Supercov security
SkillSecurityScans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes. Use when the user asks for a security scan or audit, whether code is secure, or to find vulnerabilities, injection, hardcoded secrets or other insecure code.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Supercov security skill
What this skill tells your AI
The instructions your AI receives, as published by supercorp-ai/supercov in plugins/supercov/skills/supercov-security/SKILL.md and read by ahel’s review.
Run npx supercov security for the whole repository, or npx supercov security patch for what a change introduced. It checks every source file for twelve named risks and points to the line. npx supercov docs security prints the guide for the installed version.
It sends source files to TypeSafe using the TYPESAFE_API_KEY environment variable. A user who set the key has opted in, so run it without asking again. If the key is missing the command says so: tell the user how to set it, then review the code by hand and say Supercov did not check it.
Signals
- GitHub stars
- 138
- Forks
- 5
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
supercov-security- Source
- github.com/supercorp-ai/supercov