security-scanning

PackSecurity

security-scanning is a plugin that scans code and dependencies for vulnerabilities like injection flaws and insecure libraries. It performs SAST analysis, checks dependencies for known vulnerabilities, and reviews containers for security issues. It also maps findings against OWASP Top 10 compliance and can apply automated security hardening.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have the codebase and its dependencies available for scanning.

What your AI can do with it

  • Runs SAST analysis on source code
  • Scans dependencies for known vulnerabilities
  • Checks code against OWASP Top 10 compliance
  • Scans containers for security issues
  • Applies automated security hardening

Getting started

  1. Have the codebase and its dependencies available for scanning.
  2. Add the security-scanning plugin to the agent's configuration.
  3. Ask the agent to scan the project for vulnerabilities.
  4. Review the reported findings and apply any suggested hardening.

Signals

GitHub stars
40k
Forks
4k
Last commit
Sep 2026

Questions

What kinds of vulnerabilities does it find?
It looks for issues such as injection flaws and insecure libraries, using SAST analysis, dependency vulnerability scanning, and container security scanning.
Does it check compliance standards?
It checks code against OWASP Top 10 compliance.
Can it fix issues automatically?
It can apply automated security hardening; findings from scans are reported for review.
Advanced
Item type
plugin
Key
wshobson-agents-security-scanning
Source
github.com/wshobson/agents