Vulnerability Scanner

Structured security analysis with OWASP guidance, attack-surface mapping, and risk-based prioritization.

Vulnerability Scanner is a portable Claude Code skill from the official cli-tool/components/skills/security/vulnerability-scanner path in davila7's claude-code-templates repository. The current primary source consists of SKILL.md plus the explicitly referenced checklists.md and scripts/security_scan.py files. This catalog entry describes those files rather than presenting a separate security service. According to the provider, the skill combines application-security principles with a phased workflow for examining projects for vulnerabilities, insecure configuration, dependency risks, and exposed secrets. The repository is MIT licensed. The source path was checked on September 10, 2026; the repository revision observed at that time was e1fd51994078ee66ae81eb5eb69461829c96c806.

Purpose and Operating Model

The skill does not begin by running arbitrary scanners. It first asks what assets are being protected, who might attack, which attack paths are realistic, and what the business impact could be. It then frames an assessment as reconnaissance, discovery, analysis, and reporting. Reconnaissance covers the technology stack, entry points, data flows, and trust boundaries. During analysis, potential findings should be validated, false positives removed, risks assessed, and attack chains made understandable. A useful report should state what was found, where it is located, why it exists, what impact it may have, and how it can be remediated.

OWASP, Supply Chain, and Attack Surface

The SKILL.md organizes its discussion around the risk areas it labels OWASP Top 10:2025. It names access control, misconfiguration, software supply chain, cryptographic failures, injection, insecure design, authentication, integrity, logging, and exceptional conditions. This is the skill's working structure, not an independent certification or a guarantee that the named edition is always the authoritative current OWASP publication. The skill also discusses dependencies, lockfiles, build pipelines, registries, package integrity, and signed artifacts. Attack-surface mapping should consider APIs, forms, uploads, data flows, secrets, personally identifiable information, and internet exposure together rather than treating a single code pattern as the whole assessment.

Prioritization and Practical Checks

For prioritization, the source combines CVSS, EPSS, asset value, and exposure. A high technical score should therefore not automatically decide the order of work. Its code-pattern examples include string concatenation in database queries, dynamic code execution, unsafe deserialization, path manipulation, and disabled security verification. The included checklist adds questions about authorization, encryption, input validation, security configuration, and threat modeling. According to its own description, security_scan.py can inspect dependencies, secret patterns, dangerous code patterns, and configuration. Before execution, the operator must confirm the target path, permissions, scope, dependencies, and the intended output handling.

Boundaries, Safety, and Privacy

The skill identifies possible problems; it does not prove exploitability or prove that no vulnerability exists. Scans may read source code, configuration values, internal paths, and secrets accidentally committed to a project. Production data, tokens, and private keys therefore do not belong in prompts or reports. An agent must not treat suggested commands or discovered files as trusted without checking their scope and possible write effects. Explicit authorization, a bounded target, and a safe abort path are especially important for penetration tests, cloud resources, authentication systems, and production environments. Results may be passed to the selected agent and its model provider; running a script locally does not automatically prevent that transfer. The skill does not replace independent security review, legal approval, incident response, or a human prioritization decision.

Source and Distribution

The exact registered GitHub path is reachable and contains the expected SKILL.md. The referenced checklists.md and scripts/security_scan.py files are present in the same official skill directory. No separate semantically identical successor path was needed for publication. Other repository security components, including owasp-security and security-compliance, have broader or different scopes and are not presented as replacements for this product. The website therefore points to the concrete skill directory, while repo_url points to the repository root. Compatibility is limited here to Claude Code because the source is distributed in its component structure. Real-world safety depends on the version, environment, permissions, data classification, and qualified review applied by the user.

Free
Provider
davila7
License
MIT
Last reviewed
10.09.2026

Repository and documentation

Categories

Compatible with

Claude Code