded-secret.md
│ │ ├── 02-sql-injection.md
│ │ ├── ... (đến 21, luôn chạy)
│ │ ├── 21-command-injection.md
│ │ └── 22-vulnerable-dependency.md # v0.7+: chỉ chạy với --sca
│ └── languages/ # Override chuyên sâu per language
│ ├── go/ # GORM, slog, Colly...
│ ├── php/ # mysqli/PDO, $_GET, eval/include, Laravel CSRF
│ └── README.md # Hướng dẫn add language mới
└── references/
├── chunking-strategy.md
├── sub-agent-prompts.md
├── language-detection.md
├── data-flow-classification.md
├── dependency-scan.md # v0.7+: parser manifest + OSV.dev query (--sca)
├── output-format.md
└── i18n/
├── vi.md
└── en.mdThêm rule mới (cross-language): tạo file số tiếp theo (23+) trong rules/generic/, frontmatter có id, severity_max, applies_to: all. Update bảng ở Step 4 trong file này.
Thêm language specialization mới (e.g., Ruby): tạo rules/languages/ruby/<rule-id>.md với cùng id như generic — sẽ tự override. Đọc rules/languages/README.md để biết template.
DO:
DON'T:
fmt.Sprintf là SQLi (chỉ flag nếu data là L1 và không parameterize)Mục tiêu là hiểu bảo mật, không phải đếm pattern.
© tanviet12, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 82 other files (references) in skills/vbs-scan-security of tanviet12/vbsec.
Open the folder on GitHubat commit 1b86c27
Vbs Scan Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Vbs Scan Security this skilltanviet12/vbsec | 289 | — | ~6.8k | Automated safety check: Notes | MIT | |
| Deepsec Documentation Guidevercel-labs/deepsec | 8.1k | — | ~956 | Automated safety check: Pass | Apache-2.0 | |
| Native Dependency Updatemono/SkiaSharp | 5.6k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 551 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Cyberowlaikarimhabush/cyberowl | 263 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Pre-Commit Security Scanzereight/gitlab-mcp | 2k | 1 repos | ~859 | Automated safety check: Notes | MIT |
vercel-labs/deepsec
Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.
mono/SkiaSharp
Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
karimhabush/cyberowl
Check if recent cybersecurity alerts from 10 international CERTs affect your current project.
zereight/gitlab-mcp
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
block/codecrucible
Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.
tanviet12/vbsec
A skill your agent uses when scanning code for security vulnerabilities.
Categories
A skill your agent uses when scanning code for security vulnerabilities. Vbs Scan Security is an agent skill from tanviet12/vbsec. Use when scanning code for security vulnerabilities.
Vbs Scan Security fits situations like: scanning code for security vulnerabilities; user says scan security; kiểm tra bảo mật; review security.
Run `npx skills add tanviet12/vbsec --skill vbs-scan-security -a claude-code`. Or copy the skill folder (skills/vbs-scan-security in tanviet12/vbsec) into .claude/skills/vbs-scan-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add tanviet12/vbsec --skill vbs-scan-security -a codex`. Or copy the skill folder (skills/vbs-scan-security in tanviet12/vbsec) into .agents/skills/vbs-scan-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tanviet12/vbsec --skill vbs-scan-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vbs-scan-security, .gemini/skills/vbs-scan-security, .github/skills/vbs-scan-security and .opencode/skills/vbs-scan-security in your project.
Going by SKILL.md and its folder, Vbs Scan Security needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (git, gh, go, dotnet, bash and python3). Our summary lists: Python 3; A Bash shell.
SKILL.md names 1 domain. In commands or code: api.osv.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Vbs Scan Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.8k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Vbs Scan Security: Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Native Dependency Update (mono/SkiaSharp, 5.6k stars), Security Audit (TheDecipherist/claude-code-mastery, 551 stars) and Cyberowlai (karimhabush/cyberowl, 263 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
tanviet12 (a GitHub user) maintains it in tanviet12/vbsec, which has 289 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on September 28, 2026.
Source: tanviet12/vbsec on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.