security-scan
Installation
SKILL.md
Pattern categories include XSS, SQL injection, command injection, unsafe code execution (eval/exec), SSRF, weak cryptography, hardcoded secrets, insecure deserialization, and path traversal/LFI/RFI, plus GraphQL-specific patterns (introspection, depth/complexity limiting, batching, authorization) when a GraphQL endpoint is present.
After scanning, it delegates fixes to the sniper agent with file:line, vulnerability, and fix — it does not apply fixes itself.