vulnerability-scanner
sickn33/agentic-awesome-skills
Advanced vulnerability analysis: OWASP 2025, supply chain security, attack surface mapping, and risk prioritization.
What is vulnerability-scanner?
A reference skill for security-focused agents to apply expert vulnerability analysis principles. Covers OWASP Top 10:2025 (including new Supply Chain and Exceptional Conditions categories), threat modeling, attack surface mapping, and risk prioritization using CVSS/EPSS scores. Use this when analyzing code, dependencies, or systems for security weaknesses.
- Apply security expert mindset: assume breach, zero trust, defense in depth, least privilege, fail-secure
- Analyze against OWASP Top 10:2025 categories including Broken Access Control, Security Misconfiguration, Supply Chain Security, Cryptographic Failures, and Injection
- Map attack surface: identify entry points, data flows, trust boundaries, and assets
- Prioritize vulnerabilities using CVSS score, EPSS exploitability, asset value, and exposure
- Detect high-risk code patterns: string concatenation in queries, unsafe deserialization, path manipulation, disabled security checks
- Evaluate cloud security: IAM, storage exposure, network segmentation, secrets management
How to install vulnerability-scanner
npx skills add https://github.com/sickn33/agentic-awesome-skills --skill vulnerability-scannerHow to use vulnerability-scanner
- 1.Understand the target: identify technology stack, entry points, and data flows (Reconnaissance phase)
- 2.Identify potential issues: review configuration, analyze dependencies, search for risky code patterns (Discovery phase)
- 3.Validate and prioritize: eliminate false positives, score risk using CVSS/EPSS and asset value, map attack chains (Analysis phase)
- 4.Report findings: document what, where, why, impact, and remediation for each vulnerability (Reporting phase)
Use cases
- Security review of a web application before production deployment, checking for OWASP Top 10 violations and misconfigurations
- Dependency audit of a Node.js project to identify malicious or vulnerable packages in the supply chain
- Attack surface mapping for a microservices architecture to identify entry points and trust boundaries
- Prioritization of CVE findings across a portfolio using CVSS/EPSS scores and business asset value
- Code pattern analysis to detect injection vulnerabilities, unsafe deserialization, or hardcoded secrets
- Security engineers and penetration testers
- DevSecOps practitioners integrating security into CI/CD pipelines
- Application developers performing security code reviews
- Risk and compliance teams prioritizing remediation efforts
- Cloud architects evaluating infrastructure security posture
vulnerability-scanner FAQ
CVSS measures intrinsic vulnerability severity (base score 0–10). EPSS estimates the likelihood of exploitation in the wild (0–1 probability). Use CVSS for severity and EPSS for prioritization urgency.
Maintain a verified baseline of known false positives, validate findings with manual analysis, and focus on reproducible issues. Address root causes rather than symptoms to reduce noise.
A03 (Software Supply Chain Security) is new and elevated in priority, A10 (Exceptional Conditions) replaces older categories, and SSRF is merged into A01 (Broken Access Control). The focus shifts from symptoms to root causes.
Use the prioritization matrix: Risk = Likelihood × Impact. Check EPSS first (actively exploited?), then CVSS score, then asset value and exposure. Critical = high impact + high likelihood.
Fail-closed (secure) denies access on error; fail-open (insecure) allows access. Always design for fail-closed: if auth fails, deny; if parsing fails, reject; if timeout occurs, abort.
Full instructions (SKILL.md)
Source of truth, from sickn33/agentic-awesome-skills.
name: vulnerability-scanner description: "Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization." risk: critical source: community date_added: "2026-02-27"
Vulnerability Scanner
Think like an attacker, defend like an expert. 2025 threat landscape awareness.
🔧 Runtime Scripts
Execute for automated validation:
| Script | Purpose | Usage |
|---|---|---|
scripts/security_scan.py | Validate security principles applied | python scripts/security_scan.py <project_path> |
📋 Reference Files
| File | Purpose |
|---|---|
| checklists.md | OWASP Top 10, Auth, API, Data protection checklists |
1. Security Expert Mindset
Core Principles
| Principle | Application |
|---|---|
| Assume Breach | Design as if attacker already inside |
| Zero Trust | Never trust, always verify |
| Defense in Depth | Multiple layers, no single point |
| Least Privilege | Minimum required access only |
| Fail Secure | On error, deny access |
Threat Modeling Questions
Before scanning, ask:
- What are we protecting? (Assets)
- Who would attack? (Threat actors)
- How would they attack? (Attack vectors)
- What's the impact? (Business risk)
2. OWASP Top 10:2025
Risk Categories
| Rank | Category | Think About |
|---|---|---|
| A01 | Broken Access Control | Who can access what? IDOR, SSRF |
| A02 | Security Misconfiguration | Defaults, headers, exposed services |
| A03 | Software Supply Chain 🆕 | Dependencies, CI/CD, build integrity |
| A04 | Cryptographic Failures | Weak crypto, exposed secrets |
| A05 | Injection | User input → system commands |
| A06 | Insecure Design | Flawed architecture |
| A07 | Authentication Failures | Session, credential management |
| A08 | Integrity Failures | Unsigned updates, tampered data |
| A09 | Logging & Alerting | Blind spots, no monitoring |
| A10 | Exceptional Conditions 🆕 | Error handling, fail-open states |
2025 Key Changes
2021 → 2025 Shifts:
├── SSRF merged into A01 (Access Control)
├── A02 elevated (Cloud/Container configs)
├── A03 NEW: Supply Chain (major focus)
├── A10 NEW: Exceptional Conditions
└── Focus shift: Root causes > Symptoms
3. Supply Chain Security (A03)
Attack Surface
| Vector | Risk | Question to Ask |
|---|---|---|
| Dependencies | Malicious packages | Do we audit new deps? |
| Lock files | Integrity attacks | Are they committed? |
| Build pipeline | CI/CD compromise | Who can modify? |
| Registry | Typosquatting | Verified sources? |
Defense Principles
- Verify package integrity (checksums)
- Pin versions, audit updates
- Use private registries for critical deps
- Sign and verify artifacts
4. Attack Surface Mapping
What to Map
| Category | Elements |
|---|---|
| Entry Points | APIs, forms, file uploads |
| Data Flows | Input → Process → Output |
| Trust Boundaries | Where auth/authz checked |
| Assets | Secrets, PII, business data |
Prioritization Matrix
Risk = Likelihood × Impact
High Impact + High Likelihood → CRITICAL
High Impact + Low Likelihood → HIGH
Low Impact + High Likelihood → MEDIUM
Low Impact + Low Likelihood → LOW
5. Risk Prioritization
CVSS + Context
| Factor | Weight | Question |
|---|---|---|
| CVSS Score | Base severity | How severe is the vuln? |
| EPSS Score | Exploit likelihood | Is it being exploited? |
| Asset Value | Business context | What's at risk? |
| Exposure | Attack surface | Internet-facing? |
Prioritization Decision Tree
Is it actively exploited (EPSS >0.5)?
├── YES → CRITICAL: Immediate action
└── NO → Check CVSS
├── CVSS ≥9.0 → HIGH
├── CVSS 7.0-8.9 → Consider asset value
└── CVSS <7.0 → Schedule for later
6. Exceptional Conditions (A10 - New)
Fail-Open vs Fail-Closed
| Scenario | Fail-Open (BAD) | Fail-Closed (GOOD) |
|---|---|---|
| Auth error | Allow access | Deny access |
| Parsing fails | Accept input | Reject input |
| Timeout | Retry forever | Limit + abort |
What to Check
- Exception handlers that catch-all and ignore
- Missing error handling on security operations
- Race conditions in auth/authz
- Resource exhaustion scenarios
7. Scanning Methodology
Phase-Based Approach
1. RECONNAISSANCE
└── Understand the target
├── Technology stack
├── Entry points
└── Data flows
2. DISCOVERY
└── Identify potential issues
├── Configuration review
├── Dependency analysis
└── Code pattern search
3. ANALYSIS
└── Validate and prioritize
├── False positive elimination
├── Risk scoring
└── Attack chain mapping
4. REPORTING
└── Actionable findings
├── Clear reproduction steps
├── Business impact
└── Remediation guidance
8. Code Pattern Analysis
High-Risk Patterns
| Pattern | Risk | Look For |
|---|---|---|
| String concat in queries | Injection | "SELECT * FROM " + user_input |
| Dynamic code execution | RCE | eval(), exec(), Function() |
| Unsafe deserialization | RCE | pickle.loads(), unserialize() |
| Path manipulation | Traversal | User input in file paths |
| Disabled security | Various | verify=False, --insecure |
Secret Patterns
| Type | Indicators |
|---|---|
| API Keys | api_key, apikey, high entropy |
| Tokens | token, bearer, jwt |
| Credentials | password, secret, key |
| Cloud | AWS_, AZURE_, GCP_ prefixes |
9. Cloud Security Considerations
Shared Responsibility
| Layer | You Own | Provider Owns |
|---|---|---|
| Data | ✅ | ❌ |
| Application | ✅ | ❌ |
| OS/Runtime | Depends | Depends |
| Infrastructure | ❌ | ✅ |
Cloud-Specific Checks
- IAM: Least privilege applied?
- Storage: Public buckets?
- Network: Security groups tightened?
- Secrets: Using secrets manager?
10. Anti-Patterns
| ❌ Don't | ✅ Do |
|---|---|
| Scan without understanding | Map attack surface first |
| Alert on every CVE | Prioritize by exploitability + asset |
| Ignore false positives | Maintain verified baseline |
| Fix symptoms only | Address root causes |
| Scan once before deploy | Continuous scanning |
| Trust third-party deps blindly | Verify integrity, audit code |
11. Reporting Principles
Finding Structure
Each finding should answer:
- What? - Clear vulnerability description
- Where? - Exact location (file, line, endpoint)
- Why? - Root cause explanation
- Impact? - Business consequence
- How to fix? - Specific remediation
Severity Classification
| Severity | Criteria |
|---|---|
| Critical | RCE, auth bypass, mass data exposure |
| High | Data exposure, privilege escalation |
| Medium | Limited scope, requires conditions |
| Low | Informational, best practice |
Remember: Vulnerability scanning finds issues. Expert thinking prioritizes what matters. Always ask: "What would an attacker do with this?"
When to Use
This skill is applicable to execute the workflow or actions described in the overview.
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
Related skills
More from sickn33/agentic-awesome-skills and the wider catalog.

web-performance-optimization
Optimize website performance: Core Web Vitals, bundle size, caching, and runtime speed.

workflow-automation
Durable execution infrastructure for reliable AI agent workflows with automatic recovery from failures.

youtube-summarizer
Extract and summarize YouTube video transcripts with detailed analysis frameworks.

3d-web-experience
Build interactive 3D web experiences with Three.js, React Three Fiber, and Spline.

ab-test-setup
Structured guide for setting up A/B tests with mandatory gates for hypothesis, metrics, and execution readiness.

address-github-comments
Use when you need to address review or issue comments on an open GitHub Pull Request using the gh CLI.