Scan one dependency surface, draft the advisory, and package the approved publication bundle.
Scanned 9/12/2026
Install to Claude Code
npx -y skills add aibot88/sec_skill_store --skill ecosystem-vuln-scan --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Ecosystem Vuln Scan?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aibot88-ecosystem-vuln-scan)More formats (shields.io, HTML) on the badges page.
---
name: ecosystem-vuln-scan
description: Scan one dependency surface, draft the advisory, and package the approved publication bundle.
---
# Ecosystem Vulnerability Scan
This is the public-facing advisory lane built on top of `vuln-scan`.
It keeps the security flow bounded and reviewable:
1. produce the risk packet
2. draft the advisory
3. require approval before anything is packaged for publication
## Quality Profile
- Purpose: compose scan, advisory drafting, and approval into one public-facing
security lane.
- Audience: maintainers, operators, and external readers affected by the
advisory.
- Artifact contract: risk packet, advisory draft, approval decision, and
publish packet.
- Evidence bar: public-facing claims must trace back to the risk packet and
verified advisory sources. Speculation remains private operator context.
- Voice bar: precise advisory language with clear impact, affected scope, and
remediation. No sensationalism or generic security filler.
- Strategic bar: publish only when the advisory materially helps affected
users. Otherwise keep the output as an operator remediation packet.
- Stop conditions: stop at review when severity, exposure, remediation, or
disclosure authorization is not clear.
## Inputs
- `target` (required): repo, lockfile, package set, or ecosystem slice.
- `objective` (optional): what the operator wants from the scan.
- `channel` (optional): final advisory channel; defaults to `advisory`.
- `scan_context` (optional): known incidents or previous findings.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!