deep-security-scan skillA
deep-security-scan is agent-read markdown (skill) from cowork-os/cowork-os: Use when the user asks for a deep, exhaustive, multi-pass, or variance-reducing repository-wide Codex Security scan. Run repeated independent repository-wide discovery passes with worker-specific threat models, semantically merge candidates, synthesize one canonical validation threat model, then run validation, attack-path analysis, and final reporting once. Repository-wide targets only; do not use for PRs, commits, branch diffs, working-tree diffs, or scoped paths..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Deep Security Scan ## Overview Deep Security Scan is a higher-recall repository-wide wrapper around Codex Security. It preserves the ordinary Codex Security phase model and final report shape, but repeats the most variance-sensitive phase, finding discovery, before centralized judgment. The wrapper owns orchestration only: 1. resolve the full-repository scan target once using Codex Security repository-wide semantics 2. run repeated independent discovery workers, each of which generates its own repository-level threat model before `$codex-security:finding-discovery` 3. semantically merge discovery outputs into one canonical candidate inventory 4. synthesize one canonical validation threat model from the worker threat models after discovery reaches a terminal state 5. run `$codex-security:validation`, `$codex-security:attack-path-analysis`, and final report assembly once Do not replace Codex Security's established scan rules with custom shortcuts. ## Required Capabilities Before starting, confirm that the Codex Security plugin skills needed by this workflow are available: - `$codex-security:security-scan` - `$codex-security:threat-model` …
Read the whole file at its exact version.
How to install
mdr add cowork-os/cowork-os/deep-security-scan@git:20260606.a4dececmdr add cowork-os/cowork-os/deep-security-scan@sha256:cd55b36361e44796Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_4ywsf2xrwnsh5im3)
1 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (34533 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
cowork-os/cowork-os · 459 stars · license MIT · pushed 2026-09-23 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_4ywsf2xrwnsh5im3 GET https://markdownregistry.com/api/v1/resolve?ref=cowork-os/cowork-os/deep-security-scan GET https://markdownregistry.com/api/v1/blob/cd55b36361e44796343737be3b54b8099e4236b91267e44f17c6e2da0be3fcc2
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.