snyk-security-scan

Installation
SKILL.md

Snyk Security Scan Skill

Runs Snyk scanners against code you just wrote, dependencies you are about to add, container images, IaC files and SBOMs, through the snyk MCP server bundled in this plugin. It does not replace a code review; it finds known vulnerabilities, misconfigurations and risky packages and tells you how to remediate them.

When to Use

  • After generating or editing source: snyk_code_scan (SAST) on the touched directory.
  • Before adding or upgrading a dependency: snyk_package_health_check, then snyk_breakability_check for the upgrade path.
  • On a project with a manifest/lockfile: snyk_sca_scan for known-vulnerable dependencies.
  • Before pushing a Dockerfile/image or Terraform/Kubernetes/CloudFormation: snyk_container_scan, snyk_iac_scan.
  • When handed an SBOM (CycloneDX/SPDX): snyk_sbom_scan.
  • NOT for: secrets detection, dynamic testing, or scanning code you must not upload (scans send code metadata to Snyk's cloud, see Pitfalls).
Installs
2
GitHub Stars
9
First Seen
Sep 21, 2026