Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Runs a multi-phase security audit covering static analysis (SAST), dependency scanning (SCA), secret detection, and configuration review. Maps findings to OWASP Top 10 categories with CVSS scoring. Produces a prioritized report with remediation guidance.
.claude/skills/miosa-osa-security-scan/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-20 | ✗→✓ | ▲ Improved | 35% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -6% | 0% |
| case-18 | ✗→✓ | ▲ Improved | -54% | 0% |
| case-19 | ✗→✓ | ▲ Improved | -42% | 0% |
| case-15 | ✓→✓ | = Same ✓ | 4% | 0% |
> Run comprehensive security audit: SAST, SCA, secret detection, config review.
/security-scan [path] [--focus <owasp-category>] [--severity <critical|high|medium|low>]Runs a multi-phase security audit covering static analysis (SAST), dependency scanning (SCA), secret detection, and configuration review. Maps findings to OWASP Top 10 categories with CVSS scoring. Produces a prioritized report with remediation guidance.
Detect project type, languages, sensitive file patterns, existing security configs.
Security headers, CORS, cookie flags, TLS config, auth settings.
Prioritized findings with CVSS scores, OWASP mapping, CWE correlation, and remediation steps.
bash# Full security scan /security-scan # Scan specific directory /security-scan lib/ # Focus on injection vulnerabilities /security-scan --focus A03 # Only show critical and high findings /security-scan --severity high
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-15 | pass→pass | 25,330 | 21,144 | -17% | 1 | 1 | 0% | 3,954 | 4,110 | +4% | 0 | 0 | — |
case-20 | fail→pass | 23,241 | 23,937 | +3% | 1 | 1 | 0% | 2,932 | 3,955 | +35% | 0 | 0 | — |
case-01 | fail→fail | 12,615 | 12,656 | +0% | 1 | 1 | 0% | 2,001 | 1,412 | -29% | 0 | 0 | — |
case-02 | fail→fail | 14,256 | 14,558 | +2% | 1 | 1 | 0% | 1,236 | 1,463 | +18% | 0 | 0 | — |
case-03 | fail→fail | 15,250 | 16,517 | +8% | 1 | 1 | 0% | 1,089 | 1,453 | +33% | 0 | 0 | — |
case-04 | fail→fail | 6,165 | 9,316 | +51% | 1 | 1 | 0% | 477 | 1,009 | +112% | 0 | 0 | — |
case-05 | fail→pass | 11,611 | 14,884 | +28% | 1 | 1 | 0% | 1,230 | 1,161 | -6% | 0 | 0 | — |
case-06 | fail→fail | 35,522 | 23,508 | -34% | 1 | 1 | 0% | 2,109 | 1,800 | -15% | 0 | 0 | — |
case-07 | pass→pass | 12,413 | 12,038 | -3% | 1 | 1 | 0% | 1,786 | 2,388 | +34% | 0 | 0 | — |
case-08 | pass→pass | 9,411 | 11,641 | +24% | 1 | 1 | 0% | 1,341 | 1,981 | +48% | 0 | 0 | — |
case-09 | pass→pass | 16,212 | 21,270 | +31% | 1 | 1 | 0% | 2,625 | 2,211 | -16% | 0 | 0 | — |
case-10 | pass→pass | 8,525 | 4,061 | -52% | 1 | 1 | 0% | 1,397 | 928 | -34% | 0 | 0 | — |
case-11 | pass→pass | 31,358 | 101,778 | +225% | 1 | 1 | 0% | 2,029 | 1,586 | -22% | 0 | 0 | — |
case-12 | pass→pass | 9,985 | 15,276 | +53% | 1 | 1 | 0% | 1,870 | 2,198 | +18% | 0 | 0 | — |
case-13 | pass→pass | 9,716 | 70,273 | +623% | 1 | 1 | 0% | 1,499 | 1,048 | -30% | 0 | 0 | — |
case-14 | pass→pass | 20,561 | 22,036 | +7% | 1 | 1 | 0% | 2,880 | 3,479 | +21% | 0 | 0 | — |
case-16 | pass→pass | 16,382 | 22,520 | +37% | 1 | 1 | 0% | 2,803 | 3,908 | +39% | 0 | 0 | — |
case-17 | pass→pass | 18,187 | 23,318 | +28% | 1 | 1 | 0% | 2,355 | 2,002 | -15% | 0 | 0 | — |
case-18 | fail→pass | 30,381 | 25,224 | -17% | 1 | 1 | 0% | 1,463 | 669 | -54% | 0 | 0 | — |
case-19 | fail→pass | 8,199 | 4,792 | -42% | 1 | 1 | 0% | 1,698 | 986 | -42% | 0 | 0 | — |
case-21 | pass→pass | 9,655 | 10,647 | +10% | 1 | 1 | 0% | 1,729 | 1,665 | -4% | 0 | 0 | — |
case-22 | pass→pass | 16,075 | 16,520 | +3% | 1 | 1 | 0% | 2,004 | 2,542 | +27% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +18 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.