security-scanning 1.3.2 Immutable snapshotLatest
Pinned to commit 156b7a5e7a8b93642628a339ee4039c925b34c7f, captured .
Download 1.3.2 source archive Choose something to compare with View commit on GitHub
More actions and subscriptions
Current package description (not historical)
SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening
Install
This version is listed in the verified marketplace claude-code-workflows (repository wshobson/agents). Run these in Claude Code, in order:
- Add the marketplace
/plugin marketplace add wshobson/agents - Install the plugin
/plugin install security-scanning@claude-code-workflows
These commands install the marketplace's current upstream state, not the pinned commit snapshot on this page; the two can differ.
Contents 10
Skill5
-
attack-tree-construction
plugins/security-scanning/skills/attack-tree-construction/SKILL.mdPermalink -
sast-configuration
plugins/security-scanning/skills/sast-configuration/SKILL.mdPermalink -
security-requirement-extraction
plugins/security-scanning/skills/security-requirement-extraction/SKILL.mdPermalink -
stride-analysis-patterns
plugins/security-scanning/skills/stride-analysis-patterns/SKILL.mdPermalink -
threat-mitigation-mapping
plugins/security-scanning/skills/threat-mitigation-mapping/SKILL.mdPermalink
Agent2
-
security-auditor
plugins/security-scanning/agents/security-auditor.mdPermalink -
threat-modeling-expert
plugins/security-scanning/agents/threat-modeling-expert.mdPermalink
Command3
-
security-dependencies
plugins/security-scanning/commands/security-dependencies.mdPermalink -
security-hardening
plugins/security-scanning/commands/security-hardening.mdPermalink -
security-sast
plugins/security-scanning/commands/security-sast.mdLinked component Permalink
Nothing matches.
Dependencies, compatibility and skill declarations
Recorded dependencies 0
No dependency requirements were recorded from plugin.json or marketplace entries. Only manifest fields saved with the snapshot are shown here; dependency declarations in other files are outside the current collection scope.
Recorded compatibility
No compatibility requirement was recorded for this snapshot from plugin.json or a marketplace entry. Only manifest fields saved with the snapshot are shown here. Declarations in a skill's SKILL.md header are collected separately and, when present, shown on their own under “Skill file declarations”; they never overwrite or fill in this value.
Skill file declarations 5
The content below was read separately from the header of each skill file (SKILL.md) at its pinned commit. It is text the file declares about itself, shown as an annotation only. It is stored apart from the snapshot's dependencies and compatibility (manifest fields) above and does not overwrite them. It is not the package license, version, install count or a release record, and none of it is verified.
Evidence scope and limits
- Each entry is one file at one pinned commit, and field states hold for that file only. Components that point to the same file are merged into one entry; files with identical content share one extraction.
- “Declared in file” means the file's header has the field. “Not declared in this file” appears only when the header parsed successfully and lacks the field. “Invalid declaration” means the field is present but its type, length or characters do not meet the requirements; it is never rewritten or truncated. “Not read” means no usable header was obtained (not yet read, read failed, no header, or an unparseable header), which says neither that the field was declared nor that it was not.
- Compatibility and license text are the file's own wording. They do not show that anything runs, are not legal advice, and are not a license verification. metadata.version is only an annotation inside the file; it is not the package version and is not used to judge which is newer.
- This list groups the version's skill components by their recorded source. A listed source may still be unpinned, unread or unavailable; each entry shows its state. Collection runs in bounded batches and does not promise complete coverage.
- A file whose read failed shows a “retry eligible” time. It is only when the collector may try again, not a schedule, and it does not promise a read or completion.
1–5 of 5 skill file sources · As of
-
Not readplugins/security-scanning/skills/attack-tree-construction/SKILL.mdComponents using this file 1
- attack-tree-construction
plugins/security-scanning/skills/attack-tree-construction/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
wshobson/agents- Pinned commit
156b7a5e7a8b93642628a339ee4039c925b34c7f- File identity
- Regular-file identity recorded
- Blob SHA
b58a37e6dabcbda17838e0300bd27183f6d860e0- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- attack-tree-construction
-
Not readplugins/security-scanning/skills/sast-configuration/SKILL.mdComponents using this file 1
- sast-configuration
plugins/security-scanning/skills/sast-configuration/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
wshobson/agents- Pinned commit
156b7a5e7a8b93642628a339ee4039c925b34c7f- File identity
- Regular-file identity recorded
- Blob SHA
9d6f85c082fd0062b3ecc42f40c32723e017b554- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- sast-configuration
-
Not readplugins/security-scanning/skills/security-requirement-extraction/SKILL.mdComponents using this file 1
- security-requirement-extraction
plugins/security-scanning/skills/security-requirement-extraction/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
wshobson/agents- Pinned commit
156b7a5e7a8b93642628a339ee4039c925b34c7f- File identity
- Regular-file identity recorded
- Blob SHA
a56194330bf9f70cc78a24539d1ce6c5fea8845d- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- security-requirement-extraction
-
Not readplugins/security-scanning/skills/stride-analysis-patterns/SKILL.mdComponents using this file 1
- stride-analysis-patterns
plugins/security-scanning/skills/stride-analysis-patterns/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
wshobson/agents- Pinned commit
156b7a5e7a8b93642628a339ee4039c925b34c7f- File identity
- Regular-file identity recorded
- Blob SHA
458a8074cda1ef9b24fa8cbbda6dc0a7498426d2- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- stride-analysis-patterns
-
Not readplugins/security-scanning/skills/threat-mitigation-mapping/SKILL.mdComponents using this file 1
- threat-mitigation-mapping
plugins/security-scanning/skills/threat-mitigation-mapping/SKILL.md
Fields declared in the file
- Compatibility (declared in file)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- License text (declared in file, unverified)
- Not readNo usable header, which says neither that it was declared nor that it was not.
- metadata.version (file annotation)
- Not readNo usable header, which says neither that it was declared nor that it was not.
This file has no usable extraction record yet, so all three fields show as “Not read”.
- Source
- Open pinned source file
- Repository
wshobson/agents- Pinned commit
156b7a5e7a8b93642628a339ee4039c925b34c7f- File identity
- Regular-file identity recorded
- Blob SHA
c1efac0676bf9754b163aae1dded7be7696c8bf1- Mode
100644- Identity recorded
- Header parse
- Not read
- Why not read
- The file identity is recorded, but its content has not been read yet.
declaration_unread
No extraction record yet.
- threat-mitigation-mapping