snyk-security-scan
Installation
SKILL.md
Snyk Security Scan Skill
Runs Snyk scanners against code you just wrote, dependencies you are about to add, container
images, IaC files and SBOMs, through the snyk MCP server bundled in this plugin. It does not
replace a code review; it finds known vulnerabilities, misconfigurations and risky packages and
tells you how to remediate them.
When to Use
- After generating or editing source:
snyk_code_scan(SAST) on the touched directory. - Before adding or upgrading a dependency:
snyk_package_health_check, thensnyk_breakability_checkfor the upgrade path. - On a project with a manifest/lockfile:
snyk_sca_scanfor known-vulnerable dependencies. - Before pushing a Dockerfile/image or Terraform/Kubernetes/CloudFormation:
snyk_container_scan,snyk_iac_scan. - When handed an SBOM (CycloneDX/SPDX):
snyk_sbom_scan. - NOT for: secrets detection, dynamic testing, or scanning code you must not upload (scans send code metadata to Snyk's cloud, see Pitfalls).