/security-scan — 6-Layer Security Pipeline
What
Runs a defense-in-depth static scan across 6 layers. A project with zero CVEs can still have hardcoded secrets, SQL injection, and missing auth — each layer catches a different vulnerability class. Findings map to the OWASP Top 10:2025 taxonomy and are rated Critical/High/Medium/Low by exploitability, impact, and exposure — a Critical SQL injection on a public endpoint outranks a Low info-disclosure on an admin page.
Detection patterns, OWASP mappings, remediation code, and the report template
live in references/scan-layers.md — read it before executing.
Honesty rule: this is static analysis, not a penetration test. It catches known patterns but misses business-logic flaws, complex authorization bypasses, and runtime-only vulnerabilities. Every report states this.
When
- Pre-release security gate — full scan, non-negotiable before production
- "Security scan", "security audit", "find secrets", "CVE check", "OWASP"
- After a dependency update (Layer 1), auth changes (Layer 4), config changes (Layer 2), or logging changes (Layer 6)
- Pre-pentest preparation — fix static issues before paying for a pentest
- Incident response and quarterly reviews
How
Step 1: Choose Layers
Step 2: Execute the Layers
Read references/scan-layers.md for the detection patterns per layer.
Delegate deep auth and secrets review to the security-auditor agent, pairing
the authentication and configuration skills.
Step 3: Rate with Context
Severity must match actual risk — over-classification causes alert fatigue and buries the real Critical:
- Test-fixture "secrets" and appsettings.Development.json values are expected — skip or mark INFO, don't flag as HIGH
- A missing XML comment is never a security finding
- Reserve Critical for exploitable-now issues: injection on public endpoints, exposed production secrets, auth bypass
Step 4: Report
Every finding: [SEVERITY] file:line — title, OWASP category, what's wrong,
impact if exploited, and remediation code (before/after). Produce the summary
table + per-layer status table from the reference template, prefixed with the
static-analysis disclaimer.
Example
Related
references/scan-layers.md— detection patterns, OWASP 2025 mappings, report template/verify— Phase 5 runs a lightweight version of this scan per change set/health-check— Dimension 7 (Security Posture) is the spot-check versionauthentication/configuration— remediation patterns for Layers 4 and 2


