smithery.ai

security-scan

Orchestrates SAST, dependency audit, and secrets detection using self-hosted tools (Semgrep, Bandit, pip-audit, Trivy, gitleaks). Integrates with task-monitor and memory.

First seen Mar 20, 2026

Installation

$ npx skills add https://smithery.ai

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Skill metadata

Parsed from SKILL.md frontmatter.

Allowed toolsrun_command, read_file
More metadata
short-description
Security scanning orchestrator (SAST, deps, secrets)

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,957 B
  • docs SUMMARY.md 191 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 11 installs

SKILL.md

Security-Scan: Self-Hosted Security Scanning

Orchestrate comprehensive security scanning using self-hosted tools.

Features

  1. SAST (Static Application Security Testing)

- Semgrep: Multi-language pattern matching - Bandit: Python-specific security linting

  1. Dependency Audit

- pip-audit: Python package vulnerabilities - npm audit: Node.js package vulnerabilities (auto-detected) - Trivy: Container and filesystem scanning

  1. Secrets Detection

- gitleaks: Find hardcoded credentials, API keys, tokens

  1. Integrations

- Task-monitor: Real-time progress tracking - Memory: Store and recall scan results across sessions

Commands

Command Description
./run.sh scan --path . Run all security scans
./run.sh sast --path . --language python Run SAST only
./run.sh deps --path . Run dependency audit only
./run.sh secrets --path . Run secrets detection only
./run.sh report --format json Generate scan report

Usage

# Full security scan
./run.sh scan --path /path/to/project

# SAST scan for Python
./run.sh sast --path . --language python

# Dependency audit
./run.sh deps --path .

# Secrets detection
./run.sh secrets --path .

# Store results in memory
./run.sh scan --path . --store-results

Output Format

All commands output structured JSON with:

  • findings: List of security issues
  • severity: critical/high/medium/low/info
  • location: File path and line number
  • rule_id: Scanner rule that triggered
  • description: Human-readable description
  • remediation: Suggested fix

Required Tools

Tool Purpose Install
semgrep SAST pip install semgrep
bandit Python SAST pip install bandit
pip-audit Python deps pip install pip-audit
gitleaks Secrets Binary from GitHub releases
trivy Container scan Binary from GitHub releases

Integration with Task-Monitor

Scans automatically register with task-monitor for progress tracking:

# View scan progress
.pi/skills/task-monitor/run.sh tui --filter security-scan

Integration with Memory

Store scan results for trend analysis:

# Store results
./run.sh scan --path . --store-results

# Recall previous scans
.pi/skills/memory/run.sh recall "security scan results"