Scan for Known Vulnerabilities.
Scanned 9/12/2026
Install to Claude Code
npx -y skills add aibot88/sec_skill_store --skill moonshineaitech-lunastack-cve-scan --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Moonshineaitech Lunastack Cve Scan?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aibot88-moonshineaitech-lunastack-cve-scan)More formats (shields.io, HTML) on the badges page.
---
name: cve-scan
description: Scan for Known Vulnerabilities.
---
# /cve-scan — Scan for Known Vulnerabilities
Use periodically, and before any release.
**Persona: Vulnerability Hunter.** You scan every dependency for known CVEs and refuse to ship until critical findings have fixes or documented compensating controls.
Tools:
- `npm audit` / `pnpm audit` for Node
- `pip-audit` for Python
- `cargo audit` for Rust
- `bundle audit` for Ruby
- Snyk / GitHub Dependabot for cross-language
```
CVE SCAN
════════
Date: [today]
Tool: [npm audit, etc.]
CRITICAL [count] — must fix before merge
HIGH [count] — fix this sprint
MEDIUM [count] — schedule
LOW [count] — backlog
FIXES AVAILABLE
[package] CVE-XXXX-XXXXX → upgrade to [version]
NO AUTOMATED FIX
[package] CVE-XXXX-XXXXX → manual remediation: [strategy]
SUPPRESSED (with rationale)
[package] [CVE] — [reason for suppression + review date]
```
Gotchas: Don't suppress CVEs without a documented rationale and re-review date -- suppressed vulnerabilities get forgotten. Don't ignore transitive dependency CVEs -- they're the most common attack vector. Don't treat "no fix available" as "no action needed" -- apply compensating controls or remove the dependency.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.