Security Scan — Security skill for Claude Code
Run security scan for specified platform - checks for secrets, vulnerabilities, and security best practices.
How to install Security Scan
Installs to ~/.claude/commands/muyen-vibe-to-prod-security-scan.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/muyen/vibe-to-prod/HEAD/.claude/commands/security-scan.md -o ~/.claude/commands/muyen-vibe-to-prod-security-scan.md Restart Claude Code, or start a new session, for it to be picked up.
What Security Scan does
allowed-tools: Read, Bash, Grep, Glob argument-hint: [backend|ios|android|all] description: Run security scan for specified platform - checks for secrets, vulnerabilities, and security best practices model: sonnet
Security Scan
Security scan for: $ARGUMENTS
Scan Scope
Backend (Go) Security Checks
- Hardcoded Secrets: Search for API keys, tokens, passwords in code
- SQL/NoSQL Injection: Check database queries for unsafe inputs
- Auth Bypass: Verify authen
Alternatives in Security
- Security Best Practices — Review code for language-specific security vulnerabilities 14.6k ★
- Deepsec — Deepsec is a security harness for finding vulnerabilities in your codebase powered by coding agents 7.8k ★
- T3mp3st — autonomous red teaming platform; multi-agent offensive-security meta-harness 5.7k ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Heeler Scan All
Run a complete security scan workflow with Heeler: secrets, vulnerabilities, and license checks. Use when the
Heeler Vulnerabilities Scan
Run Heeler dependency vulnerability scanning and policy gating. Use when the user asks for CVE analysis, sever
Security Sweep
Comprehensive security scanner covering OWASP Top 10 (2025), Mobile Top 10 (2024), and LLM Top 10 (2025). Scan
Vibe Audit
Security scanner for AI-built apps. Catches hardcoded secrets, injection vulnerabilities, missing rate limits,
PsyLinks 360 Security
Stop shipping insecure AI-generated code. This free skill teaches Claude & AI IDEs secure coding by default an
Security Check
Scan project for security issues — exposed secrets, missing .gitignore entries, unsafe patterns
Related Agents
Vuln Analyst
Use this agent to hunt for security vulnerabilities in a bounded region of the Revel codebase. It is the regio
Observer Lite
Lightweight code quality observer. Runs 4 quick checks: secrets scan, test gaps, silent failures, debt markers
Dotnet Security Reviewer
WHEN reviewing .NET code for security vulnerabilities, OWASP compliance, secrets exposure, or cryptographic mi