Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Continuous security vulnerability scanning for OWASP Top 10, common vulnerabilities, and insecure patterns. Use when reviewing code, before deployments, or on file changes. Scans for SQL injection, XSS, secrets exposure, auth issues. Triggers on file changes, security mentions, deployment prep.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 50% | 0% |
| case-06 | ✗→✓ | ▲ Improved | 12% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 272% | 0% |
| case-15 | ✓→✗ | ▼ Worse | 72% | 0% |
| case-07 | ✓→✓ | = Same ✓ | 38% | 0% |
Automatic security vulnerability detection.
1. SQL Injection
javascript// CRITICAL: SQL injection const query = `SELECT * FROM users WHERE id = ${userId}`; // SECURE: Parameterized query const query = 'SELECT * FROM users WHERE id = ?'; db.query(query, [userId]);
2. XSS (Cross-Site Scripting)
javascript// CRITICAL: XSS vulnerability element.innerHTML = userInput; // SECURE: Use textContent or sanitize element.textContent = userInput; // or element.innerHTML = DOMPurify.sanitize(userInput);
3. Authentication Issues
javascript// CRITICAL: Weak JWT secret const token = jwt.sign(payload, 'secret123'); // SECURE: Strong secret from environment const token = jwt.sign(payload, process.env.JWT_SECRET);
4. Sensitive Data Exposure
python# CRITICAL: Exposed password password = "admin123" # SECURE: Environment variable password = os.getenv("DB_PASSWORD")
5. Broken Access Control
javascript// CRITICAL: No authorization check app.delete('/api/users/:id', (req, res) => { User.delete(req.params.id); }); // SECURE: Authorization check app.delete('/api/users/:id', auth, checkOwnership, (req, res) => { User.delete(req.params.id); });
🚨 CRITICAL: [Vulnerability type]
📍 Location: file.js:42
🔧 Fix: [Specific remediation]
📖 Reference: [OWASP/CWE link]javascript// You write: app.get('/users', (req, res) => { const sql = `SELECT * FROM users WHERE name = '${req.query.name}'`; db.query(sql, (err, results) => res.json(results)); }); // I alert: 🚨 CRITICAL: SQL injection vulnerability (line 2) 📍 File: routes/users.js, Line 2 🔧 Fix: Use parameterized queries const sql = 'SELECT * FROM users WHERE name = ?'; db.query(sql, [req.query.name], ...); 📖 https://owasp.org/www-community/attacks/SQL_Injection
python# You write: def create_user(username, password): user = User(username=username, password=password) user.save() # I alert: 🚨 CRITICAL: Storing plain text password (line 2) 📍 File: models.py, Line 2 🔧 Fix: Hash passwords before storing from bcrypt import hashpw, gensalt hashed = hashpw(password.encode(), gensalt()) user = User(username=username, password=hashed) 📖 Use bcrypt, scrypt, or argon2 for password hashing
javascript// You write: const stripe = require('stripe')('sk_live_abc123...'); // I alert: 🚨 CRITICAL: Hardcoded API key detected (line 1) 📍 File: payment.js, Line 1 🔧 Fix: Use environment variables const stripe = require('stripe')(process.env.STRIPE_SECRET_KEY); 📖 Never commit API keys to version control
I can run security audits on dependencies:
bash# Node.js npm audit # Python pip-audit # Results flagged with severity
Me (Skill): Quick vulnerability pattern detection @code-reviewer (Sub-Agent): Deep security audit with threat modeling
Works without sandboxing: ✅ Yes Works with sandboxing: ✅ Yes
Optional: For dependency scanning
json{ "network": { "allowedDomains": [ "registry.npmjs.org", "pypi.org", "api.github.com" ] } }
security-auditor: Checks code patterns
secret-scanner: Checks for exposed secrets
Together: Comprehensive security coveragebash/review --scope staged --checks security # Workflow: # 1. My automatic security findings # 2. @code-reviewer sub-agent deep audit # 3. Comprehensive security report
Add company-specific security patterns:
bashcp -r ~/.claude/skills/security/security-auditor \ ~/.claude/skills/security/company-security-auditor # Edit SKILL.md to add: # - Internal API patterns # - Company security policies # - Custom vulnerability checks
Other measured skills in the registry, with their headline benchmark lift.