Vulnerability Scanning

secondsky/claude-skills/plugins/vulnerability-scanning/skills/vulnerability-scanning

作者 secondsky88378361314fMIT227 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫10 天前更新

Automated security scanning for dependencies, code, containers with Trivy, Snyk, npm audit. Use for CI/CD security gates, pre-deployment audits, compliance requirements, or encountering CVE detection, outdated packages, license compliance, SBOM generation errors.

僅含說明Security
AI 產生的概覽

指導使用 Trivy、Snyk、npm audit 與 Bandit 對相依套件、程式碼和容器進行自動化漏洞掃描。

功能
此技能提供用於偵測相依套件、原始碼與容器映像中安全漏洞的指示與指令範例。內容涵蓋 npm audit、Snyk、Safety、Trivy 映像與檔案系統掃描、適用於 Python 的 Bandit,以及將這些掃描器當作 CI 安全閘門執行的 GitHub Actions 工作流程。它也包含一段 Node.js 程式碼,用來執行掃描並在發現重大漏洞時以非零狀態結束,並提供讓建置失敗與追蹤發現結果的最佳實務。
適用情境
適用於建立 CI/CD 安全閘門、執行部署前稽核或滿足合規要求的情境。也適合需要偵測 CVE、找出過時套件、檢查授權合規、產生 SBOM 以及排解相關錯誤的場合。
執行需求
需要安裝並可使用相關掃描工具,例如 Trivy、Snyk、npm audit、Safety、Bandit 或 OWASP Dependency-Check,執行範例程式碼還需要 Node.js。Snyk 在 CI 中需要 SNYK_TOKEN 密鑰,並需要網路存取以取得漏洞資料。此技能僅包含指示,不附帶指令碼。

Vulnerability Scanning

Automate security vulnerability detection across code, dependencies, and containers.

Dependency Scanning

bash
# npm auditnpm audit --audit-level=high
# Snyksnyk test --severity-threshold=high
# Safety (Python)safety check --full-report

Container Scanning (Trivy)

bash
# Scan container imagetrivy image myapp:latest --severity HIGH,CRITICAL
# Scan filesystemtrivy fs --scanners vuln,secret .

GitHub Actions Integration

yaml
name: Security Scan
on: [push, pull_request]
jobs:  security:    runs-on: ubuntu-latest    steps:      - uses: actions/checkout@v4
      - name: Run Trivy vulnerability scanner        uses: aquasecurity/[email protected]        with:          scan-type: 'fs'          severity: 'CRITICAL,HIGH'          exit-code: '1'
      - name: Run Snyk        uses: snyk/actions/node@v3        env:          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}        with:          args: --severity-threshold=high
      - name: npm audit        run: npm audit --audit-level=high

Code Analysis (Bandit for Python)

bash
bandit -r src/ -ll -ii

Node.js Scanner

javascript
const { execSync } = require('child_process');
function runScan(command) {  try {    return JSON.parse(execSync(command, { stdio: ['pipe', 'pipe', 'ignore'] }).toString());  } catch (err) {    // A tool may be missing, exit non-zero, or print non-JSON output (e.g.    // trivy progress text when not on a TTY). Treat that as "no parseable    // result" rather than crashing the scanner.    console.warn(`Scan command failed or returned non-JSON: ${command}`);    return null;  }}
function runSecurityScan() {  const results = {    npm: runScan('npm audit --json'),    trivy: runScan('trivy fs --quiet --format json .')  };
  if (!results.npm || !results.npm.metadata) {    console.warn('npm audit produced no metadata; skipping npm checks');  } else {    const critical = results.npm.metadata?.vulnerabilities?.critical || 0;    if (critical > 0) {      console.error(`Found ${critical} critical vulnerabilities`);      process.exit(1);    }  }}

Best Practices

  • Integrate scanning in CI/CD pipeline
  • Fail builds on high/critical findings
  • Scan dependencies and containers
  • Track vulnerabilities over time
  • Document accepted false positives

Tools

  • Trivy (containers, filesystem)
  • Snyk (dependencies, code)
  • npm audit / yarn audit
  • Bandit (Python)
  • OWASP Dependency-Check

來源與署名

來源:secondsky/claude-skills位於plugins/vulnerability-scanning/skills/vulnerability-scanning提交8837836

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架