security-scanner
Security Scanner — OWASP Top 10:2025
Performs a systematic security audit of any codebase against all 10 OWASP 2025 categories. Produces a structured markdown report with severity ratings, code locations, and actionable remediation guidance.
Originally written by Leon van Zyl for agentic-coding-starter-kit, used here with his permission. Unchanged except for this note and the pairing section below.
Pairing with start-an-app
start-an-app checks that what it built works. It never checks that it is safe — and it is routinely used to build apps that hold a small business's customer records. This skill is the other half.
Run it after the app is real, not while it is being scaffolded. A good moment is once sign-in works and there is data in the database, since most of what A01 and A07 look for does not exist before then. start-an-app offers it at hand-off; taking it up is the user's call.
One expectation to set when the report lands in front of a non-technical owner: a finding is not a breach. Most of what a fresh scaffold produces is Low and Info — missing headers, console-only logging. Lead with the count that matters (Critical and High), say plainly if that count is zero, and don't hand someone a risk score without telling them what it means.
Execution Flow
Follow these four steps in order. Do not skip any step.