security-scan

Scan web applications, containers, and infrastructure for vulnerabilities with compliance mapping.

4|2|Updated Feb 26, 2026
One-click install
npx skills add https://github.com/wojons/skills --skill security-scan-wojons
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-scan
Source: https://github.com/wojons/skills/tree/main/skills/security-scan
Command: npx skills add https://github.com/wojons/skills --skill security-scan-wojons

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the critical need for thorough security assessments across applications, infrastructure, and dependencies, identifying vulnerabilities and misconfigurations that could be exploited.

Core Features & Use Cases

  • LLM-powered analysis: Leverages AI to detect complex and novel security issues beyond traditional tools.
  • Integrated tool ecosystem: Orchestrates multiple industry-standard security scanners (OWASP ZAP, Snyk, Trivy, etc.).
  • Multi-layer scanning: Covers applications (SAST/DAST), infrastructure (IaC), containers, and dependencies.
  • Use Case: Automatically scan a new web application deployment for critical vulnerabilities, map findings to compliance standards like SOC 2, and generate actionable remediation guidance.

Quick Start

Use the security-scan skill to perform a comprehensive security scan on the target URL 'https://app.example.com'.

Frequently Asked Questions about security-scan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What does comprehensive security scanning cover across applications and infrastructure?

Comprehensive security scanning covers web applications, container images, and infrastructure as code. It identifies vulnerabilities and misconfigurations using an integrated ecosystem of LLM-based analysis and industry-standard tools, providing actionable remediation guidance.

How do I scan infrastructure as code for misconfigurations and compliance issues?

You can scan infrastructure as code by running this Skill against your IaC files. It detects misconfigurations and maps the discovered security findings to compliance standards like SOC 2, offering specific remediation guidance.

Can LLM analysis detect novel security vulnerabilities beyond traditional scanners?

Yes, LLM analysis detects complex and novel security issues beyond traditional tools. It leverages artificial intelligence alongside standard scanners like OWASP ZAP, Snyk, and Trivy to perform multi-layer vulnerability assessments.

Does this security scan support web applications and container images?

Yes, this security scan supports web applications and container images. It performs multi-layer scanning across applications using SAST and DAST, alongside containers and dependencies, using an integrated tool ecosystem.

What's the best way to map vulnerability findings to compliance standards?

The best way to map vulnerability findings to compliance standards is using an integrated security scan. It assesses applications and infrastructure, then automatically maps the discovered vulnerabilities to frameworks like SOC 2 with remediation guidance.