exo
The single interface for building, improving, and debugging exo workflows. Routes to one of three intents. BUILD takes a rough idea through interrogation,…
Ghost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability
$ npx -y skills add ghostsecurity/skills --skill report --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/reportContext preview
The summary Claude sees to decide when to auto-load this skill.
Ghost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability
name: "ghost-report" description: "Ghost Security — combined security report. Aggregates findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report focused on the highest risk, highest confidence issues. Use when the user requests a security overview, vulnerability summary, full security audit, or combined scan results." allowed-tools: Read, Write, Edit, Glob, Grep, Bash license: apache-2.0 metadata: version: 1.1.0
You aggregate findings from all scan skills (scan-deps, scan-secrets, scan-code) into a single prioritized report. Do all work yourself — do not spawn subagents or delegate.
$ARGUMENTS
---
Run this Bash command to compute paths:
repo_name=$(basename "$(pwd)") && remote_url=$(git remote get-url origin 2>/dev/null || pwd) && short_hash=$(printf '%s' "$remote_url" | git hash-object --stdin | cut -c1-8) && repo_id="${repo_name}-${short_hash}" && short_sha=$(git rev-parse --short HEAD 2>/dev/null || date +%Y%m%d) && ghost_repo_dir="$HOME/.ghost/repos/${repo_id}" && scans_dir="${ghost_repo_dir}/scans/${short_sha}" && cache_dir="${ghost_repo_dir}/cache" && skill_dir=$(find . -path '*/skills/report/SKILL.md' 2>/dev/null | head -1 | xargs dirname) && echo "scans_dir=$scans_dir cache_dir=$cache_dir skill_dir=$skill_dir"Store `scans_dir` (commit-level scan directory), `cache_dir`, and `skill_dir`.
---
If `<scans_dir>/report.md` already exists, show:
Combined security report is at: <scans_dir>/report.md
And stop. Do not regenerate it.
---
Read `<cache_dir>/repo.md` if it exists. Extract:
If it does not exist, continue without it — this is not an error.
---
List the contents of `<scans_dir>` to see which scan-type directories exist. Recognized types:
If none of these directories exist, report an error:
No scan results found in <scans_dir>. Run one or more scan skills first: /ghost-scan-deps /ghost-scan-secrets /ghost-scan-code
And stop.
---
For each scan type that exists, glob `<scans_dir>/<type>/findings/*.md` and read each finding file **in full**. Retain the complete markdown body of every finding — the report will inline this content directly so readers never need to open individual finding files.
From each finding, also extract these metadata fields for filtering and sorting:
---
**Filter:** Keep only high-confidence findings:
**Exclude** any finding with status `clean`, `rejected`, or `false-positive`.
**Sort** the remaining findings: 1. By severity: high first, then medium, then low 2. Within same severity: deps before secrets before code
---
For `deps` and `secrets` scan types, read `<scans_dir>/<type>/report.md` if present. Extract:
Note: `code` does not produce a `report.md`. For code scan coverage, count the finding files in `<scans_dir>/code/findings/` directly. The "Candidates Scanned" count is the total number of finding files (all statuses). "Confirmed Findings" is the count with status `verified`, `confirmed`, or `unverified`. "False Positives Filtered" is the count with status `rejected`. Do NOT count clean file analyses from the nomination/analysis funnel — those never became findings.
If a per-scan report does not exist for deps or secrets, note it as unavailable.
---
1. Read `<skill_dir>/report-template.md` 2. Populate the template with collected data:
3. Write the report to `<scans_dir>/report.md`
---
Combined security report is at: <scans_dir>/report.md
Plugin marketplace repository for Ghost Security's AI-native application security skills for Claude Code.
The single interface for building, improving, and debugging exo workflows. Routes to one of three intents. BUILD takes a rough idea through interrogation,…
Starts and controls the reaper MITM proxy to capture, inspect, search, and replay HTTP/HTTPS traffic between clients and servers. Capabilities include…
Scans directory structure, detects projects, maps dependencies, and documents code organization into a repo.md file. Use when the user needs a codebase…
Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS,…
Ghost Security - Software Composition Analysis (SCA) scanner. Scans dependency lockfiles for known vulnerabilities, identifies CVEs, and generates findings…
Ghost Security - Secrets and credentials scanner. Scans codebase for leaked API keys, tokens, passwords, and sensitive data. Detects hardcoded secrets and…