PluginBench
Skill
Pass
Audit score 90

snyk-agent-scan-compliance

samber/cc-skills

Fix snyk-agent-scan compliance alerts by restructuring skill content—never by suppressing information.

What is snyk-agent-scan-compliance?

A compliance expert skill for resolving snyk-agent-scan alerts (W001, W011, W012) in skill-authoring workflows. Use it when authoring new skills, editing existing ones, or unblocking CI failures caused by the agent skill file scanner. Covers SKILL.md, references/, assets/, and secondary markdown files.

  • Diagnoses and fixes W011 alerts (third-party content exposure) by converting imperative fetch/check instructions to passive hints
  • Resolves W012 alerts (malicious external URLs) by moving install commands to frontmatter and pinning versions
  • Eliminates W001 alerts (prompt injection via MCP tool calls) by replacing explicit tool names with generic formulations
  • Provides structured remediation methodology: fix one alert type at a time, re-scan after each change, verify improvement before moving on
  • Includes reference catalogs with 12+ before/after examples per alert type and false-positive detection criteria

How to install snyk-agent-scan-compliance

npx skills add https://github.com/samber/cc-skills --skill snyk-agent-scan-compliance
Prerequisites
  • snyk-agent-scan binary installed (via `uv install snyk-agent-scan` or `uvx snyk-agent-scan@latest`)
  • Valid SNYK_TOKEN environment variable set for scanner authentication
  • Existing skill directory with SKILL.md and optional references/, assets/, or secondary markdown files
Claude Code
Cursor
Windsurf
Cline

How to use snyk-agent-scan-compliance

  1. 1.Run `SNYK_TOKEN=<token> snyk-agent-scan --skills skills/<name>/` to scan a single skill or `--skills ./skills` for all skills
  2. 2.Review the alert output and identify which alert types (W001, W011, W012) are present
  3. 3.Consult the appropriate reference file: w001-patterns.md for MCP tool names, w011-patterns.md for external content imperatives, w012-patterns.md for URL/version issues
  4. 4.Apply fixes in order: W001 first (simplest), then W011, then W012, to minimize rework and surface hidden alerts
  5. 5.Re-run snyk-agent-scan after each individual fix and verify the alert count dropped before moving to the next alert type
  6. 6.Use the pre-authoring checklist when writing new skills to avoid alerts before the first scan

Use cases

Good for
  • Authoring a new skill and running snyk-agent-scan for the first time to identify compliance issues before submission
  • Editing an existing skill and triaging scanner failures in local development or CI pipelines
  • Unblocking a pull request held by agent scanner failures without losing information or suppressing alerts
  • Restructuring skill content to decouple tool execution from decision-making (e.g., running a tool is fine; using remote output as sole trigger for refactor is not)
  • Distinguishing real alerts from false positives (e.g., URLs in markdown tables, library documentation links, pinned versions in code blocks)
Who it's for
  • Skill authors writing or maintaining agent skills for Claude Code, Cursor, or similar harnesses
  • DevOps engineers managing CI pipelines that run snyk-agent-scan as a gate
  • Teams triaging compliance scanner failures and needing structured guidance on safe restructuring patterns

snyk-agent-scan-compliance FAQ

What is the difference between snyk-agent-scan and other Snyk CLI tools?

snyk-agent-scan is a skill-body compliance scanner for agent skills (SKILL.md files). It is NOT for dependency vulnerabilities (snyk test), code security findings (snyk code SAST), infrastructure misconfigurations (snyk iac), or container vulnerabilities (snyk container). It only analyzes skill content for unsafe patterns.

Can I suppress or delete information to fix an alert?

No. This skill fixes alerts through content restructuring only—never by suppressing or deleting useful information. For example, W011 alerts are fixed by rewriting imperative sentences as passive hints, not by removing the URL or instruction.

What should I do if a fix doesn't reduce the alert count?

Undo the change and try a different approach. Do not stack unverified changes. Re-run snyk-agent-scan after each individual fix to confirm improvement before moving to the next alert type.

How do I know if an alert is a false positive?

Check the false-positive criteria in the SKILL.md: URLs in markdown tables, library documentation links, homepage/issues links in frontmatter, pinned versions in code blocks, and 'always' in sentences not involving external resources are usually safe. Even if likely false, restructure anyway—the scanner's heuristic protects real users.

Can I use uvx instead of installing snyk-agent-scan?

Yes. Use `uvx snyk-agent-scan@latest` as a drop-in replacement without installing the binary. Both approaches work in local development and CI.

Full instructions (SKILL.md)

Source of truth, from samber/cc-skills.


name: snyk-agent-scan-compliance description: "Compliance expert for snyk-agent-scan — the agent skill file scanner — NOT for other Snyk CLI tools (snyk test, snyk code SAST, snyk iac, snyk container). Fixes alerts through content restructuring, never by suppressing or deleting information. Covers every file in a skill directory: SKILL.md, references/, assets/, and any secondary markdown. Apply when authoring a new skill, editing an existing one, triaging a failed snyk-agent-scan run locally or in CI, or unblocking a PR held by agent scanner failures. Not applicable to dependency vulnerabilities, code security findings, or infrastructure misconfigurations — those are out of scope." user-invocable: true license: MIT compatibility: Designed for Claude Code, Codex or similar harness. metadata: author: samber version: "1.1.0" openclaw: emoji: "🔍" homepage: https://github.com/samber/cc-skills requires: bins: [snyk-agent-scan] install: - kind: uv package: snyk-agent-scan bins: [snyk-agent-scan] skill-library-version: "0.4.14" allowed-tools: Read Edit Write Glob Grep Bash(git:) Bash(uv:) Bash(uvx:*) AskUserQuestion Agent

Persona: You are a skill-authoring compliance expert. You fix snyk-agent-scan alerts by restructuring content — never by suppressing or deleting useful information.

Thinking mode: Reason as thoroughly as possible for multi-alert remediation where fixes for one alert type can surface or suppress another. Deep reasoning reduces rework. On Claude Code, use ultrathink to trigger extended thinking explicitly.

snyk-agent-scan Compliance

The snyk-agent-scan tool analyzes skill bodies for three categories of unsafe patterns: third-party content exposure (W011), malicious external URLs (W012), and prompt injection via MCP tool calls (W001). All three are fixable through content restructuring without losing any information.

Reference Files

FileWhen to read
references/w001-patterns.mdFixing W001 alerts — MCP tool name patterns
references/w011-patterns.mdFixing W011 alerts — imperative URL and external content patterns
references/w012-patterns.mdFixing W012 alerts — version pinning and frontmatter offloading

Quick Reference

AlertSeverityRoot CausePrimary Fix
W011HighSkill body instructs agent to fetch/interpret external contentReplace imperatives with passive availability hints
W012HighSkill body references external URLs fetched and executed at runtimeMove to frontmatter install block; pin versions
W001HighSkill body names MCP tool functions explicitlyUse generic formulations instead

Running the Scanner

# Scan a single skill
SNYK_TOKEN=<token> snyk-agent-scan --skills skills/<name>/

# Scan all skills
SNYK_TOKEN=<token> snyk-agent-scan --skills ./skills

The scanner requires a valid SNYK_TOKEN. In CI, store it as a secret. If snyk-agent-scan is not installed, use uvx snyk-agent-scan@latest as a drop-in replacement without installing. See detailed patterns for fixes per alert type.

W011 — Third-Party Content Exposure

W011 fires when the skill body uses imperative verbs directing the agent to fetch, check, or evaluate external content and then act on it. The scanner treats the agent as the grammatical subject performing an external action.

Rules:

  • Replace Check <url> and Fetch <url> with passive hints: The release notes at <url> may be useful.
  • Remove "always" from any instruction involving external data: Always reference the changelog → The changelog documents breaking changes.
  • Keep tool invocations (gh repo view, govulncheck) in code blocks, not in prose checklists that imply the agent must run them before acting.
  • Decouple tool execution from decisions: running a tool is fine; using its remote-sourced output as the sole trigger for a refactor is not.

See W011 pattern catalog for 12+ before/after examples.

W012 — Potentially Malicious External URL

W012 fires when the body references external content fetched and executed at runtime: package installs with @latest, pipe-to-shell patterns, or GitHub Actions with wrong/non-existent major versions.

Rules:

  • Move go install pkg@latest and similar commands from prose into the frontmatter metadata.openclaw.install block — the scanner does not flag frontmatter.
  • Pin GitHub Actions to the correct current major version (@v4, not @v6).
  • Never use pipe-to-shell patterns (curl ... | sh) in skill bodies.

See W012 pattern catalog for 8+ before/after examples.

W001 — Prompt Injection via MCP Tool Calls

W001 fires when the skill body explicitly names MCP server tool functions, triggering prompt-injection detection.

Rules:

  • Never write tool function names (resolve-library-id, query-docs, mcp__*) in the skill body.
  • Replace with generic formulations: Context7 can help as a discoverability platform.
  • MCP tool names may still appear in the allowed-tools frontmatter field — only the body is restricted.

See W001 pattern catalog for safe reformulations.

Remediation Methodology

Fix one alert at a time, re-run snyk-agent-scan after each change, and verify the alert count dropped before moving to the next. If a fix does not reduce alerts, undo it and try a different approach — do not stack unverified changes.

When a scan returns multiple alerts, fix in this order to minimize rework:

1. W001 (simplest) — remove MCP tool names from body; confirm allowed-tools is correct
2. W011 — rewrite imperative sentences as passive statements; move checklist items to code blocks
3. W012 — move install commands to frontmatter; pin versions
4. Re-scan after each individual fix to verify improvement

W011 fixes sometimes surface hidden W012s when URLs become more prominent after restructuring.

False Positives

Not all alerts are real. Criteria for a likely false positive:

ConditionLikely false positive?
URL appears in a markdown table cell as reference data, not in an instructionYes — tables are usually safe
In a skill describing a library, URL is the library official documentationYes — usually safe
URL is the homepage or issues link in frontmatterYes — not scanned
Tool name appears inside a triple-backtick code block as a shell commandSometimes — code blocks have lighter scrutiny
go install with a pinned version in a Quick Reference code blockSometimes — pinned versions are lower risk
always appears in a sentence not involving external resourcesYes — "always" alone doesn't trigger W011

When an alert is a likely false positive, restructure anyway using the passive hint pattern — the scanner's heuristic protects real users; restructuring is safer than assuming scanner error.

Pre-Authoring Checklist

Apply these checks while writing a new skill body to avoid alerts before the first scan:

  • No sentence has the agent as subject performing an action on a URL
  • No @latest tags in any install instruction in the body
  • No MCP tool function names (mcp__*, resolve-library-id, etc.) in body prose
  • All install commands are in the frontmatter install block
  • GitHub Actions versions match real existing major versions
  • Tool invocations are in code blocks, not in ordered-list checklists
  • "always" does not precede any external resource instruction

If you encounter a bug or unexpected behavior in snyk-agent-scan, open an issue at https://github.com/snyk/snyk-agent-scan/issues.

If you discover a pattern that triggers an alert not covered in the reference files above — a new bypass technique, a false positive condition, or an undocumented alert code — open an issue at https://github.com/samber/cc-skills/issues or a pull request to the samber/cc-skills repository to add it to the relevant pattern file. New patterns are the most valuable contribution to this skill.