Overview
- Skill Key
- brandonwise/vulnerability-scanner
- Author
- brandonwise
- Source Repo
- openclaw/skills
- Version
- -
- Source Path
- skills/brandonwise/vulnerability-scanner
- Latest Commit SHA
- d6e0b7d43ef9fade4387990a5cf7be82f6b401e4
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 Vulnerability Scanner 技能。 若已安装,则直接安装 Vulnerability Scanner 技能。
# Vulnerability Scanner Advanced vulnerability analysis for OWASP 2025, supply chain security, attack surface mapping, and risk prioritization. ## Description USE WHEN: - Auditing code for security vulnerabilities - Reviewing dependencies for supply chain risks - Scanning for hardcoded secrets or credentials - Identifying dangerous code patterns (injection, XSS, deserialization) - Preparing for security audits or penetration tests - Prioritizing vulnerability remediation by risk DON'T USE WHEN: - Need runtime dynamic analysis (use actual pentest tools) - Scanning compiled binaries (this is source-code focused) - Need compliance-specific audits (PCI-DSS, HIPAA have dedicated tools) ## Scripts | Script | Purpose | Usage | |--------|---------|-------| | `scripts/security_scan.py` | Full security scan | `python scripts/security_scan.py <path> [--scan-type all\|deps\|secrets\|patterns\|config]` | ### Quick Start ```bash # Full scan python scripts/security_scan.py /path/to/project # Just check for secrets python scripts/security_scan.py /path/to/project --scan-type secrets # Summary output python scripts/security_scan.py /path/to/project --output summary ``` ## Reference Files | File | Purpose | |------|---------| | [checklists.md](checklists.md) | OWASP Top 10, Auth, API, Data protection checklists | --- ## 1. Security Expert Mindset ### Core Principles | Principle | Application | |-----------|-------------| | **Assume Breach** | Design as if attacker already inside | | **Zero Trust** | Never trust, always verify | | **Defense in Depth** | Multiple layers, no single point | | **Least Privilege** | Minimum required access only | | **Fail Secure** | On error, deny access | ### Threat Modeling Questions Before scanning, ask: 1. What are we protecting? (Assets) 2. Who would attack? (Threat actors) 3. How would they attack? (Attack vectors) 4. What's the impact? (Business risk) --- ## 2. OWASP Top 10:2025 ### Risk Categories | Rank | Category | Think A...
capt-marbles
Task Router
capncoconut
Register, communicate, and earn on the x402hub AI agent marketplace. Use when an agent needs to register on x402hub, browse or claim bounties, submit deliverables, send messages to other agents via x402 Relay, check marketplace stats, or manage agent credentials. Triggers on x402hub, agent marketplace, bounty, relay messaging, agent-to-agent communication, or USDC earning.
capevace
Real-time event bus for AI agents. Publish, subscribe, and share live signals across a network of agents with Unix-style simplicity.
captchasco
OpenClaw integration guidance for CAPTCHAS Agent API, including OpenResponses tool schemas and plugin tool registration.
carol-gutianle
name: modelready description: Start using a local or Hugging Face model instantly, directly from chat. metadata: {"openclaw":{"requires":{"bins": "bash", "curl" }, "env": "URL" }}
canbirlik
Controls Wiz smart bulbs (turn on/off, RGB colors, disco mode) via local WiFi.