security-scanner
Provides comprehensive security scanning for codebases, detecting vulnerabilities, secrets, and compliance violations across various environments.
Install this skill
Security score
The security-scanner skill was audited on Feb 28, 2026 and we found 42 security issues across 4 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
System command execution
| 552 | "code": "os.system(f'tar -czf backup.tar.gz {directory}')", |
Python os.system command execution
| 552 | "code": "os.system(f'tar -czf backup.tar.gz {directory}')", |
Python subprocess execution
| 555 | "remediation": "Use subprocess with argument list: subprocess.run(['tar', '-czf', 'backup.tar.gz', directory])", |
Webhook reference - potential data exfiltration
| 397 | "slack_webhook": null, |
Access to hidden dotfiles in home directory
| 153 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 158 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 164 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 170 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 180 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 186 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 192 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 202 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 207 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 214 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 225 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 230 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 236 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 247 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 252 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 258 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 268 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 274 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 281 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 291 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 297 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 304 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 416 | python ~/.claude/skills/security-scanner/scripts/main.py |
Access to hidden dotfiles in home directory
| 427 | python ~/.claude/skills/security-scanner/scripts/main.py |
Access to hidden dotfiles in home directory
| 433 | python ~/.claude/skills/dependency-guardian/scripts/main.py --operation check |
Access to hidden dotfiles in home directory
| 434 | python ~/.claude/skills/security-scanner/scripts/main.py --operation scan-dependencies |
Access to hidden dotfiles in home directory
| 442 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 452 | python ~/.claude/skills/security-scanner/scripts/main.py --operation scan-container |
Access to hidden dotfiles in home directory
| 453 | python ~/.claude/skills/container-validator/scripts/main.py --operation validate |
Access to hidden dotfiles in home directory
| 463 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 509 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 568 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 642 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 704 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
Access to hidden dotfiles in home directory
| 761 | python ~/.claude/skills/security-scanner/scripts/main.py \ |
External URL reference
| 536 | "references": ["https://owasp.org/www-community/attacks/SQL_Injection"] |
External URL reference
| 546 | "references": ["https://owasp.org/www-community/attacks/xss/"] |
External URL reference
| 556 | "references": ["https://owasp.org/www-community/attacks/Command_Injection"] |