skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
ruvnet/ruflo748 installs

security-scan

Run full security scans on the codebase using Ruflo security tools. Use when reviewing PRs for security regressions, auditing auth/input-handling code, before production deploys, or when the user asks for a security check at quick/standard/deep depth.

How do I install this agent skill?

npx skills add https://github.com/ruvnet/ruflo --skill security-scan
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubwarn

    The skill downloads and executes an unpinned external package via npx at runtime and processes untrusted source files or PR data without adequate isolation or boundary markers.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Run a security scan at the specified depth.

Via CLI:

npx @claude-flow/cli@latest security scan --depth DEPTH --output json
npx @claude-flow/cli@latest security cve --list
npx @claude-flow/cli@latest security threats --model stride --export md
DepthChecks
quickDependencies, known CVEs
standard+ Input validation, path traversal, secrets
deep+ Threat modeling, injection vectors, auth flows

Store findings via MCP: mcp__plugin_ruflo-core_ruflo__memory_store({ key: "scan-findings", value: "SUMMARY", namespace: "security-findings" })

Train patterns: mcp__plugin_ruflo-core_ruflo__hooks_post-task({ taskId: "security-scan", success: true, storeResults: true })

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/ruvnet/ruflo/security-scan">View security-scan on skillZs</a>