security-scan

SkillDatabases & data

Use when scanning for XSS, SQL injection, command injection, hardcoded secrets, or any OWASP Top 10 vulnerability across a codebase.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the security-scan skill

What this skill tells your AI

The instructions your AI receives, as published by fusengine/agents in plugins/security-expert/skills/security-scan/SKILL.md and read by ahel’s review.

Pattern categories include XSS, SQL injection, command injection, unsafe code execution (eval/exec), SSRF, weak cryptography, hardcoded secrets, insecure deserialization, and path traversal/LFI/RFI, plus GraphQL-specific patterns (introspection, depth/complexity limiting, batching, authorization) when a GraphQL endpoint is present.

After scanning, it delegates fixes to the sniper agent with file:line, vulnerability, and fix — it does not apply fixes itself.

Security Scan Skill

Overview

Orchestrates the full security scanning workflow across all supported languages.

Supported Languages

LanguageMarker FilesPattern Count
JavaScript/TypeScriptpackage.json25+
PHPcomposer.json20+
Pythonrequirements.txt, pyproject.toml18+
Swift/iOSPackage.swift, *.xcodeproj15+
Gogo.mod12+
RustCargo.toml10+

Workflow

  1. Detect language from project markers
  2. Load patterns from references/scan-patterns.md
  3. Run bun ${CLAUDE_PLUGIN_ROOT}/../node_modules/@fusengine/harness/dist/cli/bin.mjs scan <dir> for automated scanning (OWASP patterns ported into the harness)
  4. Map findings to OWASP categories via references/owasp-top10.md
  5. Generate report using references/templates/scan-report.md

Pattern Categories

  • XSS (Cross-Site Scripting)
  • SQL Injection
  • Command Injection
  • Code Execution (eval, exec)
  • SSRF (Server-Side Request Forgery)
  • Weak Cryptography
  • Hardcoded Secrets
  • Insecure Deserialization
  • Path Traversal / LFI / RFI

Integration

After scanning, delegate fixes to sniper:

Agent(subagent_type="fuse-ai-pilot:sniper", prompt="Security fixes: [FILE:LINE] [VULN] [FIX]")

References

Signals

GitHub stars
25
Forks
4
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
security-scan-fusengine
Source
github.com/fusengine/agents