Skip to content
Back to skills

Nuclei Scanning

ASecurity

Usar cuando se escanean vulnerabilidades conocidas (CVEs, misconfigs) con Nuclei.

  • 50 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
ai-agentsgobashtestinggitsecurity

Security analysis

A96/100
  • mediumUses curl or wget to download content

Pro scans all 2 files and shows the line behind each finding

Scanned September 28, 2026

npx -y skills add gonzalezpazmonica/savia --skill nuclei-scanning --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Nuclei Scanning?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Nuclei Scanning
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gonzalezpazmonica-nuclei-scanning/badge)](https://www.skillsdirectory.com/skills/gonzalezpazmonica-nuclei-scanning)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
layer: peripheral
name: nuclei-scanning
description: "Usar cuando se escanean vulnerabilidades conocidas (CVEs, misconfigs) con Nuclei."
allowed-tools: [Bash, Read, Write]
metadata:
  # --- metadata.savia.* (SE-333) ---
  savia.category: quality
  savia.maturity: beta
  savia.context: Invocado por /security-pipeline y /pentesting. Complementa security-attacker con deteccion basada en templates.
  savia.disable-model-invocation: false
  savia.user-invocable: False
---

# Nuclei Scanner — Skill de Seguridad Complementario

## Proposito

Complementar el analisis LLM (security-attacker, pentester) con un scanner
basado en templates que detecta CVEs conocidos, misconfiguraciones estandar
y paneles expuestos. El LLM encuentra vulnerabilidades logicas; Nuclei
encuentra las conocidas que el LLM podria pasar por alto.

## Verificacion de instalacion

```bash
if command -v nuclei &>/dev/null; then
  NUCLEI_VERSION=$(nuclei -version 2>&1 | head -1)
  echo "OK: Nuclei disponible — $NUCLEI_VERSION"
else
  echo "SKIP: Nuclei no instalado. Scan complementario omitido."
  echo "Instalar: go install github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest"
  # Degradacion graceful — el pipeline continua sin Nuclei
fi
```

## Ejecucion del scan

```bash
nuclei -u "${TARGET_URL}" \
  -severity critical,high,medium \
  -silent -json \
  -rate-limit 50 \
  -timeout 10 \
  -o "output/security/nuclei-$(date +%Y%m%d-%H%M%S).json"
```

### Parametros obligatorios
- `-severity critical,high,medium` — no reportar low/info (ruido)
- `-silent -json` — output estructurado, sin banners
- `-rate-limit 50` — maximo 50 requests/segundo
- `-timeout 10` — timeout por request en segundos

## Parseo de resultados

Cada linea JSON contiene:

| Campo | Uso |
|-------|-----|
| `template-id` | Identificador del template (ej: `CVE-2024-1234`) |
| `info.severity` | critical, high, medium |
| `info.name` | Nombre legible de la vulnerabilidad |
| `info.classification.cwe-id` | CWE para deduplicacion con hallazgos LLM |
| `matched-at` | URL donde se detecto |
| `curl-command` | Comando para reproducir manualmente |

## Deduplicacion con hallazgos LLM

Mapear hallazgos por CWE:
1. Extraer `cwe-id` de cada hallazgo Nuclei
2. Comparar contra CWEs del security-attacker
3. Si coinciden: marcar como "confirmado por ambas fuentes" (mayor confianza)
4. Si solo Nuclei: anadir como hallazgo nuevo con `source: nuclei`
5. Si solo LLM: mantener con `source: llm`

## Integracion con scoring

Misma formula que el pipeline adversarial:
```
score = 100 - (critical * 25 + high * 10 + medium * 3 + low * 1)
```

Hallazgos Nuclei se marcan con `source: nuclei` en el informe.

## Restricciones por entorno

| Entorno | Permitido | Prohibido |
|---------|-----------|-----------|
| DEV | Scan completo | — |
| PRE | Scan sin DoS templates | `-exclude-tags dos,fuzzing` |
| PROD | Solo pasivo | `-type http -exclude-tags dos,fuzzing,intrusive` |

**NUNCA ejecutar contra produccion sin confirmacion explicita del PM.**

## Degradacion graceful

| Nuclei | Target accesible | Resultado |
|--------|-----------------|-----------|
| Instalado | Si | Scan completo |
| Instalado | No | Solo templates de config local |
| No instalado | — | Skip con aviso, pipeline continua |

## Instalacion de Nuclei

```bash
# Opcion 1: Go install
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

# Opcion 2: Binario directo (Linux amd64)
curl -sL https://github.com/projectdiscovery/nuclei/releases/latest/download/nuclei_linux_amd64.zip \
  -o /tmp/nuclei.zip && unzip -o /tmp/nuclei.zip -d /usr/local/bin/ nuclei
```

## Output

Fichero: `output/security/nuclei-{fecha}.json`
Resumen en informe del pipeline: seccion "Hallazgos Nuclei" con tabla.

Files in this skill

  • DOMAIN.md2.1 KB
  • SKILL.md3.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…