security-scan
Installation
SKILL.md
Security Scan
Run the security scanner against the codebase.
Step 1: Run the Scanner
Execute this Bash command:
node .claude/scripts/security-scan.mjs $ARGUMENTS
If $ARGUMENTS is empty, the script defaults to scanning src/.
The script runs three tiers of analysis:
- Custom regex scanner (always runs) — 10-phase check for code injection, XSS, SQL injection, hardcoded secrets, missing auth, unvalidated input, insecure cookies, info leakage, prototype pollution, open redirects
- npm audit (always available) — dependency vulnerability check
- Semgrep (runs if installed) — deep pattern matching with OWASP rules