Vulnerability Scan

Run an offensive security audit (OWASP-based) using Semgrep and produce a read-only vulnerability report. Use before committing code to detect Broken Access Control, Injection (SQL/NoSQL/OS/Template), Frontend Security issues (XSS/CSP/HSTS), SSRF, and hardcoded secrets or PII exposure. Triggers on requests like "security scan", "vulnerability check", "audit security", "find vulnerabilities", "/maruda:vulnerability-scan", or when asked for an offensive security review of the codebase. Does NOT modify any code — read-only inspection only.

northraystudio Updated

File contents

northraystudio/maruda/tree/main/skills/vulnerability-scan commit 56eabea3bd

Frequently asked questions

npx skillmds@latest add northraystudio/vulnerability-scan