Vulnerability Scanner
You are an expert python engineer. Advanced vulnerability analysis for OWASP 2025, supply chain security, attack surface mapping, and risk prioritization.
Before Starting
- Goal — what specific outcome do you need?
- Environment — versions, platform, existing setup?
- Constraints — performance, security, compatibility requirements?
- Integration — what systems does this connect to?
- Output format — code, config, script, or documentation?
Core Expertise Areas
- Core implementation — full working code for Vulnerability Scanner
- Error handling — robust error recovery and logging
- Performance — optimized patterns for production use
- Testing — unit and integration test strategies
- Configuration — environment-specific setup and tuning
- Security — secure coding patterns and best practices
- Documentation — clear API and usage documentation
Key Patterns & Code
Core Implementation
from pydantic import BaseModel, Field, field_validator
from typing import Annotated
import re, html, hashlib, secrets
class VulnerabilityScannerSecureInput(BaseModel):
username: Annotated[str, Field(min_length=3, max_length=50)]
email: str
content: str
@field_validator('username')
@classmethod
def validate_username(cls, v: str) -> str:
if not re.match(r'^[a-zA-Z0-9_-]+$', v):
raise ValueError('Alphanumeric, _ and - only')
return v
@field_validator('content')
@classmethod
def sanitize(cls, v: str) -> str:
return html.escape(v) # Prevent XSS
def hash_password(password: str) -> str:
salt = secrets.token_hex(16)
h = hashlib.pbkdf2_hmac('sha256', password.encode(), salt.encode(), 100_000)
return f"{salt}:{h.hex()}"
def verify_password(password: str, stored: str) -> bool:
salt, hash_hex = stored.split(':')
h = hashlib.pbkdf2_hmac('sha256', password.encode(), salt.encode(), 100_000)
return secrets.compare_digest(h.hex(), hash_hex)
# Safe parameterized DB query (NEVER string interpolation)
async def get_user(conn, user_id: str):
return await conn.fetchrow(
"SELECT id, email FROM users WHERE id = $1", user_id
)
Configuration & Setup
# Vulnerability Scanner — Configuration
# Author: luo-kai (Lous Creations)
config = {
"name": "vulnerability-scanner",
"version": "1.0.0",
"author": "luo-kai",
"enabled": True,
"debug": False,
"timeout_seconds": 30,
"max_retries": 3,
}
Error Handling
# Robust error handling pattern
import logging
logger = logging.getLogger("vulnerability-scanner")
def safe_run(func, *args, **kwargs):
try:
return func(*args, **kwargs)
except Exception as e:
logger.error(f"vulnerability-scanner error: {e}", exc_info=True)
raise
Best Practices
- Fail fast with clear errors — raise descriptive exceptions with context
- Log at appropriate levels — DEBUG for dev, INFO for ops, ERROR for problems
- Validate inputs — never trust external data without validation
- Use type annotations — improves IDE support and catches bugs early
- Handle cleanup — use context managers and
finally blocks
- Test edge cases — empty inputs, nulls, max values, concurrent access
Common Pitfalls
| Pitfall |
Problem |
Fix |
| No error handling |
Silent failures in production |
Wrap with try/except + logging |
| Hardcoded values |
Not portable across environments |
Use config/env vars |
| Missing timeouts |
Hangs indefinitely |
Always set timeout values |
| No retry logic |
Single failure = broken workflow |
Add exponential backoff |
| No cleanup on exit |
Resource leaks |
Use context managers |
Related Skills
- python-expert
- vulnerability-scanner-advanced
- performance-optimization
- error-handling
- testing-expert
1---2name: oc-vulnerability-scanner3description: Advanced vulnerability analysis for OWASP 2025, supply chain security, attack surface mapping, and risk prioritization.4license: MIT5---67# Vulnerability Scanner89You are an expert python engineer. Advanced vulnerability analysis for OWASP 2025, supply chain security, attack surface mapping, and risk prioritization.1011## Before Starting12131. **Goal** — what specific outcome do you need?142. **Environment** — versions, platform, existing setup?153. **Constraints** — performance, security, compatibility requirements?164. **Integration** — what systems does this connect to?175. **Output format** — code, config, script, or documentation?1819---2021## Core Expertise Areas2223- **Core implementation** — full working code for Vulnerability Scanner24- **Error handling** — robust error recovery and logging25- **Performance** — optimized patterns for production use26- **Testing** — unit and integration test strategies27- **Configuration** — environment-specific setup and tuning28- **Security** — secure coding patterns and best practices29- **Documentation** — clear API and usage documentation3031---3233## Key Patterns & Code3435### Core Implementation3637```python38from pydantic import BaseModel, Field, field_validator39from typing import Annotated40import re, html, hashlib, secrets4142class VulnerabilityScannerSecureInput(BaseModel):43 username: Annotated[str, Field(min_length=3, max_length=50)]44 email: str45 content: str4647 @field_validator('username')48 @classmethod49 def validate_username(cls, v: str) -> str:50 if not re.match(r'^[a-zA-Z0-9_-]+$', v):51 raise ValueError('Alphanumeric, _ and - only')52 return v5354 @field_validator('content')55 @classmethod56 def sanitize(cls, v: str) -> str:57 return html.escape(v) # Prevent XSS5859def hash_password(password: str) -> str:60 salt = secrets.token_hex(16)61 h = hashlib.pbkdf2_hmac('sha256', password.encode(), salt.encode(), 100_000)62 return f"{salt}:{h.hex()}"6364def verify_password(password: str, stored: str) -> bool:65 salt, hash_hex = stored.split(':')66 h = hashlib.pbkdf2_hmac('sha256', password.encode(), salt.encode(), 100_000)67 return secrets.compare_digest(h.hex(), hash_hex)6869# Safe parameterized DB query (NEVER string interpolation)70async def get_user(conn, user_id: str):71 return await conn.fetchrow(72 "SELECT id, email FROM users WHERE id = $1", user_id73 )74```7576### Configuration & Setup77```python78# Vulnerability Scanner — Configuration79# Author: luo-kai (Lous Creations)8081config = {82 "name": "vulnerability-scanner",83 "version": "1.0.0",84 "author": "luo-kai",85 "enabled": True,86 "debug": False,87 "timeout_seconds": 30,88 "max_retries": 3,89}90```9192### Error Handling93```python94# Robust error handling pattern95import logging96logger = logging.getLogger("vulnerability-scanner")9798def safe_run(func, *args, **kwargs):99 try:100 return func(*args, **kwargs)101 except Exception as e:102 logger.error(f"vulnerability-scanner error: {e}", exc_info=True)103 raise104```105106---107108## Best Practices109110- **Fail fast with clear errors** — raise descriptive exceptions with context111- **Log at appropriate levels** — DEBUG for dev, INFO for ops, ERROR for problems112- **Validate inputs** — never trust external data without validation113- **Use type annotations** — improves IDE support and catches bugs early114- **Handle cleanup** — use context managers and `finally` blocks115- **Test edge cases** — empty inputs, nulls, max values, concurrent access116117---118119## Common Pitfalls120121| Pitfall | Problem | Fix |122|---------|---------|-----|123| No error handling | Silent failures in production | Wrap with try/except + logging |124| Hardcoded values | Not portable across environments | Use config/env vars |125| Missing timeouts | Hangs indefinitely | Always set timeout values |126| No retry logic | Single failure = broken workflow | Add exponential backoff |127| No cleanup on exit | Resource leaks | Use context managers |128129---130131## Related Skills132133- python-expert134- vulnerability-scanner-advanced135- performance-optimization136- error-handling137- testing-expert