scan-report
A worked example of the report shape this agent produces. Note the structure: a tight summary, a short *fix now* list, then everything else ranked below it. The raw scan had 47 findings; triage reduced the release-blocking set to 3.
$ npx -y skills add vanara-agents/skills --agent claude-codeHow it fires
How this agent gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
Context preview
The summary Claude sees to decide when to auto-load this agent.
A worked example of the report shape this agent produces. Note the structure: a tight summary, a short *fix now* list, then everything else ranked below it. The raw scan had 47 findings; triage reduced the release-blocking set to 3.
Agent definition
scan-report.mdExample: Vulnerability Scan Report
A worked example of the report shape this agent produces. Note the structure: a tight summary, a short *fix now* list, then everything else ranked below it. The raw scan had 47 findings; triage reduced the release-blocking set to 3.
---
Summary
- **Scope:** npm dependencies (lockfile), source secret scan, Dockerfile base image.
- **Findings:** 1 critical, 2 high, 6 medium, 38 low/info (47 raw -> 9 actionable after triage).
- **Most urgent:** rotate the AWS key committed in `config/legacy.env` — assume compromised.
Fix now (release-blocking)
| Item | Severity | Fix | Breaking? | Reachability | |---|---|---|---|---| | AWS access key in `config/legacy.env` | critical | rotate in IAM, move to env var | n/a | Live credential, public history | | `lodash@4.17.15` (CVE-2020-8203) | high | -> `4.17.21` | no | Reachable via `util/merge.js` | | `axios@0.21.0` (SSRF, CVE-2021-3749) | high | -> `0.21.4` | no | Used in outbound webhook client |
Plan (schedule, not blocking)
- **`next@12 -> 14` (3 medium CVEs):** breaking major. Clears 3 advisories but requires app-router
migration review. Estimate: 1 sprint. Group as one coordinated upgrade.
- **`debug=true` in `config/prod.json`:** medium. Leaks stack traces to clients; set `false`.
- **6 transitive medium CVEs in dev-only deps:** real but build-time only; bump opportunistically.
Exposed secrets
| Secret | Location | Action | |---|---|---| | AWS access key `AKIA…` | `config/legacy.env:4` | **Rotate** in IAM (revoke old), replace with `AWS_ACCESS_KEY_ID` env var, add pre-commit secret hook | | Slack webhook URL | `scripts/notify.sh:12` | Rotate webhook in Slack, move to secret manager |
Removal from the latest commit is **not** sufficient — both are still valid at the provider.
Config / container risks
- **Base image `node:18.0-alpine`:** carries 4 OS-package CVEs. Bump to current `node:18-alpine` patch.
- **Container runs as root:** add a non-root `USER` to the Dockerfile.
Accepted / suppressed (with reason)
- **CVE-2025-XXXX in `fast-xml@3.1.0` (CVSS 9.8):** vulnerable `parseAttrs` path requires
`allowAttributes:true`; app uses defaults. Downgraded critical -> medium, scheduled.
- **`AKIAEXAMPLE…` in `docs/setup.md`:** documentation placeholder, not a live key. Suppressed.
- **CVE in `jest@…`:** dev/test-only dependency, not in production bundle. Backlog.
Read more
Example: Vulnerability Scan Report
A worked example of the report shape this agent produces. Note the structure: a tight summary, a short *fix now* list, then everything else ranked below it. The raw scan had 47 findings; triage reduced the release-blocking set to 3.
---
Summary
- **Scope:** npm dependencies (lockfile), source secret scan, Dockerfile base image.
- **Findings:** 1 critical, 2 high, 6 medium, 38 low/info (47 raw -> 9 actionable after triage).
- **Most urgent:** rotate the AWS key committed in `config/legacy.env` — assume compromised.
Fix now (release-blocking)
| Item | Severity | Fix | Breaking? | Reachability | |---|---|---|---|---| | AWS access key in `config/legacy.env` | critical | rotate in IAM, move to env var | n/a | Live credential, public history | | `lodash@4.17.15` (CVE-2020-8203) | high | -> `4.17.21` | no | Reachable via `util/merge.js` | | `axios@0.21.0` (SSRF, CVE-2021-3749) | high | -> `0.21.4` | no | Used in outbound webhook client |
Plan (schedule, not blocking)
- **`next@12 -> 14` (3 medium CVEs):** breaking major. Clears 3 advisories but requires app-router
migration review. Estimate: 1 sprint. Group as one coordinated upgrade.
- **`debug=true` in `config/prod.json`:** medium. Leaks stack traces to clients; set `false`.
- **6 transitive medium CVEs in dev-only deps:** real but build-time only; bump opportunistically.
Exposed secrets
| Secret | Location | Action | |---|---|---| | AWS access key `AKIA…` | `config/legacy.env:4` | **Rotate** in IAM (revoke old), replace with `AWS_ACCESS_KEY_ID` env var, add pre-commit secret hook | | Slack webhook URL | `scripts/notify.sh:12` | Rotate webhook in Slack, move to secret manager |
Removal from the latest commit is **not** sufficient — both are still valid at the provider.
Config / container risks
- **Base image `node:18.0-alpine`:** carries 4 OS-package CVEs. Bump to current `node:18-alpine` patch.
- **Container runs as root:** add a non-root `USER` to the Dockerfile.
Accepted / suppressed (with reason)
- **CVE-2025-XXXX in `fast-xml@3.1.0` (CVSS 9.8):** vulnerable `parseAttrs` path requires
`allowAttributes:true`; app uses defaults. Downgraded critical -> medium, scheduled.
- **`AKIAEXAMPLE…` in `docs/setup.md`:** documentation placeholder, not a live key. Suppressed.
- **CVE in `jest@…`:** dev/test-only dependency, not in production bundle. Backlog.
🐒 Free agents, skills & packs for Claude Code One subscription. An army of Claude Code agents. 30 production-grade agents, skills, and packs for Claude Code — free, Apache-2.0, install with one command.
Repo: vanara-agents/skills
Other agents on vanara-agents-skills.
- AGENT
Use when designing a new HTTP/GraphQL API or changing an existing one — modeling resources, defining endpoint contracts, choosing status codes, pagination, filtering, error envelopes, versioning, and idempotency. Produces a reviewable API contract plus an OpenAPI snippet, not
Open agent - review-notes
This shows how the api-designer agent reviews a flawed draft. Findings are severity-ranked so the implementer fixes the contract-breakers first. Severity legend: **CRITICAL** (breaks clients / data risk), **HIGH** (real bug or inconsistency), **MEDIUM** (maintainability),
Open agent - contract-and-openapi
The contract is the deliverable. Express it as an **OpenAPI 3.1** document so it is human-readable *and* machine-checkable. This reference covers how to structure that document and what `scripts/lint-openapi.mjs` enforces.
Open agent - design-checklist
Run through this before declaring an API contract done. It is ordered the way you should *design*: resources first, cross-cutting rules last. Every box is a place real APIs go wrong in production.
Open agent - versioning-and-evolution
APIs are forever once published: a consumer you've never met may depend on any field you expose. Design so you can **add without breaking**, and version explicitly when you must break.
Open agent - pr-comment-template
Copy-paste templates for leaving review comments. Keep each comment to one finding: an anchor, the problem, and the fix.
Open agent

