Vulnerability Scanner
Structured security analysis with OWASP guidance, attack-surface mapping, and risk-based prioritization.
- Skill Road
- Vulnerability Scanner
Vulnerability Scanner is a portable Claude Code skill from the official cli-tool/components/skills/security/vulnerability-scanner path in davila7's claude-code-templates repository. The current primary source consists of SKILL.md plus the explicitly referenced checklists.md and scripts/security_scan.py files. This catalog entry describes those files rather than presenting a separate security service. According to the provider, the skill combines application-security principles with a phased workflow for examining projects for vulnerabilities, insecure configuration, dependency risks, and exposed secrets. The repository is MIT licensed. The source path was checked on September 10, 2026; the repository revision observed at that time was e1fd51994078ee66ae81eb5eb69461829c96c806.
Purpose and Operating Model
The skill does not begin by running arbitrary scanners. It first asks what assets are being protected, who might attack, which attack paths are realistic, and what the business impact could be. It then frames an assessment as reconnaissance, discovery, analysis, and reporting. Reconnaissance covers the technology stack, entry points, data flows, and trust boundaries. During analysis, potential findings should be validated, false positives removed, risks assessed, and attack chains made understandable. A useful report should state what was found, where it is located, why it exists, what impact it may have, and how it can be remediated.
OWASP, Supply Chain, and Attack Surface
The SKILL.md organizes its discussion around the risk areas it labels OWASP Top 10:2025. It names access control, misconfiguration, software supply chain, cryptographic failures, injection, insecure design, authentication, integrity, logging, and exceptional conditions. This is the skill's working structure, not an independent certification or a guarantee that the named edition is always the authoritative current OWASP publication. The skill also discusses dependencies, lockfiles, build pipelines, registries, package integrity, and signed artifacts. Attack-surface mapping should consider APIs, forms, uploads, data flows, secrets, personally identifiable information, and internet exposure together rather than treating a single code pattern as the whole assessment.
Prioritization and Practical Checks
For prioritization, the source combines CVSS, EPSS, asset value, and exposure. A high technical score should therefore not automatically decide the order of work. Its code-pattern examples include string concatenation in database queries, dynamic code execution, unsafe deserialization, path manipulation, and disabled security verification. The included checklist adds questions about authorization, encryption, input validation, security configuration, and threat modeling. According to its own description, security_scan.py can inspect dependencies, secret patterns, dangerous code patterns, and configuration. Before execution, the operator must confirm the target path, permissions, scope, dependencies, and the intended output handling.
Boundaries, Safety, and Privacy
The skill identifies possible problems; it does not prove exploitability or prove that no vulnerability exists. Scans may read source code, configuration values, internal paths, and secrets accidentally committed to a project. Production data, tokens, and private keys therefore do not belong in prompts or reports. An agent must not treat suggested commands or discovered files as trusted without checking their scope and possible write effects. Explicit authorization, a bounded target, and a safe abort path are especially important for penetration tests, cloud resources, authentication systems, and production environments. Results may be passed to the selected agent and its model provider; running a script locally does not automatically prevent that transfer. The skill does not replace independent security review, legal approval, incident response, or a human prioritization decision.
Source and Distribution
The exact registered GitHub path is reachable and contains the expected SKILL.md. The referenced checklists.md and scripts/security_scan.py files are present in the same official skill directory. No separate semantically identical successor path was needed for publication. Other repository security components, including owasp-security and security-compliance, have broader or different scopes and are not presented as replacements for this product. The website therefore points to the concrete skill directory, while repo_url points to the repository root. Compatibility is limited here to Claude Code because the source is distributed in its component structure. Real-world safety depends on the version, environment, permissions, data classification, and qualified review applied by the user.
- Provider
- davila7
- License
- MIT
- Last reviewed
- 10.09.2026
Repository and documentation
Categories
Compatible with
Related guides
Guides and background related to this entry.
Set up the Fakechat plugin for Claude Code
Install the Fakechat plugin, start Claude Code with the channels flag, and test messages and files through a local browser interface.
30.09.2026
Setting up Laravel Boost
Install Laravel Boost in a Laravel application and connect it to Claude Code, Cursor, or Codex.
29.09.2026
Set up the Azure DevOps MCP Server
Start Set up the Azure DevOps MCP Server with verified links, minimal permissions, and a safe first test.
25.09.2026
Installing a Claude Code plugin
Installing a plugin from the official Anthropic marketplace – using the Code Review plugin as an example.
24.09.2026