Security Scan Skill
SkillFiles & storageRun a comprehensive security scan on a codebase using available security scanners (Semgrep, Bandit, Trivy, osv-scanner). Returns structured findings with severity, file location, and OWASP mapping.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Security Scan Skill skill
What this skill tells your AI
The instructions your AI receives, as published by jiayaoqijia/eth2030 in .claude/skills/scan/SKILL.md and read by ahel’s review.
Overview
Run a multi-engine security scan on a target directory or repo and produce a structured vulnerability report.
Inputs
- Target: directory path, GitHub repo URL, or "." for current directory
- Scope: "full" (all engines) or specific engine name
Engines
- Semgrep - SAST rules for Python/JS/TS/Go
- Trivy - Dependency + container + IaC scanning
- osv-scanner - Open-source vulnerability database lookup
- Bandit - Python-specific security linting (if Python code present)
Workflow
- Detect project languages and package managers
- Run applicable scanners in parallel
- Deduplicate findings across engines
- Classify by severity: CRITICAL, HIGH, MEDIUM, LOW
- Map findings to OWASP Top 10 / OWASP LLM Top 10
- Output structured JSON report + human-readable summary
Output Format
{
"scan_id": "uuid",
"target": "path/or/url",
"timestamp": "ISO8601",
"summary": {
"critical": 0,
"high": 2,
"medium": 5,
"low": 12,
"total": 19
},
"findings": [
{
"id": "finding-uuid",
"engine": "semgrep",
"rule": "typescript.express.security.audit.xss",
"severity": "HIGH",
"file": "src/api/handler.ts",
"line": 42,
"title": "Cross-Site Scripting (XSS)",
"description": "User input rendered without sanitization",
"owasp": "A03:2021 Injection",
"fix_available": true,
"estimated_loc": 3
}
]
}
Guardrails
- Read-only: do not modify any scanned files
- Do not execute untrusted code from scanned repos
- Filter out low-confidence results by default
- Report scanner errors separately from findings
Signals
- GitHub stars
- 97
- Forks
- 10
- Last commit
- May 2026
Advanced
- Catalog kind
- skill
- Gateway key
scan-jiayaoqijia- Source
- github.com/jiayaoqijia/eth2030