Agent skill

Pre-Commit Security Scan

by zereight in zereight/gitlab-mcp

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

MITAuto-check: notesSecurity

Install Pre-Commit Security Scan

skills CLI
$ npx skills add zereight/gitlab-mcp --skill security-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zereight/gitlab-mcp security-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/security-scan .claude/skills/security-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scan
GitHub stars
2k
Used in
1 other repo
Token cost
~859 tokens
SKILL.md length
235 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

  • Works in 5 steps: Determine Scope → Secrets Scan → Dependency Audit → …
  • Running a quick security gate before opening a pull request
  • SKILL.md covers When to Use, Scan Protocol, Output Format and Severity Quick Reference, plus 1 more section
  • Calls git, npm and cargo

What it does

The scan is meant to be faster than a full review and focused only on security, run before committing code that touches auth, user input, data storage or external APIs, or right after adding a new dependency. It starts by scoping to the files changed since the last commit, defaulting to git diff --name-only HEAD~1.

A secrets scan greps changed source files for common secret patterns, such as long API-key-shaped strings, and treats any match found in committed code as an immediate blocker. A dependency audit then runs the language-appropriate tool, for example npm audit at a high severity level, and reports the count of critical and high CVEs with their package names.

The remaining steps are a manual spot-check: for files touching user input, whether it is validated, whether SQL queries are parameterized, whether HTML output is escaped and whether file paths are sanitized against traversal; for files touching auth, whether authentication runs before authorization, whether checks exist on every relevant endpoint, whether JWTs are validated on algorithm, signature and expiry, and whether session cookies are HttpOnly, Secure and SameSite=Strict. Findings are reported with a severity table ranking issues from a hardcoded secret, rated critical, down to plain HTTP instead of HTTPS, rated medium.

When your agent uses it

  • Running a quick security gate before opening a pull request
  • Checking for leaked secrets or vulnerable dependencies after a change
  • Spot-checking new input handling or authorization code for common gaps

Example prompts

  • “Run a security scan on my recent changes before I open this PR.”
  • “Check for secrets or vulnerable dependencies after this npm install.”
  • “Scan the new payment endpoint for missing auth checks.”

Requirements

  • git
  • A dependency audit tool for the project's language (such as npm)

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Determine Scope
  2. Secrets Scan
  3. Dependency Audit
  4. Input Validation Spot-Check
  5. Auth/Authz Quick Check

What it can do on your machine

Read from SKILL.md and the folder at commit 0109168. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npm
    • cargo
    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pre-Commit Security Scan loads about 859 tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 235 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~859

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:41
    # Check .env is in .gitignore

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zereight/gitlab-mcp at commit 0109168, republished under its MIT licence (© zereight). 235 words, ~859 tokens.

Download SKILL.mdSave it as .claude/skills/security-scan/SKILL.md (or your agent's skills folder).
name
security-scan
description
Rapid security scanning workflow for code changes. Activates a focused security sweep. Activate when: security scan, scan for vulnerabilities, check for secrets, security check, run security audit, check deps.
argument-hint
[path or scope to scan — defaults to recent git changes]

Security Scan

Rapid security sweep for code changes. Faster than a full /review — focused on security only.

When to Use

  • Before committing code that touches auth, user input, data storage, or external APIs
  • After adding new dependencies
  • Quick pre-PR security gate

Scan Protocol

Step 1: Determine Scope
bash
# Default: scan recent changes
git diff --name-only HEAD~1

# Or use provided path
Step 2: Secrets Scan
bash
# Scan for common secret patterns
grep -rn --include="*.{ts,js,py,go,rs,java,cs,yaml,json,env,sh,toml}" \
  -e "sk-[A-Za-z0-9]\{32,\}" \
  -e "ghp_[A-Za-z0-9]\{36\}" \
  -e "AKIA[0-9A-Z]\{16\}" \
  -e "api.key\s*=\s*['\"][^'\"]\{8,\}" \
  -e "password\s*=\s*['\"][^'\"]\{4,\}" \
  -e "secret\s*=\s*['\"][^'\"]\{8,\}" \
  .

# Check .env is in .gitignore
cat .gitignore | grep -E "\.env$|\.env\."

CRITICAL: Any match in committed code = immediate blocker.

Step 3: Dependency Audit

Run language-appropriate audit:

bash
# Node.js
npm audit --audit-level=high

# Python
pip-audit  # or: safety check

# Rust
cargo audit

# Go
govulncheck ./...

# Java/Maven
mvn dependency-check:check

Report: Count of critical/high severity CVEs and their package names.

Step 4: Input Validation Spot-Check

For changed files that handle user input (API endpoints, form handlers, CLI args):

  • Is input validated/sanitized before use?
  • Are SQL queries parameterized (no string concatenation)?
  • Is HTML output escaped before rendering?
  • Are file paths sanitized (no ../ traversal)?
Step 5: Auth/Authz Quick Check

For changed files touching auth:

  • Is authentication checked BEFORE authorization?
  • Are authorization checks on EVERY relevant endpoint?
  • Are JWT tokens validated (algorithm + signature + expiry)?
  • Are session cookies HttpOnly; Secure; SameSite=Strict?

Output Format

## Security Scan Report

**Scope:** [files scanned]
**Date:** [timestamp]

### Secrets
- [ ] No hardcoded secrets found
- ⚠ Found: [file:line — description]

### Dependencies
- Critical CVEs: X
- High CVEs: Y
- Packages: [list if any]

### Input Validation
- [ ] User inputs sanitized in changed files
- ⚠ Risk: [file:line — description]

### Auth
- [ ] Auth/authz checks present on relevant routes
- ⚠ Risk: [file:line — description]

### Verdict
CLEAN / NEEDS ATTENTION / BLOCKER

### Next Steps
- [Action items with file:line references]

Severity Quick Reference

FindingSeverityAction
Hardcoded secret in committed fileCRITICALRotate key + remove from history
Critical CVE in direct dependencyHIGHUpdate package immediately
SQL injection riskCRITICALParameterize query before PR
Missing auth check on endpointHIGHAdd before PR
High CVE in transitive dependencyMEDIUMTrack in backlog
HTTP instead of HTTPSMEDIUMEnforce HTTPS redirect

See Also

  • @security-reviewer — comprehensive OWASP Top 10 security review
  • /review — full code review including security
  • /coding-standards — baseline code quality rules

© zereight, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/security-scan of zereight/gitlab-mcp.

Open the folder on GitHubat commit 0109168

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in zereight/gitlab-mcp, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Pre-Commit Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pre-Commit Security Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pre-Commit Security Scan this skillzereight/gitlab-mcp2k1 repos~859Automated safety check: NotesMIT
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Code Vuln Auditzebbern/claude-code-guide4.6k—~1.3kAutomated safety check: PassMIT
Security Vuln Remediationstacklok/toolhive-studio170—~2.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Code Vuln Audit

    zebbern/claude-code-guide

    Scan code for security issues: dependency vulnerabilities (npm/pip audit), secret leaks (regex and entropy analysis), and OWASP anti-patterns like SQL injection, XSS, or command injection.

    4.6k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • Security Vuln Remediation

    stacklok/toolhive-studio

    Remediate security vulnerabilities found by Grype or pnpm audit.

    170 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check: notes
  • Security Scan

    bagofwords1/bagofwords

    Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

    458 GitHub stars~1.7k tokensUpdated today
    SecurityAuto-check passed

More from zereight/gitlab-mcp

All 24 skills in this repo
  • OMG Mode Canceller

    zereight/gitlab-mcp

    Detects which autonomous OMG mode is currently active - Autopilot, Ralph, Ultrawork, UltraQA, Team or Self-Improve - and shuts it down cleanly.

    2k GitHub starsUsed in 1 repo~690 tokens
    Auto-check passed
  • CCG Tri-Model Orchestration

    zereight/gitlab-mcp

    Runs a task through Codex and Gemini CLIs in parallel alongside Claude, then synthesizes the three outputs into one answer with agreements and conflicts called out.

    2k GitHub starsUsed in 1 repo~657 tokens
    Auto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Remember Project Knowledge

    zereight/gitlab-mcp

    Sorts what you learned in a session into the right memory surface, filtering out ephemeral notes and duplicates before anything is stored.

    2k GitHub starsUsed in 1 repo~846 tokens
    Auto-check passed
  • Skill Inventory Stocktake

    zereight/gitlab-mcp

    Audits a project's skill directories for broken frontmatter, missing template sync and quality gaps, then produces a health report of what needs fixing.

    2k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed
  • OMG Mode Status

    zereight/gitlab-mcp

    Reports which OMG modes are active, such as autopilot, ralph, team, ultraqa and self-improve, with phase, story or cycle progress read from their state files.

    2k GitHub starsUsed in 1 repo~441 tokens
    Auto-check passed

Works with

Categories

Questions about Pre-Commit Security Scan

What does Pre-Commit Security Scan do?

Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps. The scan is meant to be faster than a full review and focused only on security, run before committing code that touches auth, user input, data storage or external APIs, or right after adding a new dependency. It starts by scoping to the files changed since the last commit, defaulting to git diff --name-only HEAD~1.

When should I use Pre-Commit Security Scan?

Pre-Commit Security Scan fits situations like: running a quick security gate before opening a pull request; checking for leaked secrets or vulnerable dependencies after a change; spot-checking new input handling or authorization code for common gaps.

How do I install Pre-Commit Security Scan in Claude Code?

Run `npx skills add zereight/gitlab-mcp --skill security-scan -a claude-code`. Or copy the skill folder (.github/skills/security-scan in zereight/gitlab-mcp) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.

How do I install Pre-Commit Security Scan in Codex?

Run `npx skills add zereight/gitlab-mcp --skill security-scan -a codex`. Or copy the skill folder (.github/skills/security-scan in zereight/gitlab-mcp) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.

Can I use Pre-Commit Security Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zereight/gitlab-mcp --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.

What does Pre-Commit Security Scan need to run?

Going by SKILL.md and its folder, Pre-Commit Security Scan needs the command-line tools its instructions call (git, npm, cargo and mvn). Our summary lists: git; A dependency audit tool for the project's language (such as npm).

Does Pre-Commit Security Scan access the network?

SKILL.md contains no URLs. Its commands use git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pre-Commit Security Scan safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Pre-Commit Security Scan use?

Pre-Commit Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pre-Commit Security Scan use?

About 859 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pre-Commit Security Scan?

Skills that share tags, products or a category with Pre-Commit Security Scan: Security Audit (TheDecipherist/claude-code-mastery, 550 stars), CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars) and Code Vuln Audit (zebbern/claude-code-guide, 4.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pre-Commit Security Scan?

zereight (a GitHub user) maintains it in zereight/gitlab-mcp, which has 2,027 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: zereight/gitlab-mcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.