本文へ移動
cccskills
無料GitHub で公開

security-scan

Scan the repository for hardcoded secrets, exposed API keys, insecure network configurations, and vulnerable dependencies. Use when the user asks for a security audit, secret detection, credential scan, vulnerability check, or wants to find leaked tokens in the codebase.

インストール方法を見る

含まれるファイル(5)

  • SKILL.md2.0 KB
  • scripts/main_scan.sh671 B
  • scripts/scan_deps.sh290 B
  • scripts/scan_network.py2.2 KB
  • scripts/scan_secrets.py2.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Security Scan

Detect hardcoded secrets, insecure network patterns, and vulnerable dependencies in the repository using integrated scanning scripts.

Workflow

1. Determine scope

Identify whether to scan the entire repo or specific subdirectories based on the user request.

2. Run the scan

bash .agents/skills/security/scripts/main_scan.sh

The scan checks three categories:

  • Secret detection: Hardcoded API keys, tokens, passwords, and credentials (e.g., patterns like AKIA, sk-, ghp_, Bearer)
  • Network check: Hardcoded IP addresses and insecure protocol usage (http:// where https:// is expected)
  • Dependency audit: npm audit for vulnerable packages

If the main script is unavailable, run checks manually:

# Secret patterns
grep -rn "AKIA\|sk-\|ghp_\|password\s*=\|api_key\s*=" --include="*.ts" --include="*.js" --include="*.env" .

# Insecure protocols
grep -rn "http://" --include="*.ts" --include="*.js" . | grep -v localhost

# Dependency vulnerabilities
npm audit --json

3. Report findings

Organize results by severity:

SeverityExamples
HighExposed API keys, hardcoded passwords, leaked tokens
MediumInsecure protocol usage, hardcoded IPs in production code
LowOutdated dependencies with low-severity CVEs

Provide actionable remediation for each finding (e.g., "Rotate this key and move to environment variable", "Upgrade package X to version Y").

4. Safety

CRITICAL: Never display a full secret in the output. Mask all sensitive values (e.g., AKIA...XXXX, sk-...abcd). Warn the user about the risk of committing secrets to version control.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Skill for adding or updating educational algorithm guides, ensuring consistent patterns and simple explanations suitable for an 8-year-old.

日本語の概要は準備中です。原文の説明を表示しています。

rkmahale17/rulcode.com152026年10月6日 更新

Install and configure PostHog analytics SDK in React Native applications, including event tracking, feature flags, user identification, and error tracking. Use when the user needs to add PostHog analytics, session recording, or feature flags to a React Native app.

日本語の概要は準備中です。原文の説明を表示しています。

rkmahale17/rulcode.com152026年10月6日 更新

PostHog integration for React Router v6 applications

日本語の概要は準備中です。原文の説明を表示しています。

rkmahale17/rulcode.com152026年10月6日 更新

Develop and extend the RulCode technical interview preparation platform built with React, Vite, TypeScript, and Supabase. Use when adding new algorithm problems, building visualization components, implementing DSA topic pages, updating the problem editor, or modifying the interview preparation UI.

日本語の概要は準備中です。原文の説明を表示しています。

rkmahale17/rulcode.com152026年10月6日 更新

Skill for adding or updating system design guides tailored for college students and beginners, using simple analogies and no simulations.

日本語の概要は準備中です。原文の説明を表示しています。

rkmahale17/rulcode.com152026年10月6日 更新

React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.

日本語の概要は準備中です。原文の説明を表示しています。

rkmahale17/rulcode.com152026年10月6日 更新

rkmahale17 のスキルをすべて見る

このスキルの問題を報告する