Sec Scan Sca — Security skill for Claude Code
오픈소스 라이브러리 CVE 취약점 진단 (SCA) — Gradle / npm — scan_sca_gradle_tree.py + LLM CVE 관련성 검토.
How to install Sec Scan Sca
Installs to ~/.claude/commands/hssg1109-palantir-sec-scan-sca.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/hssg1109/palantir/HEAD/.claude/commands/sec-scan-sca.md -o ~/.claude/commands/hssg1109-palantir-sec-scan-sca.md Restart Claude Code, or start a new session, for it to be picked up.
What Sec Scan Sca does
allowed-tools: Read, Glob, Grep, Bash, Edit, Write, Agent, WebFetch description: 오픈소스 라이브러리 CVE 취약점 진단 (SCA) — Gradle / npm — scan_sca_gradle_tree.py + LLM CVE 관련성 검토
Sec Scan SCA
대상: $ARGUMENTS (미입력 시 testbed/ 내 대상 목록을 먼저 확인)
실행 절차
`sec-scan-sca/SKILL.md` 전체 내용을 읽고 절차대로 실행할 것.
sec-scan-sca/SKILL.md읽기shared/references/task_prompts/task_11_asset_identification.md읽기sec-scan-sca/references/task_prompts/task_sca.md읽기- `sec-scan-sca/references/task_prompts/task
Alternatives in Security
- Cve MCP Server — Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS sco 1.2k ★
- Promptmap — Security scanner for custom LLM apps 1.2k ★
- Claude Bootstrap — Opinionated project initialization with security-first guardrails, spec-driven atomic todos, LLM testing patte 536 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Pre Publish Audit
Pre-publish audit for agent-tree — version sync (6 fields), exact tarball file-set, dist freshness, MCP manife
Auto Package Migration
A Claude Code Skill that automates package upgrades, CVE remediation, and Jira-driven dependency maintenance a
Sec Triage Agent
Autonomous LLM security triage agent built with Python, Claude Code, Ollama, and Pydantic. Automatically parse
Ccc Audit
Run npm audit + bundle size check + lint scan. Returns vulnerabilities, oversized bundles, and lint errors.
Coremind Sec
Route security operations to the appropriate scan, audit, posture, or mission workflow.
Heeler Vulnerabilities Scan
Run Heeler dependency vulnerability scanning and policy gating. Use when the user asks for CVE analysis, sever
Related Agents
Security Audit Agent
자바 코드 보안 취약점 검증 전문. Refactor 작업 직후 또는 git commit 직전 호출. OWASP Top 10 + Secret Scan (trufflehog/ggshield) + Pro
Dep Cve Auditor
Audits dependency manifests for CVEs (npm/pip/cargo/govulncheck) to disk. Manifests only — security-audit-work
Cicd Manager
Owns CI/CD pipeline design — stage sequencing, gate placement (SAST/SCA/image scan/IaC scan/DAST), promotion b