lens-security

Identifies security vulnerabilities and risks in Java codebases using OWASP standards.

Updated Aug 26, 2025
One-click install
npx skills add https://github.com/ThonkTank/Salt-Marcher --skill lens-security
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: lens-security
Source: https://github.com/ThonkTank/Salt-Marcher/tree/main/tools/quality/skills/lens-security
Command: npx skills add https://github.com/ThonkTank/Salt-Marcher --skill lens-security

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

This Skill streamlines the process of conducting comprehensive code reviews, pinpointing security vulnerabilities, and identifying potential risks to the codebase.

Core Features & Use Cases

  • Security Vulnerability Scanning: Automated identification of security risks aligned with OWASP standards.
  • Threat Modeling: Evaluates attack surfaces and trust boundaries for each code component.
  • Technical Analysis: Inspects and evaluates specific vulnerability patterns, including injection attacks, authentication weaknesses, and sensitive data exposure.
  • Use Case: As a senior application security engineer, utilize this Skill to review changes in the codebase, focusing on real-world attack vectors and potential security breaches.

Quick Start

Run the lens-security skill to initiate a code review and perform a security check on the specified code or modules.

Frequently Asked Questions about lens-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security code review aligned with OWASP standards?

Security code reviews aligned with OWASP standards involve scanning your codebase to identify vulnerabilities and evaluate attack surfaces. This Skill pinpoints specific vulnerability patterns like injection attacks and authentication weaknesses, providing diagnostic outputs for application security engineering workflows.

Can I use automated vulnerability scanning to identify injection attacks in Java applications?

Yes, automated vulnerability scanning can identify injection attacks in Java applications. This Skill inspects specific vulnerability patterns including injection attacks and sensitive data exposure, leveraging realistic attack scenarios to pinpoint potential security breaches in your codebase.

What is threat modeling and how does it apply to codebase security checks?

Threat modeling in codebase security checks involves evaluating attack surfaces and trust boundaries for each code component. This Skill applies threat modeling to pinpoint security vulnerabilities and identify potential risks during comprehensive code reviews.

Does this vulnerability scanning approach work for reviewing codebase changes in application security workflows?

Yes, this vulnerability scanning approach works for reviewing codebase changes in application security workflows. Senior application security engineers can utilize this Skill to review code changes, focusing on real-world attack vectors and potential security breaches.

What are the limitations of automated OWASP security reviews for Java applications?

The limitations of automated OWASP security reviews include focusing specifically on vulnerability patterns in Java applications. This Skill provides diagnostic outputs for code reviews but is designed to evaluate realistic attack scenarios and specific vulnerability patterns rather than generic code quality issues.