Skip to content
Development
Command

/security-scan

Security-focused code scan. Checks for hardcoded secrets, vulnerable dependencies, and common security issues.

BOOST
From plugin
project-starter
1.4k26 skills7 agents26 commands6 hooks
Install
> /plugin marketplace add CloudAI-X/claude-workflow-v2
> /plugin install project-starter@claude-workflow

How it fires

How this command gets triggered: by you, by Claude, or both.

  • Fires itselfClaude auto-loads it when your prompt matches the work.
  • You can call itInvoke it directly when you want it.
  • Slash command/security-scan

Context preview

What this command does when you run it.

Security-focused code scan. Checks for hardcoded secrets, vulnerable dependencies, and common security issues.

Command definition

security-scan.md
description: Security-focused code scan. Checks for hardcoded secrets, vulnerable dependencies, and common security issues.

Security Scan

Security-focused code scanning. Run before commits and PRs to catch vulnerabilities.

Phase 1: Secret Detection

Scan for hardcoded credentials:

# Common secret patterns (-E: extended regex, so ? and {n} work)
grep -rnE "(password|passwd|secret|token|api[_-]?key)[[:space:]]*[=:][[:space:]]*['\"]" --include="*.js" --include="*.jsx" --include="*.ts" --include="*.tsx" --include="*.py" --include="*.go" --include="*.java" --include="*.rb" --include="*.json" --include="*.yml" --include="*.yaml" --exclude-dir=node_modules --exclude-dir=.git . 2>/dev/null

# Secrets in .env files (templates excluded)
grep -rnE "^[A-Za-z0-9_]*(PASSWORD|SECRET|TOKEN|API_KEY)[A-Za-z0-9_]*=.+" --include=".env*" --exclude=".env.example" --exclude=".env.template" --exclude=".env.sample" --exclude-dir=node_modules --exclude-dir=.git . 2>/dev/null

# AWS keys
grep -rnE "AKIA[0-9A-Z]{16}" --exclude-dir=node_modules --exclude-dir=.git . 2>/dev/null

# Private keys
find . \( -name "*.pem" -o -name "*.key" -o -name "id_rsa" \) -not -path "./node_modules/*" -not -path "./.git/*" 2>/dev/null

Phase 2: Dependency Audit

Check for vulnerable dependencies:

Node.js

npm audit --json 2>/dev/null | head -100
# or
yarn audit --json 2>/dev/null | head -100

Python

pip-audit 2>/dev/null || safety check 2>/dev/null

Go

govulncheck ./... 2>/dev/null

Rust

cargo audit 2>/dev/null

Phase 3: Code Pattern Analysis

Check for dangerous patterns:

SQL Injection

  • String concatenation in SQL queries
  • Unparameterized queries
  • Dynamic table/column names from user input

Command Injection

  • Shell execution with user input (`exec`, `system`, `subprocess`)
  • Unsanitized path construction

XSS Vulnerabilities

  • `innerHTML` with user data
  • `dangerouslySetInnerHTML` without sanitization
  • Unescaped template variables

Path Traversal

  • User input in file paths without sanitization
  • Missing `..` checks

Phase 4: Configuration Check

Verify security settings:

  • [ ] Debug mode disabled in production configs
  • [ ] HTTPS enforced (no HTTP URLs in prod)
  • [ ] CORS properly configured
  • [ ] Security headers present (CSP, X-Frame-Options, etc.)
  • [ ] No default/weak passwords in configs

Output Format

## Security Scan: [PASS/FAIL/WARNINGS]

### Secrets Detected: [count]
1. **CRITICAL** - `file:line`
   - Type: [API key/password/token/private key]
   - Action: Remove immediately and rotate credential

### Vulnerable Dependencies: [count]
1. **[package@version]** - Severity: [Critical/High/Medium/Low]
   - CVE: [CVE number if available]
   - Fixed in: [version]
   - Action: Update to [version]

### Code Vulnerabilities: [count]
1. **[Vulnerability Type]** - `file:line`
   - Risk: [description]
   - Fix: [remediation steps]

### Configuration Issues: [count]
1. **[Issue]**
   - Current: [state]
   - Recommended: [secure state]

### Recommendations
1. [Prioritized action items]

NEVER Commit If

  • Secrets detected in code (rotate and remove)
  • Critical CVEs in dependencies (update first)
  • Obvious injection vulnerabilities (fix first)

Usage

This command ships with the project-starter plugin. Invoke with: `/project-starter:security-scan`

Read more
Ships withproject-starter

A universal Claude Code workflow plugin with specialized agents, skills, hooks, and mode commands for any software project. Compatible with skills.sh — works with Claude Code, Cursor, Codex, and 35+ AI agents.

Get the whole plugin

Other commands on project-starter.