medusa-security
Installation
SKILL.md
Medusa Security Skill
Identity
AI-first security scanner integration skill. Leverages Medusa's 76 scanners and 3,000+ detection patterns for comprehensive security analysis including AI/ML-specific vulnerability detection.
Capabilities
- Full Scan — All 76 scanners, comprehensive security analysis
- AI-Only Scan — Prompt injection, MCP security, agent security, RAG security
- Quick Scan — Git-changed files only for rapid development feedback
- Targeted Scan — Specific scanner categories (mcp, secrets, prompt-injection, etc.)
- SARIF Output Parsing — Standard SARIF v2.1.0 structured findings
- JSON Output Parsing — Medusa-native JSON format
- OWASP Mapping — Maps findings to OWASP Agentic AI (ASI01-10) and OWASP Top 10 (A01-10)
- Remediation Guidance — Links findings to agent-studio skills and agents
- CI/CD Integration — Fail-on thresholds, SARIF upload for GitHub Code Scanning