Security Scanner

🌐Community
by eddiebe147 · vlatest · Repository

Identifies vulnerabilities in websites and applications using automated scans and reports potential risks.

Install on your platform

We auto-selected Claude Code based on this skill’s supported platforms.

1

Run in terminal (recommended)

terminal
claude mcp add security-scanner npx -- -y @trustedskills/security-scanner
2

Or manually add to ~/.claude/settings.json

~/.claude/settings.json
{
  "mcpServers": {
    "security-scanner": {
      "command": "npx",
      "args": [
        "-y",
        "@trustedskills/security-scanner"
      ]
    }
  }
}

Requires Claude Code (claude CLI). Run claude --version to verify your install.

About This Skill

Security Scanner

What it does

This skill allows AI agents to automatically scan codebases, configurations, and dependencies for known security vulnerabilities. It leverages integrated tools like semgrep, trivy, and bandit to identify risks without requiring manual setup of complex scanning pipelines.

When to use it

  • Before deploying a new application to production to catch critical flaws early.
  • During code reviews when an agent needs to validate that recent changes haven't introduced vulnerabilities.
  • When auditing third-party libraries or dependencies for outdated or compromised packages.
  • As part of a continuous integration pipeline to ensure security compliance on every commit.

Key capabilities

  • Scans source code using semgrep for static analysis rules.
  • Checks container images and infrastructure configurations with trivy.
  • Identifies common Python security issues via bandit.
  • Generates actionable reports detailing found vulnerabilities and suggested fixes.

Example prompts

  • "Run a full security scan on my current project repository and summarize any high-severity findings."
  • "Check if my Dockerfile contains insecure practices or outdated base images using trivy."
  • "Analyze this Python module for potential buffer overflows or hardcoded secrets using bandit."

Tips & gotchas

Ensure your AI agent has read access to the relevant repositories and container registries before initiating scans. Some scanners may produce false positives; always review flagged items in context rather than applying fixes blindly.

Tags

🛡️

TrustedSkills Verification

Unlike other registries that point to live repositories, TrustedSkills pins every skill to a verified commit hash. This protects you from malicious updates — what you install today is exactly what was reviewed and verified.

Security Audits

Gen Agent Trust HubPass
SocketPass
SnykPass

Details

Version
vlatest
License
Author
eddiebe147
Installs
47

🌐 Community

Passed automated security scans.