Home / fusengine / agents · plugins/security-expert/skills/security-scan/SKILL.md · GitHub

security-scan skillA

security-scan is agent-read markdown (skill) from fusengine/agents: Use when scanning for XSS, SQL injection, command injection, hardcoded secrets, or any OWASP Top 10 vulnerability across a codebase..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

<objective>
This skill orchestrates a full security scan across JavaScript/TypeScript, PHP, Python,
Swift/iOS, Go, and Rust: it detects the language from project markers, loads the matching
pattern set, runs the harness's automated scanner (OWASP patterns ported into
`@fusengine/harness`), maps findings to OWASP Top 10 categories, and generates a structured
report.

Pattern categories include XSS, SQL injection, command injection, unsafe code execution
(eval/exec), SSRF, weak cryptography, hardcoded secrets, insecure deserialization, and path
traversal/LFI/RFI, plus GraphQL-specific patterns (introspection, depth/complexity limiting,
batching, authorization) when a GraphQL endpoint is present.

After scanning, it delegates fixes to the sniper agent with file:line, vulnerability, and
fix — it does not apply fixes itself.
</objective>

# Security Scan Skill

## Overview

Orchestrates the full security scanning workflow across all supported languages.

## Supported Languages

| Language | Marker Files | Pattern Count |
|----------|-------------|---------------|
| JavaScript/TypeScript | package.json | 25+ |
| PHP | composer.json | 20+ |
…

Read the whole file at its exact version.

How to install

Latest version
mdr add fusengine/agents/security-scan@git:20260729.3b91eed
Exact content
mdr add fusengine/agents/security-scan@sha256:198d5e35f3b4724f

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_5qgnscnv52kudbkl.svg)](https://markdownregistry.com/a/art_5qgnscnv52kudbkl)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260729.3b91eed latest2026-07-29 3b91eed 2,936 BA view · diff
git:20260705.8c2f9bc2026-07-05 8c2f9bc 2,198 BA view · diff
git:20260404.8e1be802026-04-04 8e1be80 1,708 BA view · diff
git:20260221.ef8fc892026-02-21 ef8fc89 1,708 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (2936 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

fusengine/agents · 28 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_5qgnscnv52kudbkl
GET https://markdownregistry.com/api/v1/resolve?ref=fusengine/agents/security-scan
GET https://markdownregistry.com/api/v1/blob/198d5e35f3b4724fda971e65ed3e4787d6c3063177274606a13bec330b3ce4fc

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from fusengine/agents

agent-creator skill
fusengine/agents · plugins/ai-pilot/skills/agent-creator/SKILL.md · Use when creating expert agents. Generates agent.md with frontmatter, hooks, required sections, and skill references.
git:20260904.5f1d30f · audit A · 28 stars
apex-methodology skill
fusengine/agents · plugins/ai-pilot/skills/apex-methodology/SKILL.md · Use when starting ANY development task -- feature, bug fix, refactor, hotfix (triggers: implement, create, build, fix…
git:20260729.3b91eed · audit A · 28 stars
brainstorming skill
fusengine/agents · plugins/ai-pilot/skills/brainstorming/SKILL.md · Use when creating a feature/component or adding functionality. Fires BEFORE APEX Analyze to refine requirements via…
git:20260904.5f1d30f · audit A · 28 stars
challenge skill
fusengine/agents · plugins/ai-pilot/skills/challenge/SKILL.md · Use before a root-cause, done/verified claim, irreversible action, or 2nd-time fix reaches the owner (APEX or plain…
git:20260729.3b91eed · audit A · 28 stars
code-quality skill
fusengine/agents · plugins/ai-pilot/skills/code-quality/SKILL.md · Use when validating code quality after modifications -- SOLID compliance, DRY duplication, linter errors, architecture…
git:20260729.3b91eed · audit A · 28 stars
elicitation skill
fusengine/agents · plugins/ai-pilot/skills/elicitation/SKILL.md · Use when an expert agent self-reviews and self-corrects code after the Execute phase, before sniper validation…
git:20260729.3b91eed · audit A · 28 stars
exploration skill
fusengine/agents · plugins/ai-pilot/skills/exploration/SKILL.md · Use when exploring an unfamiliar codebase -- architecture analysis, pattern detection, dependency mapping, rapid…
git:20260729.3b91eed · audit A · 28 stars
fuse-browser-usage skill
fusengine/agents · plugins/ai-pilot/skills/fuse-browser-usage/SKILL.md · Use when about to call any mcp__fuse-browser__* tool. Routes fetch/crawl/SERP vs live browser session vs screenshot…
git:20260729.3b91eed · audit A · 28 stars
modularize skill
fusengine/agents · plugins/ai-pilot/skills/modularize/SKILL.md · Use when converting existing code to modular architecture (Laravel, Next.js, React). Triggers: "modularize", "convert…
git:20260729.3b91eed · audit A · 28 stars
pr-summary skill
fusengine/agents · plugins/ai-pilot/skills/pr-summary/SKILL.md · Summarize current pull request with diff, comments, and changed files. Use when reviewing PRs or before merging.
git:20260729.3b91eed · audit A · 28 stars
react-effects-audit skill
fusengine/agents · plugins/ai-pilot/skills/react-effects-audit/SKILL.md · Use when auditing React or Next.js components for unnecessary or unsafe useEffect usage -- detects 9 anti-patterns from…
git:20260729.3b91eed · audit A · 28 stars
research skill
fusengine/agents · plugins/ai-pilot/skills/research/SKILL.md · Use when researching documentation, best practices, or complex technical investigations -- Context7 + Exa + Sequential…
git:20260729.3b91eed · audit A · 28 stars

Every file in fusengine/agents

Other files named security-scan

security-scan skill
anbeime/skill · antinet-agentteams/skills/security-scan/SKILL.md · 对进入系统的文件或 URL 执行安全与合规扫描,输出 pass/reject 判定与扫描报告,作为所有文档处理的强制前置关卡。
git:20260902.d0fbb12 · audit A · 7,173 stars
security-scan skill
cowork-os/cowork-os · resources/plugin-packs/codex-security/skills/security-scan/SKILL.md · Use when the user asks for a repository-wide or scoped-path security scan.
git:20260919.7b075ca · audit A · 459 stars
security-scan skill
byerlikaya/claude-starter-kit · claude-starter/skills/security-scan/SKILL.md · Stack-agnostic security audit: map the attack surface, trace untrusted input to dangerous calls, surface dependency and…
git:20260917.265f088 · audit A · 24 stars
security-scan skill
byerlikaya/claude-starter-kit · plugin/skills/security-scan/SKILL.md · Stack-agnostic security audit: map the attack surface, trace untrusted input to dangerous calls, surface dependency and…
git:20260917.265f088 · audit A · 24 stars
security-scan skill
cooneycw/claude-power-pack · codex/skills/security-scan/SKILL.md · Run full security scan (native + external tools)
git:20260911.3a0a7c8 · audit A · 19 stars
security-scan skill
ray0907/security-scan · SKILL.md · Use when a user asks to scan a repository for dependency vulnerabilities, insecure code patterns, CVEs, or OWASP Top 10…
v1.4.0 · audit A · 15 stars
security-scan skill
jdanigo/hydraia · skills/security-scan/SKILL.md · Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection…
git:20260702.9dc0119 · audit A · 8 stars
security-scan skill
ahgraber/skills · skills/security-scan/SKILL.md · Use when the user asks for a security scan or review of a repository, a scoped path (package, folder, or submodule), or…
git:20260728.79ff2f8 · audit A · 5 stars

Browse by kind, by grade A, or by owner.