Vuln Scan

Static source-code vulnerability scan. Reads a target directory (and THREAT_MODEL.md if present), spawns parallel review subagents per focus area, and writes VULN-FINDINGS.json + .md for /triage to consume. Read-only — no building, running, or network. For execution-verified crashes, use vuln-pipeline instead. Use when asked to "scan for vulns", "review this code for security issues", "find bugs in <dir>", or as the step between /threat-model and /triage.

anthropics ca91990 11.8 KB Updated

File contents

anthropics/defending-code-reference-harness/tree/main/.claude/skills/vuln-scan commit ca91990951

Frequently asked questions

npx skillmds@latest add anthropics/vuln-scan