security-scan

Installation
SKILL.md

Security scan — orchestrate scanners, triage the noise, emit a gate

A machine-first vulnerability sweep. Point automated scanners at a codebase, collect SARIF/JSON, then do the work that has actual value: dedupe cross-tool overlap, rank by exploitability, and emit one gate artifact CI can act on. The finding comes from a tool run, not a hunch — if you are reasoning about a design or hand-writing a fix, that is secure-coding, not this skill.

Your job is orchestration + triage: every finding traces to a scanner run with a ruleId and a source location, so the output is reproducible. Not eyeballing code, not authoring patches.

Read-only by default. Scan, triage, report. Apply fixes (version bumps, rotation, .gitignore edits) only when the user asks — a security sweep that silently mutates the tree destroys the evidence and the trust.

Installs
3
GitHub Stars
116
First Seen
Aug 6, 2026
security-scan — ericrisco/rsc-harness