Vuln Scan — Security skill for Claude Code
Multi-agent security vulnerability sweep — fans out region-scoped hunters, verifies findings, and reports.
How to install Vuln Scan
Installs to ~/.claude/commands/letsrevel-revel-backend-vuln-scan.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/letsrevel/revel-backend/HEAD/.claude/commands/vuln-scan.md -o ~/.claude/commands/letsrevel-revel-backend-vuln-scan.md Restart Claude Code, or start a new session, for it to be picked up.
What Vuln Scan does
description: Multi-agent security vulnerability sweep — fans out region-scoped hunters, verifies findings, and reports argument-hint: "[scope: full (default) | | diff] [--fast | --deep] [--report ]" allowed-tools: Bash(git ls-files:*), Bash(git diff:*), Bash(git merge-base:*), Bash(git log:*), Bash(git rev-parse:*), Bash(date:*) disable-model-invocation: true
You are the **orchestrator** for a multi-agent security review of the Revel backend. You run in the main session
Alternatives in Security
- Security Scan Report — Generated: 2026-04-10 20:48 UTC Skills scanned: 134 Total findings: 836 Critical: 32 High: 50 Safe skills: 100 18.1k ★
- Skills — Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows 4k ★
- Review Artifact — Creates one polished, self-contained HTML artifact from review findings, audit notes, PR feedback, code review 652 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Wormhook Setup
Interactively set up wormhook's out-of-Claude scanning (CLI, git-pull audit, hourly sweep, scan roots)
Audit Codebase
Cold-start, time-boxed, multi-domain audit sweep — surfaces ranked findings with reasoning chains across secur
Code Review Intense Flow
Heavy code review - fans out to all applicable specialized reviewers (security, frontend, seo, geo, playwright
Audit Strict
Multi-pass consensus audit — runs the audit twice with different prompts, only reports consensus findings. Agg
Gse Meta Audit Fix
Post-audit fix session for the GSE-One methodology repository. Consumes the canonical registry _LOCAL/audit/au
Public Skills Builder
Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no
Related Agents
Vuln Analyst
Use this agent to hunt for security vulnerabilities in a bounded region of the Revel codebase. It is the regio
PR Review Orchestrator
Diff-scoped design-level PR review. Reads the diff versus the derived default branch, classifies the changed p
After Confirming A Vulnerability
findings.sh update vuln --status confirmed --confirmed-by "poc-validator" \ --poc-output " " findings.sh updat