security-scanning
Static analysis, dependency vulnerability scanning, secret detection, and container image scanning using open-source tools.
What this skill does
# Security Scanning
Run static analysis, dependency audits, secret detection, and container scanning.
## Static Analysis (SAST)
### Semgrep — find code-level vulnerabilities
```bash
# Scan current directory with auto-detected rules
semgrep scan --config auto .
# Scan with OWASP top 10 rules
semgrep scan --config "p/owasp-top-ten" .
# Scan specific language
semgrep scan --config "p/python" src/
# Output as JSON for processing
semgrep scan --config auto --json . | jq '.results[] | {path: .path, line: .start.line, rule: .check_id, message: .extra.message}'
# Scan with severity filter
semgrep scan --config auto --severity ERROR .
```
## Dependency Vulnerability Scanning (SCA)
### Trivy — scan project dependencies
```bash
# Scan filesystem for vulnerable dependencies
trivy fs --severity HIGH,CRITICAL .
# Scan with JSON output
trivy fs --format json --output trivy-report.json .
# Scan specific lockfile
trivy fs --scanners vuln package-lock.json
# Scan and fail on critical (useful for CI)
trivy fs --exit-code 1 --severity CRITICAL .
```
### Snyk — dependency and code scanning
```bash
# Test dependencies for known vulnerabilities
snyk test
# Monitor project (registers with Snyk dashboard)
snyk monitor
# Test a specific manifest
snyk test --file=requirements.txt
# Code analysis
snyk code test
# Show dependency tree
snyk test --print-deps
```
### npm/pnpm audit (no extra tools needed)
```bash
# npm
npm audit --json | jq '.vulnerabilities | to_entries[] | {name: .key, severity: .value.severity, via: .value.via[0]}'
# pnpm
pnpm audit --json
# pip (Python)
pip audit --format json
```
## Secret Detection
### TruffleHog — find leaked credentials
```bash
# Scan git history for secrets
trufflehog git file://. --json | jq '{detector: .DetectorName, file: .SourceMetadata.Data.Git.file, line: .SourceMetadata.Data.Git.line}'
# Scan filesystem only (no git history)
trufflehog filesystem . --json
# Scan specific branch
trufflehog git file://. --branch main
# Scan since specific commit
trufflehog git file://. --since-commit abc123
```
## Container Image Scanning
### Trivy — scan Docker images
```bash
# Scan a local image
trivy image --severity HIGH,CRITICAL myapp:latest
# Scan with full report
trivy image --format json --output image-report.json myapp:latest
# Scan remote image
trivy image --severity CRITICAL nginx:latest
```
### Grype — image vulnerability scanner
```bash
# Scan local image
grype myapp:latest
# Scan with severity filter
grype myapp:latest --only-fixed --fail-on critical
# Scan from Dockerfile build context
grype dir:.
# JSON output
grype myapp:latest -o json | jq '.matches[] | {name: .vulnerability.id, severity: .vulnerability.severity, package: .artifact.name}'
```
## Quick Triage Workflow
1. **Secrets first** — `trufflehog git file://. --json` (most urgent, leaked creds = immediate risk)
2. **Dependencies** — `trivy fs --severity HIGH,CRITICAL .` (known CVEs in your supply chain)
3. **Code** — `semgrep scan --config auto .` (your own code vulnerabilities)
4. **Images** — `trivy image myapp:latest` (if containerized)
## Notes
- Always review findings before acting — false positives are common in SAST.
- Severity levels: CRITICAL > HIGH > MEDIUM > LOW > INFO. Focus on CRITICAL and HIGH first.
- For CI pipelines, use `--exit-code 1` (Trivy) or `--error` (Semgrep) to fail builds on findings.
- Secret detection in git history can be slow on large repos. Use `--since-commit` to limit scope.
- Run `snyk auth` before first use of Snyk CLI.
Related in Image & Video
watch
IncludedWatch a video (URL or local path). Downloads with yt-dlp, extracts auto-scaled frames with ffmpeg, pulls the transcript from captions (or Whisper API fallback), and hands the result to Claude so it can answer questions about what's in the video.
physical-ai-defect-image-generation
IncludedUse when the user wants to orchestrate defect image generation, run associated setup, or handle outputs on OSMO. The Day 0 path handles cold-start with USD-to-ROI, image-edit augmentation, and AnomalyGen to create initial PCBA datasets. The Day 1 path performs inference and labeling on real images. This skill helps with first-time asset setup, creation of finetuning checkpoints, and configuring deployment. Trigger keywords: defect image generation, dig workflow, dig pipeline, defect image detection workflow, aoi pipeline, aoi anomalygen, usd2roi anomalygen, day 0 pcba, day 1 pcba, day 1 real-photo alignment, day 1 manual roi, metal surface anomaly, glass defect, anomalygen finetune, setup_pcb, setup_metal, setup_glass, setup_pretrained, dig setup, dig datasets, dig pretrained checkpoint, dig image-edit endpoint.
accelint-react-best-practices
IncludedReact performance optimization and best practices. ALWAYS use this skill when working with any React code - writing components, hooks, JSX; refactoring; optimizing re-renders, memoization, state management; reviewing for performance; fixing hydration mismatches; debugging infinite re-renders, stale closures, input focus loss, animations restarting; preventing remounting; implementing transitions, lazy initialization, effect dependencies. Even simple React tasks benefit from these patterns. Covers React 19+ (useEffectEvent, Activity, ref props). Triggers - useEffect, useState, useMemo, useCallback, memo, inline components, nested components, components inside components, re-render, performance, hydration, SSR, Next.js, useDeferredValue, combined hooks.
elevenlabs-agents
IncludedBuild conversational AI voice agents with ElevenLabs Platform using React, JavaScript, React Native, or Swift SDKs. Configure agents, tools (client/server/MCP), RAG knowledge bases, multi-voice, and Scribe real-time STT. Use when: building voice chat interfaces, implementing AI phone agents with Twilio, configuring agent workflows or tools, adding RAG knowledge bases, testing with CLI "agents as code", or troubleshooting deprecated @11labs packages, Android audio cutoff, CSP violations, dynamic variables, or WebRTC config. Keywords: ElevenLabs Agents, ElevenLabs voice agents, AI voice agents, conversational AI, @elevenlabs/react, @elevenlabs/client, @elevenlabs/react-native, @elevenlabs/elevenlabs-js, @elevenlabs/agents-cli, elevenlabs SDK, voice AI, TTS, text-to-speech, ASR, speech recognition, turn-taking model, WebRTC voice, WebSocket voice, ElevenLabs conversation, agent system prompt, agent tools, agent knowledge base, RAG voice agents, multi-voice agents, pronunciation dictionary, voice speed control, elevenlabs scribe, @11labs deprecated, Android audio cutoff, CSP violation elevenlabs, dynamic variables elevenlabs, case-sensitive tool names, webhook authentication
humanizer
IncludedHumanize AI-generated text by detecting and removing patterns typical of LLM output. Rewrites text to sound natural, specific, and human. Uses 28 pattern detectors, 560+ AI vocabulary terms across 3 tiers, and statistical analysis (burstiness, type-token ratio, readability) for comprehensive detection. Use when asked to humanize text, de-AI writing, make content sound more natural/human, review writing for AI patterns, score text for AI detection, or improve AI-generated drafts. Covers content, language, style, communication, and filler categories.
generating-mermaid-diagrams
IncludedSalesforce architecture diagrams using Mermaid with ASCII fallback. Use this skill when generating text-based diagrams for Salesforce architecture, OAuth flows, ERDs, integration sequences, or Agentforce structure. TRIGGER when: user says "diagram", "visualize", "ERD", or asks for sequence diagrams, flowcharts, class diagrams, or architecture visualizations in Mermaid. DO NOT TRIGGER when: user wants PNG/SVG image output (use generating-visual-diagrams), or asks about non-Salesforce systems.