Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Run full security scans on the codebase using Ruflo security tools. Use when reviewing PRs for security regressions, auditing auth/input-handling code, before production deploys, or when the user asks for a security check at quick/standard/deep depth.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | -37% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -56% | 0% |
| case-06 | ✗→✓ | ▲ Improved | -67% | 0% |
| case-07 | ✗→✓ | ▲ Improved | -65% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -41% | 0% |
Run a security scan at the specified depth.
Via CLI:
bashnpx @claude-flow/cli@latest security scan --depth DEPTH --output json npx @claude-flow/cli@latest security cve --list npx @claude-flow/cli@latest security threats --model stride --export md
| Depth | Checks | |-------|--------| | quick | Dependencies, known CVEs | | standard | + Input validation, path traversal, secrets | | deep | + Threat modeling, injection vectors, auth flows |
Store findings via MCP: mcp__plugin_ruflo-core_ruflo__memory_store({ key: "scan-findings", value: "SUMMARY", namespace: "security-findings" })
Train patterns: mcp__plugin_ruflo-core_ruflo__hooks_post-task({ taskId: "security-scan", success: true, storeResults: true })
Other measured skills in the registry, with their headline benchmark lift.