Agent skill

Security Scanner

by WrongStack in WrongStack/WrongStack

A skill your agent uses when scanning code or configuration for security vulnerabilities.

MITAuto-check passedSecurity

Install Security Scanner

skills CLI
$ npx skills add WrongStack/WrongStack --skill security-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install WrongStack/WrongStack security-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/WrongStack/WrongStack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/packages/core/skills/security-scanner .claude/skills/security-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scanner
GitHub stars
370
Token cost
~2.1k tokens
SKILL.md length
654 words
Files
2
Skills in repo
38
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when scanning code or configuration for security vulnerabilities.

  • Works in 7 steps: Always provide remediation — "found X"… → Verify regex matches before flagging —… → Don't scan node_modules — use npm audit… → …
  • Configuration for security vulnerabilities
  • SKILL.md covers Overview, Rules, Patterns and Workflow, plus 10 more sections
  • Calls npm, aws and pnpm

What it does

Security Scanner is an agent skill from WrongStack/WrongStack. Use this skill when scanning code or configuration for security vulnerabilities. Triggers: user says "security", "vulnerability", "CVE", "secret", "injection", "XSS", "SQL injection", "audit security", "supply chain".

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `SKILL.save.md`).

It sits in Security, covering Vulnerability scanning, Web application vulnerabilities and Supply chain security. The repository describes itself as: An AI coding agent that reads your code, edits files, runs commands, and reasons through bugs — across a terminal REPL, a full-screen TUI, and a browser UI, while you keep your… The licence is MIT.

When your agent uses it

  • Configuration for security vulnerabilities
  • Tasks that involve Vulnerability scanning
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “security”
  • “vulnerability”
  • “secret”
  • “/security-scanner”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Always provide remediation — "found X" without "do Y" is useless.
  2. Verify regex matches before flagging — generic patterns cause false positives.
  3. Don't scan node_modules — use npm audit for supply chain issues.
  4. Don't flag test fixtures — mock credentials in tests are acceptable.
  5. Always run dependency audit — supply chain is a real attack vector.
  6. Flag config issues (TLS disabled, HTTP in production) as CRITICAL.
  7. Never echo a full secret into the report — redact it (short prefix + char count, e.g. ghp_…36 chars). Cite file:line you have read; don't…

What it can do on your machine

Read from SKILL.md and the folder at commit 57f6018. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • aws
    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, aws and pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Scanner loads about 2.1k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 654 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from WrongStack/WrongStack at commit 57f6018, republished under its MIT licence (© WrongStack). 654 words, ~2,074 tokens.

Download SKILL.mdSave it as .claude/skills/security-scanner/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
security-scanner
description
Use this skill when scanning code or configuration for security vulnerabilities. Triggers: user says "security", "vulnerability", "CVE", "secret", "injection", "XSS", "SQL injection", "audit security", "supply chain".
version
1.3.0
required-capabilities
filesystem.read, code.inspect
optional-capabilities
dependencies.manage

Security Scanner

Overview

Scans code, configs, and dependencies for security issues. Reports with severity (CRITICAL/HIGH/MEDIUM/LOW) and concrete remediation steps. Pairs with npm audit for supply chain scanning.

Rules

  1. Always provide remediation — "found X" without "do Y" is useless.
  2. Verify regex matches before flagging — generic patterns cause false positives.
  3. Don't scan node_modules — use npm audit for supply chain issues.
  4. Don't flag test fixtures — mock credentials in tests are acceptable.
  5. Always run dependency audit — supply chain is a real attack vector.
  6. Flag config issues (TLS disabled, HTTP in production) as CRITICAL.
  7. Never echo a full secret into the report — redact it (short prefix + char count, e.g. ghp_…36 chars). Cite file:line you have read; don't flag from a pattern guess.

Patterns

Do
typescript
// ✅ SAFE — parameterized query
db.query("SELECT * FROM users WHERE id = $1", [userId]);

// ✅ SAFE — escape user input
element.textContent = userInput;

// ✅ SAFE — execFile with args array
execFile('find', ['.', '-name', userInput], { signal: AbortSignal.timeout(5000) });
Don't
typescript
// ❌ CRITICAL — hardcoded AWS credentials
const awsKey = "[REDACTED:aws_access_key]";

// ❌ CRITICAL — private key committed
const pem = "-----BEGIN RSA PRIVATE KEY-----\nMIIE...";

// ❌ HIGH — XSS via innerHTML
element.innerHTML = userInput;

// ❌ HIGH — shell injection
exec(`find . -name ${userInput}`);

// ❌ HIGH — SQL injection
const query = "SELECT * FROM users WHERE id = " + userId;

Workflow

1. Scope:  Accept paths or use sensible defaults
2. Secrets:  Credential patterns (plus the secret_scanner_test tool when that plugin is loaded)
3. Injection:  The security-ast-scan tool per file when available, then read every hit
4. Config:  Check TLS, crypto, auth configurations
5. Audit:  Run package audit
6. Report:  Prioritized markdown with remediation

Severity levels

LevelMeaningAction
CRITICALActive exploit possibleFix immediately
HIGHVulnerability likely exploitableFix before release
MEDIUMRisk exists but harder to exploitFix soon
LOWBest practice violationConsider fixing

Secret patterns

| Pattern | Example | Level |
|---------|---------|-------|
| GitHub token | `ghp_[a-zA-Z0-9]{36}` | CRITICAL |
| AWS Access Key | `(AKIA|ASIA)[0-9A-Z]{16}` | CRITICAL |
| AWS Secret | base64 40-char | CRITICAL |
| Private Key PEM | `-----BEGIN.*PRIVATE KEY-----` | CRITICAL |
| JWT | `eyJ[a-zA-Z0-9_-]+` | HIGH |
| Generic API Key | 32+ random chars | MEDIUM |
| Bearer token | `Authorization: Bearer xxx` | HIGH |

Real examples

typescript
// ❌ CRITICAL — hardcoded AWS credentials
const awsKey = "[REDACTED:aws_access_key]";

// ❌ CRITICAL — private key committed
const pem = "-----BEGIN RSA PRIVATE KEY-----\nMIIE...";

// ❌ HIGH — JWT in code
const token = "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...";

// ❌ HIGH — XSS via innerHTML
element.innerHTML = userInput;

// ❌ HIGH — shell injection
exec(`find . -name ${userInput}`);

// ❌ HIGH — SQL injection
const query = "SELECT * FROM users WHERE id = " + userId;

// ✅ SAFE — parameterized query
db.query("SELECT * FROM users WHERE id = $1", [userId]);

// ✅ SAFE — escape user input
element.textContent = userInput;

Injection vectors

ConstructSafe alternative
eval(str), new Function(str)Parse instead (JSON.parse, a real parser); new Function evaluates strings exactly like eval
innerHTML = xtextContent or DOMPurify.sanitize
exec(\cmd ${input}`)`execFile with args array
SQL = "SELECT * FROM " + tableparameterized query
fs.readFile(path + userInput)path.resolve + allowlist
fetch(userSuppliedUrl) (SSRF)Allowlist hosts; block private, loopback, and metadata addresses after DNS resolution
Object.assign(target, JSON.parse(body)) (prototype pollution)Reject __proto__ and constructor keys; validate with a schema
/orders/:id loaded without an ownership check (broken object-level authorization)Authorize against the specific object on every request
new RegExp(userInput), nested quantifiers on user input (ReDoS)Escape input, bound its length, use linear-time patterns

Configuration checks

- TLS verification disabled? → CRITICAL for production
- HTTP instead of HTTPS? → MEDIUM for production
- Secrets in env vars logged to console? → CRITICAL
- Hardcoded credentials in config? → CRITICAL
- Overly permissive CORS? → MEDIUM
- Missing rate limiting? → MEDIUM-HIGH

Anti-patterns

  • Don't scan node_modules — use npm audit instead
  • Don't report without remediation — "found X" is useless without "do Y"
  • Don't ignore false positives — verify regex matches before flagging (especially generic patterns)
  • Don't skip dependency scanning — supply chain is a real attack vector
  • Don't flag test fixtures — mock credentials in tests are ok, but not in production code

Remediation template

## Remediation Checklist
- [ ] Remove hardcoded credentials from `src/config.ts`
- [ ] Move secrets to environment variables, add to .gitignore
- [ ] Use parameterized queries in `src/db/` files
- [ ] Add rate limiting to `src/api/` routes

<nextsteps>
1. Fix the hardcoded API key in src/config.ts
2. Fix the shell injection in src/auth/login.ts
3. Fix the missing rate limiting in src/api/routes.ts
</nextsteps>
Show full SKILL.md (327 more words)Show less

Out of scope

  • Don't echo a full secret in the report. Redact. A ghp_…36 chars is enough for the reader to find and rotate it. The unredacted value in a report is itself a leak.
  • Don't flag a file:line you haven't read. Generic patterns cause false positives; verify the line is real before reporting. No "looks like a secret" findings.
  • Don't flag test fixtures as leaked secrets. Mock credentials in tests/ and __fixtures__ are expected. Skip them; flag leaks in production code.
  • Don't scan node_modules. Use npm audit / pnpm audit for supply chain. Grepping node_modules is a noise machine.
  • Don't report without remediation. "Found X" without "do Y" is a finding the user has to research themselves. Always include the fix.
  • Don't claim CRITICAL without proof of exploitability. Severity ladders are real. A pattern hit is a lead, not a warrant. State the input that triggers the bug and the consequence.
  • Don't bypass dependency audit. Supply chain is an attack vector; skipping npm audit / lockfile review is skipping the scanner.
  • Don't disable TLS or relax auth configs as a "config option" without flagging CRITICAL. TLS disabled in production is a CRITICAL, not a config note.

Before returning

  • Every file:line opened and confirmed; no flag from a regex guess
  • Secrets redacted in the report (prefix + char count, never the value)
  • Test fixtures skipped for secrets; flagged only for leak/unawaited patterns
  • node_modules not scanned; supply chain via npm audit / lockfile review
  • Every finding carries a remediation; "found X" without "do Y" not shipped
  • Severity passes the ladder; CRITICAL reserved for proven exploitability
  • Dependency audit included; CVE/version drift covered
  • TLS / HTTP / CORS / rate-limit configuration checked and reported
  • False-positive rate called out with a cause when it exceeds 30%
  • Summary counts match the findings listed; <nextsteps> mirrors them in severity order

Skills in scope

  • bug-hunter — for general code quality bugs found during security scan
  • audit-log — for dependency version audit trails
  • git-flow — for committing security patches properly
  • output-standards — for standardized <nextsteps> formatting

© WrongStack, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in packages/core/skills/security-scanner of WrongStack/WrongStack.

  • SKILL.md
  • SKILL.save.md

Open the folder on GitHubat commit 57f6018

Compare with similar skills

Security Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Scanner this skillWrongStack/WrongStack370—~2.1kAutomated safety check: PassMIT
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
Vulnerability ScannerxenitV1/Antigravity-Workflows1307 repos~1.8kAutomated safety check: NotesMIT
Dependency AwarenessGoldziher/ai-rulez158—~250Automated safety check: PassMIT
Agent BomLeoYeAI/openclaw-master-skills2.2k—~4.4kAutomated safety check: PassApache-2.0
Skill InspectorNVIDIA/SkillSpector20k1 repos~1.8kAutomated safety check: PassApache-2.0

Similar skills

  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Vulnerability Scanner

    xenitV1/Antigravity-Workflows

    Advanced vulnerability analysis principles. An agent skill from xenitV1/Antigravity-Workflows.

    130 GitHub starsUsed in 7 repos~1.8k tokens
    SecurityAuto-check: notes
  • Dependency Awareness

    Goldziher/ai-rulez

    Per-language dependency vulnerability audit tool reference (cargo audit/deny, pip-audit, npm/pnpm audit, govulncheck, bundler-audit, composer audit, OWASP dependency-check, dotnet vulnerable…

    158 GitHub stars~250 tokensUpdated today
    SecurityAuto-check passed
  • Agent Bom

    LeoYeAI/openclaw-master-skills

    Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS…

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes

More from WrongStack/WrongStack

All 38 skills in this repo
  • Design Craft

    WrongStack/WrongStack

    Design or substantially improve user-facing interfaces with a product-specific visual direction, content hierarchy, and rendered critique.

    370 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Design Critique

    WrongStack/WrongStack

    A skill your agent uses to audit an interface that already exists and say precisely why it looks generated, templated, or unfinished — a scored rubric across composition, typography, color, states…

    370 GitHub stars~3k tokensUpdated yesterday
    Auto-check passed
  • Mailbox Bridge

    WrongStack/WrongStack

    A skill your agent uses when external coding agents (Claude Code, Aider, custom scripts) need to participate in the project's shared WrongStack mailbox, or when a user asks to "expose the mailbox"…

    370 GitHub stars~3.9k tokensUpdated yesterday
    Auto-check passed
  • Multi Agent

    WrongStack/WrongStack

    A skill your agent uses whenever work can be split across multiple AI agents running in parallel, or when orchestrating leader/worker patterns in WrongStack.

    370 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Web Platform Baseline

    WrongStack/WrongStack

    Use this skill before asserting that a CSS, HTML or accessibility capability is available, unavailable, or the right tool — it carries dated, refreshable platform facts and refuses to let stale…

    370 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Wrongstack Mailbox

    WrongStack/WrongStack

    A skill your agent uses when the user wants to communicate with WrongStack's shared project mailbox from outside WrongStack — read messages sent by WrongStack agents, send replies, broadcast to all…

    370 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Security Scanner

What does Security Scanner do?

A skill your agent uses when scanning code or configuration for security vulnerabilities. Security Scanner is an agent skill from WrongStack/WrongStack. Use this skill when scanning code or configuration for security vulnerabilities.

When should I use Security Scanner?

Security Scanner fits situations like: configuration for security vulnerabilities; tasks that involve Vulnerability scanning; tasks that involve Web application vulnerabilities.

How do I install Security Scanner in Claude Code?

Run `npx skills add WrongStack/WrongStack --skill security-scanner -a claude-code`. Or copy the skill folder (packages/core/skills/security-scanner in WrongStack/WrongStack) into .claude/skills/security-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Security Scanner in Codex?

Run `npx skills add WrongStack/WrongStack --skill security-scanner -a codex`. Or copy the skill folder (packages/core/skills/security-scanner in WrongStack/WrongStack) into .agents/skills/security-scanner in your project. Codex loads it when a task matches its description.

Can I use Security Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add WrongStack/WrongStack --skill security-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scanner, .gemini/skills/security-scanner, .github/skills/security-scanner and .opencode/skills/security-scanner in your project.

What does Security Scanner need to run?

Going by SKILL.md and its folder, Security Scanner needs the command-line tools its instructions call (npm, aws and pnpm).

Does Security Scanner access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Scanner use?

Security Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Scanner use?

About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Scanner?

Skills that share tags, products or a category with Security Scanner: Cyber Neo (Hainrixz/cyber-neo, 281 stars), Vulnerability Scanner (xenitV1/Antigravity-Workflows, 130 stars), Dependency Awareness (Goldziher/ai-rulez, 158 stars) and Agent Bom (LeoYeAI/openclaw-master-skills, 2.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Scanner?

WrongStack (a GitHub organization) maintains it in WrongStack/WrongStack, which has 370 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on October 7, 2026.

Source: WrongStack/WrongStack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.