Skip to content
Back to skills

Security Scan

ASecurity

Check code for security vulnerabilities

  • 147 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentsrustshellsqlapisecurity

Works with

  • api

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add prapaa-ai/agav --skill security-scan --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Scan?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Scan
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/prapaa-ai-security-scan/badge)](https://www.skillsdirectory.com/skills/prapaa-ai-security-scan)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: security-scan
description: Check code for security vulnerabilities
version: 1.0.0
invocation: user
allowed-tools: read_file grep_search find_files list_directory run_command
tags:
  - security
  - audit
---

# Security Scan

Scan code for security vulnerabilities and report findings with remediation guidance.

## Instructions

1. Identify the project's language, framework, and dependency manager.
2. Scan for OWASP Top 10 vulnerabilities:
   - **Injection**: SQL injection, command injection, XSS, template injection. Search for string concatenation in queries, unsanitized user input in shell commands or HTML output.
   - **Broken Authentication**: Weak password handling, missing rate limiting, session fixation.
   - **Sensitive Data Exposure**: Hardcoded secrets, API keys, passwords, tokens in source files or config. Grep for patterns like `password=`, `secret`, `api_key`, `token`, base64-encoded credentials.
   - **Insecure Deserialization**: Use of pickle, eval, unserialize, or YAML.load with untrusted data.
   - **Missing Input Validation**: Endpoints or functions accepting user input without type checks, length limits, or sanitization.
   - **Security Misconfiguration**: Debug mode enabled, CORS wildcard, permissive file permissions, missing security headers.
   - **Vulnerable Dependencies**: Run `npm audit`, `pip audit`, or equivalent to check for known CVEs.
3. For each finding, report:
   - **Severity**: Critical, High, Medium, or Low
   - **Location**: File path and line number
   - **Description**: What the vulnerability is and how it could be exploited
   - **Remediation**: Specific steps or code changes to fix it
4. Sort findings by severity (critical first).
5. If no vulnerabilities are found, confirm the scan was clean and note what was checked.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…