Cyber Neo
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
A skill your agent uses when scanning code or configuration for security vulnerabilities.
$ npx skills add WrongStack/WrongStack --skill security-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install WrongStack/WrongStack security-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/security-scanner .claude/skills/security-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-scanner" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/security-scanner into .claude/skills/security-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/security-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add WrongStack/WrongStack --skill security-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install WrongStack/WrongStack security-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/packages/core/skills/security-scanner .agents/skills/security-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-scanner" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/security-scanner into .agents/skills/security-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill security-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install WrongStack/WrongStack security-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/packages/core/skills/security-scanner .cursor/skills/security-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-scanner" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/security-scanner into .cursor/skills/security-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/WrongStack/WrongStack.git --path packages/core/skills/security-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add WrongStack/WrongStack --skill security-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install WrongStack/WrongStack security-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/packages/core/skills/security-scanner .gemini/skills/security-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-scanner" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/security-scanner into .gemini/skills/security-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install WrongStack/WrongStack security-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add WrongStack/WrongStack --skill security-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .github/skills && cp -r skills-src/packages/core/skills/security-scanner .github/skills/security-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-scanner" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/security-scanner into .github/skills/security-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add WrongStack/WrongStack --skill security-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install WrongStack/WrongStack security-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/packages/core/skills/security-scanner .opencode/skills/security-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-scanner" agent skill from https://github.com/WrongStack/WrongStack/tree/main/packages/core/skills/security-scanner into .opencode/skills/security-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-scannerA skill your agent uses when scanning code or configuration for security vulnerabilities.
Security Scanner is an agent skill from WrongStack/WrongStack. Use this skill when scanning code or configuration for security vulnerabilities. Triggers: user says "security", "vulnerability", "CVE", "secret", "injection", "XSS", "SQL injection", "audit security", "supply chain".
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SKILL.save.md`).
It sits in Security, covering Vulnerability scanning, Web application vulnerabilities and Supply chain security. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmawspnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, aws and pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Scanner loads about 2.1k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 654 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 654 words, ~2,074 tokens.
.claude/skills/security-scanner/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Scans code, configs, and dependencies for security issues. Reports with severity (CRITICAL/HIGH/MEDIUM/LOW) and concrete remediation steps. Pairs with npm audit for supply chain scanning.
node_modules — use npm audit for supply chain issues.ghp_…36 chars). Cite file:line you have read; don't flag from a pattern guess.// ✅ SAFE — parameterized query
db.query("SELECT * FROM users WHERE id = $1", [userId]);
// ✅ SAFE — escape user input
element.textContent = userInput;
// ✅ SAFE — execFile with args array
execFile('find', ['.', '-name', userInput], { signal: AbortSignal.timeout(5000) });// ❌ CRITICAL — hardcoded AWS credentials
const awsKey = "[REDACTED:aws_access_key]";
// ❌ CRITICAL — private key committed
const pem = "-----BEGIN RSA PRIVATE KEY-----\nMIIE...";
// ❌ HIGH — XSS via innerHTML
element.innerHTML = userInput;
// ❌ HIGH — shell injection
exec(`find . -name ${userInput}`);
// ❌ HIGH — SQL injection
const query = "SELECT * FROM users WHERE id = " + userId;1. Scope: Accept paths or use sensible defaults
2. Secrets: Credential patterns (plus the secret_scanner_test tool when that plugin is loaded)
3. Injection: The security-ast-scan tool per file when available, then read every hit
4. Config: Check TLS, crypto, auth configurations
5. Audit: Run package audit
6. Report: Prioritized markdown with remediation| Level | Meaning | Action |
|---|---|---|
| CRITICAL | Active exploit possible | Fix immediately |
| HIGH | Vulnerability likely exploitable | Fix before release |
| MEDIUM | Risk exists but harder to exploit | Fix soon |
| LOW | Best practice violation | Consider fixing |
| Pattern | Example | Level |
|---------|---------|-------|
| GitHub token | `ghp_[a-zA-Z0-9]{36}` | CRITICAL |
| AWS Access Key | `(AKIA|ASIA)[0-9A-Z]{16}` | CRITICAL |
| AWS Secret | base64 40-char | CRITICAL |
| Private Key PEM | `-----BEGIN.*PRIVATE KEY-----` | CRITICAL |
| JWT | `eyJ[a-zA-Z0-9_-]+` | HIGH |
| Generic API Key | 32+ random chars | MEDIUM |
| Bearer token | `Authorization: Bearer xxx` | HIGH |// ❌ CRITICAL — hardcoded AWS credentials
const awsKey = "[REDACTED:aws_access_key]";
// ❌ CRITICAL — private key committed
const pem = "-----BEGIN RSA PRIVATE KEY-----\nMIIE...";
// ❌ HIGH — JWT in code
const token = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...";
// ❌ HIGH — XSS via innerHTML
element.innerHTML = userInput;
// ❌ HIGH — shell injection
exec(`find . -name ${userInput}`);
// ❌ HIGH — SQL injection
const query = "SELECT * FROM users WHERE id = " + userId;
// ✅ SAFE — parameterized query
db.query("SELECT * FROM users WHERE id = $1", [userId]);
// ✅ SAFE — escape user input
element.textContent = userInput;| Construct | Safe alternative |
|---|---|
eval(str), new Function(str) | Parse instead (JSON.parse, a real parser); new Function evaluates strings exactly like eval |
innerHTML = x | textContent or DOMPurify.sanitize |
exec(\cmd ${input}`)` | execFile with args array |
SQL = "SELECT * FROM " + table | parameterized query |
fs.readFile(path + userInput) | path.resolve + allowlist |
fetch(userSuppliedUrl) (SSRF) | Allowlist hosts; block private, loopback, and metadata addresses after DNS resolution |
Object.assign(target, JSON.parse(body)) (prototype pollution) | Reject __proto__ and constructor keys; validate with a schema |
/orders/:id loaded without an ownership check (broken object-level authorization) | Authorize against the specific object on every request |
new RegExp(userInput), nested quantifiers on user input (ReDoS) | Escape input, bound its length, use linear-time patterns |
- TLS verification disabled? → CRITICAL for production
- HTTP instead of HTTPS? → MEDIUM for production
- Secrets in env vars logged to console? → CRITICAL
- Hardcoded credentials in config? → CRITICAL
- Overly permissive CORS? → MEDIUM
- Missing rate limiting? → MEDIUM-HIGHnode_modules — use npm audit instead## Remediation Checklist
- [ ] Remove hardcoded credentials from `src/config.ts`
- [ ] Move secrets to environment variables, add to .gitignore
- [ ] Use parameterized queries in `src/db/` files
- [ ] Add rate limiting to `src/api/` routes
<nextsteps>
1. Fix the hardcoded API key in src/config.ts
2. Fix the shell injection in src/auth/login.ts
3. Fix the missing rate limiting in src/api/routes.ts
</nextsteps>ghp_…36 chars is enough for the reader to find and rotate it. The unredacted value in a report is itself a leak.file:line you haven't read. Generic patterns cause false positives; verify the line is real before reporting. No "looks like a secret" findings.tests/ and __fixtures__ are expected. Skip them; flag leaks in production code.node_modules. Use npm audit / pnpm audit for supply chain. Grepping node_modules is a noise machine.npm audit / lockfile review is skipping the scanner.file:line opened and confirmed; no flag from a regex guessnode_modules not scanned; supply chain via npm audit / lockfile review<nextsteps> mirrors them in severity orderbug-hunter — for general code quality bugs found during security scanaudit-log — for dependency version audit trailsgit-flow — for committing security patches properlyoutput-standards — for standardized <nextsteps> formatting© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in packages/core/skills/security-scanner of WrongStack/WrongStack.
Open the folder on GitHubat commit 57f6018
Security Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Scanner this skillWrongStack/WrongStack | 370 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Vulnerability ScannerxenitV1/Antigravity-Workflows | 130 | 7 repos | ~1.8k | Automated safety check: Notes | MIT | |
| Dependency AwarenessGoldziher/ai-rulez | 158 | — | ~250 | Automated safety check: Pass | MIT | |
| Agent BomLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | |
| Skill InspectorNVIDIA/SkillSpector | 20k | 1 repos | ~1.8k | Automated safety check: Pass | Apache-2.0 |
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
xenitV1/Antigravity-Workflows
Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.
Goldziher/ai-rulez
Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…
LeoYeAI/openclaw-master-skills
Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…
NVIDIA/SkillSpector
Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.
eigent-ai/eigent
Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.
WrongStack/WrongStack
Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.
WrongStack/WrongStack
A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…
WrongStack/WrongStack
A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…
WrongStack/WrongStack
A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.
WrongStack/WrongStack
Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…
WrongStack/WrongStack
A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…
Categories
A skill your agent uses when scanning code or configuration for security vulnerabilities. Security Scanner is an agent skill from WrongStack/WrongStack. Use this skill when scanning code or configuration for security vulnerabilities.
Security Scanner fits situations like: configuration for security vulnerabilities; tasks that involve Vulnerability scanning; tasks that involve Web application vulnerabilities.
Run `npx skills add WrongStack/WrongStack --skill security-scanner -a claude-code`. Or copy the skill folder (packages/core/skills/security-scanner in WrongStack/WrongStack) into .claude/skills/security-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add WrongStack/WrongStack --skill security-scanner -a codex`. Or copy the skill folder (packages/core/skills/security-scanner in WrongStack/WrongStack) into .agents/skills/security-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill security-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scanner, .gemini/skills/security-scanner, .github/skills/security-scanner and .opencode/skills/security-scanner in your project.
Going by SKILL.md and its folder, Security Scanner needs the command-line tools its instructions call (npm, aws and pnpm).
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Scanner: Cyber Neo (Hainrixz/cyber-neo, 281 stars), Vulnerability Scanner (xenitV1/Antigravity-Workflows, 130 stars), Dependency Awareness (Goldziher/ai-rulez, 158 stars) and Agent Bom (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.
Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.