security-scan
Run the security scan gate before pushing.
Install / Use
npx skills add alirezarezvani/claude-skillsInstalls into whichever agent you are using.
Claude Commands
Claude Code slash commands
Quality Score
Category
SecuritySupported Platforms
Our assessment of security-scan
security-scan scores 56/100 on our quality scale, 538th of 559 Security skills we index.
Its Claude Commands is 659 bytes long, written without headings and no code examples: fairly brief, so expect to fill in details yourself.
With 26,437 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 27 days ago, so security-scan is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-26. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
security-scan compared with similar skills
All 4 of these similar skills score higher than security-scan; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| security-scan (this skill)by alirezarezvani | 56 | 26.4k | 27d ago | Claude Commands |
| claude-memby thedotmack | 100 | 94.7k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 85.5k | 10d ago | CLAUDE.md |
| Understand-Anythingby Egonex-AI | 100 | 84.2k | 14d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 73.8k | today | CLAUDE.md |
Frequently asked questions
- How do I install security-scan?
- Run
npx skills add alirezarezvani/claude-skills. The install tabs above show the steps for each supported agent. - Which AI agents does security-scan work with?
- It is written for Claude Code, as a Claude Commands file. Other agents that read the same format can often use it too.
- Is security-scan safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is security-scan still maintained?
- The repository was last updated 27 days ago, so security-scan is actively maintained.
Skill content
View source on GitHubdescription: Run the security scan gate before pushing.
- Ensure dependencies are installed:
pip install safety==3.2.4 brew install gitleaks # or appropriate package manager - Scan for committed secrets:
gitleaks detect --verbose --redact- Resolve any findings before continuing.
- Audit Python dependencies (if requirements files exist):
for f in $(find . -name "requirements*.txt" 2>/dev/null); do safety check --full-report --file "$f" done - Record results in the commit template's Testing section.
- After a clean pass, proceed with commit and push workflow.
Related Skills
claude-mem
94.7kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
85.5kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
Understand-Anything
84.2kGraphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
headroom
73.8kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
