PluginBench
Skill
Review
Audit score 70

vulnerability-scanner

sickn33/agentic-awesome-skills

Advanced vulnerability analysis: OWASP 2025, supply chain security, attack surface mapping, and risk prioritization.

What is vulnerability-scanner?

A reference skill for security-focused agents to apply expert vulnerability analysis principles. Covers OWASP Top 10:2025 (including new Supply Chain and Exceptional Conditions categories), threat modeling, attack surface mapping, and risk prioritization using CVSS/EPSS scores. Use this when analyzing code, dependencies, or systems for security weaknesses.

  • Apply security expert mindset: assume breach, zero trust, defense in depth, least privilege, fail-secure
  • Analyze against OWASP Top 10:2025 categories including Broken Access Control, Security Misconfiguration, Supply Chain Security, Cryptographic Failures, and Injection
  • Map attack surface: identify entry points, data flows, trust boundaries, and assets
  • Prioritize vulnerabilities using CVSS score, EPSS exploitability, asset value, and exposure
  • Detect high-risk code patterns: string concatenation in queries, unsafe deserialization, path manipulation, disabled security checks
  • Evaluate cloud security: IAM, storage exposure, network segmentation, secrets management

How to install vulnerability-scanner

npx skills add https://github.com/sickn33/agentic-awesome-skills --skill vulnerability-scanner
Claude Code
Cursor
Windsurf
Cline

How to use vulnerability-scanner

  1. 1.Understand the target: identify technology stack, entry points, and data flows (Reconnaissance phase)
  2. 2.Identify potential issues: review configuration, analyze dependencies, search for risky code patterns (Discovery phase)
  3. 3.Validate and prioritize: eliminate false positives, score risk using CVSS/EPSS and asset value, map attack chains (Analysis phase)
  4. 4.Report findings: document what, where, why, impact, and remediation for each vulnerability (Reporting phase)

Use cases

Good for
  • Security review of a web application before production deployment, checking for OWASP Top 10 violations and misconfigurations
  • Dependency audit of a Node.js project to identify malicious or vulnerable packages in the supply chain
  • Attack surface mapping for a microservices architecture to identify entry points and trust boundaries
  • Prioritization of CVE findings across a portfolio using CVSS/EPSS scores and business asset value
  • Code pattern analysis to detect injection vulnerabilities, unsafe deserialization, or hardcoded secrets
Who it's for
  • Security engineers and penetration testers
  • DevSecOps practitioners integrating security into CI/CD pipelines
  • Application developers performing security code reviews
  • Risk and compliance teams prioritizing remediation efforts
  • Cloud architects evaluating infrastructure security posture

vulnerability-scanner FAQ

What's the difference between CVSS and EPSS scoring?

CVSS measures intrinsic vulnerability severity (base score 0–10). EPSS estimates the likelihood of exploitation in the wild (0–1 probability). Use CVSS for severity and EPSS for prioritization urgency.

How do I handle false positives in scanning results?

Maintain a verified baseline of known false positives, validate findings with manual analysis, and focus on reproducible issues. Address root causes rather than symptoms to reduce noise.

What's new in OWASP Top 10:2025?

A03 (Software Supply Chain Security) is new and elevated in priority, A10 (Exceptional Conditions) replaces older categories, and SSRF is merged into A01 (Broken Access Control). The focus shifts from symptoms to root causes.

How should I prioritize vulnerabilities across multiple systems?

Use the prioritization matrix: Risk = Likelihood × Impact. Check EPSS first (actively exploited?), then CVSS score, then asset value and exposure. Critical = high impact + high likelihood.

What's the difference between fail-open and fail-closed?

Fail-closed (secure) denies access on error; fail-open (insecure) allows access. Always design for fail-closed: if auth fails, deny; if parsing fails, reject; if timeout occurs, abort.

Full instructions (SKILL.md)

Source of truth, from sickn33/agentic-awesome-skills.


name: vulnerability-scanner description: "Advanced vulnerability analysis principles. OWASP 2025, Supply Chain Security, attack surface mapping, risk prioritization." risk: critical source: community date_added: "2026-02-27"

Vulnerability Scanner

Think like an attacker, defend like an expert. 2025 threat landscape awareness.

🔧 Runtime Scripts

Execute for automated validation:

ScriptPurposeUsage
scripts/security_scan.pyValidate security principles appliedpython scripts/security_scan.py <project_path>

📋 Reference Files

FilePurpose
checklists.mdOWASP Top 10, Auth, API, Data protection checklists

1. Security Expert Mindset

Core Principles

PrincipleApplication
Assume BreachDesign as if attacker already inside
Zero TrustNever trust, always verify
Defense in DepthMultiple layers, no single point
Least PrivilegeMinimum required access only
Fail SecureOn error, deny access

Threat Modeling Questions

Before scanning, ask:

  1. What are we protecting? (Assets)
  2. Who would attack? (Threat actors)
  3. How would they attack? (Attack vectors)
  4. What's the impact? (Business risk)

2. OWASP Top 10:2025

Risk Categories

RankCategoryThink About
A01Broken Access ControlWho can access what? IDOR, SSRF
A02Security MisconfigurationDefaults, headers, exposed services
A03Software Supply Chain 🆕Dependencies, CI/CD, build integrity
A04Cryptographic FailuresWeak crypto, exposed secrets
A05InjectionUser input → system commands
A06Insecure DesignFlawed architecture
A07Authentication FailuresSession, credential management
A08Integrity FailuresUnsigned updates, tampered data
A09Logging & AlertingBlind spots, no monitoring
A10Exceptional Conditions 🆕Error handling, fail-open states

2025 Key Changes

2021 → 2025 Shifts:
├── SSRF merged into A01 (Access Control)
├── A02 elevated (Cloud/Container configs)
├── A03 NEW: Supply Chain (major focus)
├── A10 NEW: Exceptional Conditions
└── Focus shift: Root causes > Symptoms

3. Supply Chain Security (A03)

Attack Surface

VectorRiskQuestion to Ask
DependenciesMalicious packagesDo we audit new deps?
Lock filesIntegrity attacksAre they committed?
Build pipelineCI/CD compromiseWho can modify?
RegistryTyposquattingVerified sources?

Defense Principles

  • Verify package integrity (checksums)
  • Pin versions, audit updates
  • Use private registries for critical deps
  • Sign and verify artifacts

4. Attack Surface Mapping

What to Map

CategoryElements
Entry PointsAPIs, forms, file uploads
Data FlowsInput → Process → Output
Trust BoundariesWhere auth/authz checked
AssetsSecrets, PII, business data

Prioritization Matrix

Risk = Likelihood × Impact

High Impact + High Likelihood → CRITICAL
High Impact + Low Likelihood  → HIGH
Low Impact + High Likelihood  → MEDIUM
Low Impact + Low Likelihood   → LOW

5. Risk Prioritization

CVSS + Context

FactorWeightQuestion
CVSS ScoreBase severityHow severe is the vuln?
EPSS ScoreExploit likelihoodIs it being exploited?
Asset ValueBusiness contextWhat's at risk?
ExposureAttack surfaceInternet-facing?

Prioritization Decision Tree

Is it actively exploited (EPSS >0.5)?
├── YES → CRITICAL: Immediate action
└── NO → Check CVSS
         ├── CVSS ≥9.0 → HIGH
         ├── CVSS 7.0-8.9 → Consider asset value
         └── CVSS <7.0 → Schedule for later

6. Exceptional Conditions (A10 - New)

Fail-Open vs Fail-Closed

ScenarioFail-Open (BAD)Fail-Closed (GOOD)
Auth errorAllow accessDeny access
Parsing failsAccept inputReject input
TimeoutRetry foreverLimit + abort

What to Check

  • Exception handlers that catch-all and ignore
  • Missing error handling on security operations
  • Race conditions in auth/authz
  • Resource exhaustion scenarios

7. Scanning Methodology

Phase-Based Approach

1. RECONNAISSANCE
   └── Understand the target
       ├── Technology stack
       ├── Entry points
       └── Data flows

2. DISCOVERY
   └── Identify potential issues
       ├── Configuration review
       ├── Dependency analysis
       └── Code pattern search

3. ANALYSIS
   └── Validate and prioritize
       ├── False positive elimination
       ├── Risk scoring
       └── Attack chain mapping

4. REPORTING
   └── Actionable findings
       ├── Clear reproduction steps
       ├── Business impact
       └── Remediation guidance

8. Code Pattern Analysis

High-Risk Patterns

PatternRiskLook For
String concat in queriesInjection"SELECT * FROM " + user_input
Dynamic code executionRCEeval(), exec(), Function()
Unsafe deserializationRCEpickle.loads(), unserialize()
Path manipulationTraversalUser input in file paths
Disabled securityVariousverify=False, --insecure

Secret Patterns

TypeIndicators
API Keysapi_key, apikey, high entropy
Tokenstoken, bearer, jwt
Credentialspassword, secret, key
CloudAWS_, AZURE_, GCP_ prefixes

9. Cloud Security Considerations

Shared Responsibility

LayerYou OwnProvider Owns
Data✅❌
Application✅❌
OS/RuntimeDependsDepends
Infrastructure❌✅

Cloud-Specific Checks

  • IAM: Least privilege applied?
  • Storage: Public buckets?
  • Network: Security groups tightened?
  • Secrets: Using secrets manager?

10. Anti-Patterns

❌ Don't✅ Do
Scan without understandingMap attack surface first
Alert on every CVEPrioritize by exploitability + asset
Ignore false positivesMaintain verified baseline
Fix symptoms onlyAddress root causes
Scan once before deployContinuous scanning
Trust third-party deps blindlyVerify integrity, audit code

11. Reporting Principles

Finding Structure

Each finding should answer:

  1. What? - Clear vulnerability description
  2. Where? - Exact location (file, line, endpoint)
  3. Why? - Root cause explanation
  4. Impact? - Business consequence
  5. How to fix? - Specific remediation

Severity Classification

SeverityCriteria
CriticalRCE, auth bypass, mass data exposure
HighData exposure, privilege escalation
MediumLimited scope, requires conditions
LowInformational, best practice

Remember: Vulnerability scanning finds issues. Expert thinking prioritizes what matters. Always ask: "What would an attacker do with this?"

When to Use

This skill is applicable to execute the workflow or actions described in the overview.

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.