Vulnerability Scanning

by secondsky88378361314fMIT227 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 10 days ago

Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit. Use for CI/CD security gates, pre-deployment audits, compliance requirements, or encountering CVE detection, outdated packages, license compliance, SBOM generation errors.

Instructions onlySecurity
AI-generated overview

Guides automated vulnerability scanning of dependencies, code and containers with Trivy, Snyk, npm audit and Bandit.

What it does
This skill provides instructions and command examples for detecting security vulnerabilities across dependencies, source code and container images. It covers npm audit, Snyk, Safety, Trivy image and filesystem scans, Bandit for Python, and a GitHub Actions workflow that runs these scanners as CI security gates. It also includes a Node.js snippet that runs scans and exits non-zero when critical vulnerabilities are found, plus best practices for failing builds and tracking findings.
When to use it
Use it when setting up CI/CD security gates, running pre-deployment audits, or meeting compliance requirements. It also fits when you need to detect CVEs, find outdated packages, check license compliance, or generate SBOMs and troubleshoot related errors.
Requirements
Requires the relevant scanning tools to be installed and available, such as Trivy, Snyk, npm audit, Safety, Bandit or OWASP Dependency-Check, plus Node.js for the included snippet. Snyk needs a SNYK_TOKEN secret in CI, and network access is needed to fetch vulnerability data. The skill ships instructions only, with no scripts.

Vulnerability Scanning

Automate security vulnerability detection across code, dependencies, and containers.

Dependency Scanning

bash
# npm auditnpm audit --audit-level=high
# Snyksnyk test --severity-threshold=high
# Safety (Python)safety check --full-report

Container Scanning (Trivy)

bash
# Scan container imagetrivy image myapp:latest --severity HIGH,CRITICAL
# Scan filesystemtrivy fs --scanners vuln,secret .

GitHub Actions Integration

yaml
name: Security Scan
on: [push, pull_request]
jobs:  security:    runs-on: ubuntu-latest    steps:      - uses: actions/checkout@v4
      - name: Run Trivy vulnerability scanner        uses: aquasecurity/[email protected]        with:          scan-type: 'fs'          severity: 'CRITICAL,HIGH'          exit-code: '1'
      - name: Run Snyk        uses: snyk/actions/node@v3        env:          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}        with:          args: --severity-threshold=high
      - name: npm audit        run: npm audit --audit-level=high

Code Analysis (Bandit for Python)

bash
bandit -r src/ -ll -ii

Node.js Scanner

javascript
const { execSync } = require('child_process');
function runScan(command) {  try {    return JSON.parse(execSync(command, { stdio: ['pipe', 'pipe', 'ignore'] }).toString());  } catch (err) {    // A tool may be missing, exit non-zero, or print non-JSON output (e.g.    // trivy progress text when not on a TTY). Treat that as "no parseable    // result" rather than crashing the scanner.    console.warn(`Scan command failed or returned non-JSON: ${command}`);    return null;  }}
function runSecurityScan() {  const results = {    npm: runScan('npm audit --json'),    trivy: runScan('trivy fs --quiet --format json .')  };
  if (!results.npm || !results.npm.metadata) {    console.warn('npm audit produced no metadata; skipping npm checks');  } else {    const critical = results.npm.metadata?.vulnerabilities?.critical || 0;    if (critical > 0) {      console.error(`Found ${critical} critical vulnerabilities`);      process.exit(1);    }  }}

Best Practices

  • Integrate scanning in CI/CD pipeline
  • Fail builds on high/critical findings
  • Scan dependencies and containers
  • Track vulnerabilities over time
  • Document accepted false positives

Tools

  • Trivy (containers, filesystem)
  • Snyk (dependencies, code)
  • npm audit / yarn audit
  • Bandit (Python)
  • OWASP Dependency-Check

Source and attribution

Source:secondsky/claude-skillsinplugins/vulnerability-scanning/skills/vulnerability-scanningat commit8837836

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal