security-scanner

Installation
SKILL.md

Security Scanner — OWASP Top 10:2025

Performs a systematic security audit of any codebase against all 10 OWASP 2025 categories. Produces a structured markdown report with severity ratings, code locations, and actionable remediation guidance.

Originally written by Leon van Zyl for agentic-coding-starter-kit, used here with his permission. Unchanged except for this note and the pairing section below.

Pairing with start-an-app

start-an-app checks that what it built works. It never checks that it is safe — and it is routinely used to build apps that hold a small business's customer records. This skill is the other half.

Run it after the app is real, not while it is being scaffolded. A good moment is once sign-in works and there is data in the database, since most of what A01 and A07 look for does not exist before then. start-an-app offers it at hand-off; taking it up is the user's call.

One expectation to set when the report lands in front of a non-technical owner: a finding is not a breach. Most of what a fresh scaffold produces is Low and Info — missing headers, console-only logging. Lead with the count that matters (Critical and High), say plainly if that count is zero, and don't hand someone a risk score without telling them what it means.

Execution Flow

Follow these four steps in order. Do not skip any step.

Step 1: Detect Project Context

Installs
1
GitHub Stars
6
First Seen
Jul 28, 2026