Project overview
The skill maps a repository’s technologies and attack surfaces, runs a bundled set of SAST, dependency, secret, container, and infrastructure scanners, then performs parallel deep dives into areas such as authorization, injection, supply chain, and agentic risks. It emits Markdown, SARIF, CycloneDX, and a reusable baseline, supports Claude Code only, and is best run inside an isolated container.
Repository facts
- Primary language
- Python
- License
- MIT
- Repository updated
- Jun 19, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacy
Platforms
Claude Code, Codex, and more
Runtime
Docker
Capabilities
Verification and evals