vulnerability-scanning
SKILL.md
Vulnerability Scanning
Purpose
Automatically scan code and infrastructure for known vulnerabilities and security weaknesses.
When to Use
- Every build (CI/CD)
- Before releases
- Regular security audits
- After dependency updates
Process
- Configure scanning tools
- Run SAST (static analysis)
- Run DAST (dynamic analysis)
- Review findings
- Prioritize and remediate
StudyAbroad-Specific Considerations
- npm audit for dependencies
- Snyk for continuous monitoring
- OWASP ZAP for DAST
- Trivy for container scanning
Examples
# CI/CD Security Scan Stage
security-scan:
script:
- npm audit --production
- npx snyk test --severity-threshold=high
- docker run --rm -v $(pwd):/app aquasec/trivy fs /app
Weekly Installs
1
Repository
vihang-hub/inte…rameworkGitHub Stars
1
First Seen
4 days ago
Security Audits
Installed on
amp1
cline1
openclaw1
opencode1
cursor1
kimi-cli1