security-scanner
Run security scans including SAST, dependency scanning, and secret detection
npx skills add a5c-ai/babysitter --skill security-scanner --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# Security Scanner Skill ## Overview Runs comprehensive security scans including SAST scanning with Semgrep/CodeQL, dependency vulnerability scanning with Snyk/OWASP, secret detection, and container image scanning. ## Capabilities - SAST scanning (Semgrep, CodeQL) - Dependency vulnerability scanning (Snyk, OWASP Dependency-Check) - Secret detection (git-secrets, truffleHog, gitleaks) - Container image scanning (Trivy, Grype) - License compliance checking - SBOM generation - CVE database lookup ## Target Processes - security-architecture-review - iac-review ## Input Schema ```json { "type": "object", "required": ["targets"], "properties": { "targets": { "type": "array", "items": { "type": "string" }, "description": "Paths to scan" }, "scanTypes": { "type": "array", "items": { "type": "string", "enum": ["sast", "dependencies", "secrets", "containers", "licenses"] }, "default": ["sast", "dependencies", "secrets"] }, "tools": { "type": "object", "properties": { "sast": { "type": "string", "enum": ["semgrep", "codeql"], "default": "semgrep" }, "dependencies": { "type": "string", "enum": ["snyk", "owasp", "npm-audit"], "default": "snyk" }, "secrets": { "type": "string", "enum": ["gitleak
- Overview
- Capabilities
- Target Processes
- Input Schema
- Output Schema
- Usage Example
What does the security-scanner skill do?
Run security scans including SAST, dependency scanning, and secret detection
How do I install it?
Run `npx skills add a5c-ai/babysitter --skill security-scanner --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From a5c-ai/babysitter, a repository with 1,642 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
