security-scan

Installation
SKILL.md

Security Scan

Run the security scanner against the codebase.

Step 1: Run the Scanner

Execute this Bash command:

node .claude/scripts/security-scan.mjs $ARGUMENTS

If $ARGUMENTS is empty, the script defaults to scanning src/.

The script runs three tiers of analysis:

  1. Custom regex scanner (always runs) — 10-phase check for code injection, XSS, SQL injection, hardcoded secrets, missing auth, unvalidated input, insecure cookies, info leakage, prototype pollution, open redirects
  2. npm audit (always available) — dependency vulnerability check
  3. Semgrep (runs if installed) — deep pattern matching with OWASP rules
Installs
2
GitHub Stars
6
First Seen
May 22, 2026
security-scan — corvalis-llc/crow-stack