Pattern categories include XSS, SQL injection, command injection, unsafe code execution
(eval/exec), SSRF, weak cryptography, hardcoded secrets, insecure deserialization, and path
traversal/LFI/RFI, plus GraphQL-specific patterns (introspection, depth/complexity limiting,
batching, authorization) when a GraphQL endpoint is present.
After scanning, it delegates fixes to the sniper agent with file:line, vulnerability, and
fix — it does not apply fixes itself.
Security Scan Skill
Overview
Orchestrates the full security scanning workflow across all supported languages.
Supported Languages
| Language |
Marker Files |
Pattern Count |
| JavaScript/TypeScript |
package.json |
25+ |
| PHP |
composer.json |
20+ |
| Python |
requirements.txt, pyproject.toml |
18+ |
| Swift/iOS |
Package.swift, *.xcodeproj |
15+ |
| Go |
go.mod |
12+ |
| Rust |
Cargo.toml |
10+ |
Workflow
- Detect language from project markers
- Load patterns from
references/scan-patterns.md
- Run
bun ${CLAUDE_PLUGIN_ROOT}/../node_modules/@fusengine/harness/dist/cli/bin.mjs scan <dir> for automated scanning (OWASP patterns ported into the harness)
- Map findings to OWASP categories via
references/owasp-top10.md
- Generate report using
references/templates/scan-report.md
Pattern Categories
- XSS (Cross-Site Scripting)
- SQL Injection
- Command Injection
- Code Execution (eval, exec)
- SSRF (Server-Side Request Forgery)
- Weak Cryptography
- Hardcoded Secrets
- Insecure Deserialization
- Path Traversal / LFI / RFI
Integration
After scanning, delegate fixes to sniper:
Agent(subagent_type="fuse-ai-pilot:sniper", prompt="Security fixes: [FILE:LINE] [VULN] [FIX]")
References
- OWASP Top 10 Mapping
- Scan Patterns by Language
- Report Template
- GraphQL Security Patterns — Load when the target exposes a GraphQL endpoint (introspection, depth/complexity limiting, batching, authorization checks).
- Scan Patterns - Python, Swift/iOS, Go, Rust — Load when scanning Python, Swift/iOS, Go, or Rust source code (patterns not covered in
scan-patterns.md).
1---2name: security-scan3description: Use when scanning for XSS, SQL injection, command injection, hardcoded secrets, or any OWASP Top 10 vulnerability across a codebase.4---56<objective>7This skill orchestrates a full security scan across JavaScript/TypeScript, PHP, Python,8Swift/iOS, Go, and Rust: it detects the language from project markers, loads the matching9pattern set, runs the harness's automated scanner (OWASP patterns ported into10`@fusengine/harness`), maps findings to OWASP Top 10 categories, and generates a structured11report.1213Pattern categories include XSS, SQL injection, command injection, unsafe code execution14(eval/exec), SSRF, weak cryptography, hardcoded secrets, insecure deserialization, and path15traversal/LFI/RFI, plus GraphQL-specific patterns (introspection, depth/complexity limiting,16batching, authorization) when a GraphQL endpoint is present.1718After scanning, it delegates fixes to the sniper agent with file:line, vulnerability, and19fix — it does not apply fixes itself.20</objective>2122# Security Scan Skill2324## Overview2526Orchestrates the full security scanning workflow across all supported languages.2728## Supported Languages2930| Language | Marker Files | Pattern Count |31|----------|-------------|---------------|32| JavaScript/TypeScript | package.json | 25+ |33| PHP | composer.json | 20+ |34| Python | requirements.txt, pyproject.toml | 18+ |35| Swift/iOS | Package.swift, *.xcodeproj | 15+ |36| Go | go.mod | 12+ |37| Rust | Cargo.toml | 10+ |3839## Workflow40411. **Detect** language from project markers422. **Load** patterns from `references/scan-patterns.md`433. **Run** `bun ${CLAUDE_PLUGIN_ROOT}/../node_modules/@fusengine/harness/dist/cli/bin.mjs scan <dir>` for automated scanning (OWASP patterns ported into the harness)444. **Map** findings to OWASP categories via `references/owasp-top10.md`455. **Generate** report using `references/templates/scan-report.md`4647## Pattern Categories4849- XSS (Cross-Site Scripting)50- SQL Injection51- Command Injection52- Code Execution (eval, exec)53- SSRF (Server-Side Request Forgery)54- Weak Cryptography55- Hardcoded Secrets56- Insecure Deserialization57- Path Traversal / LFI / RFI5859## Integration6061After scanning, delegate fixes to sniper:62```63Agent(subagent_type="fuse-ai-pilot:sniper", prompt="Security fixes: [FILE:LINE] [VULN] [FIX]")64```6566## References6768- [OWASP Top 10 Mapping](references/owasp-top10.md)69- [Scan Patterns by Language](references/scan-patterns.md)70- [Report Template](references/templates/scan-report.md)71- [GraphQL Security Patterns](references/graphql-security.md) — Load when the target exposes a GraphQL endpoint (introspection, depth/complexity limiting, batching, authorization checks).72- [Scan Patterns - Python, Swift/iOS, Go, Rust](references/scan-patterns-extra.md) — Load when scanning Python, Swift/iOS, Go, or Rust source code (patterns not covered in `scan-patterns.md`).