security-scanning
SkillSecurityThis skill lets your AI run a security audit on your code, so weaknesses are found before they cause problems. It checks code against 102 rules across 5 scanning categories, and can optionally run simulated attacks to see how your code holds up under real threats.
Available today. Use it from your connected AI after setup.
No other account needed.
After adding it, ask your AI to run a security audit on your code. If you want a deeper check, ask it to include the simulated attack testing as well.
Then ask your AI: use the security-scanning skill
What your AI can do with it
- Run security audits on your code
- Check code against 102 security rules
- Scan code across 5 security categories
- Simulate attacks with optional red-team testing
What this skill tells your AI
The instructions your AI receives, as published by a5c-ai/babysitter in library/methodologies/everything-claude-code/skills/security-scanning/SKILL.md and read by ahel’s review.
- AWS access keys (AKIA pattern)
- GitHub tokens (ghp_, gho_, ghs_, ghr_)
- Generic API keys and bearer tokens
- Database connection strings with credentials
- Private keys (RSA, EC, SSH)
- JWT secrets and signing keys
- OAuth client secrets
- Slack tokens and webhooks
- Cloud provider credentials (GCP, Azure)
2. Permission Auditing
- File system read/write scope
- Network calls and protocols
- Process execution (child_process)
- File permissions (777, world-writable)
- CORS and CSP headers
- Docker privilege escalation
3. Hook Injection Analysis
- Git hooks for command injection
- npm lifecycle scripts (preinstall, postinstall)
- Claude Code hooks for unsafe patterns
- eval()/Function()/dynamic code execution
- Unvalidated user input in shell commands
4. MCP Risk Profiling
- Tool permission inventory
- Data exposure risk mapping
- Transport security (stdio vs SSE vs HTTP)
- Prompt injection via tool descriptions
- Rate limiting verification
5. Agent Config Review
- Model settings integrity
- Prompt injection resistance
- Tool allowlist scoping
- Output validation and sanitization
- Information leakage in error messages
Optional: Red Team Simulation
- Attack simulation against found vulnerabilities
- Exploitability rating: trivial, moderate, difficult, theoretical
- Blue-team defense recommendations
When to Use
- Pre-deployment security review
- New dependency introduction
- Hook or plugin configuration changes
- Agent or MCP server setup
Agents Used
security-reviewer(primary consumer)
Signals
- GitHub stars
- 2k
- Forks
- 106
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
security-scanning- Source
- github.com/a5c-ai/babysitter