Security Test Scanner
Automated security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, and authentication issues
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 1.29.0
- Author
- Claude Code Plugins
What Security Test Scanner is
Security Test Scanner is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Security Test Scanner adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Security Test Scanner
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install security-test-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Security Test Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/testing/security-test-scanner/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Automated security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, authentication issues, and authorization flaws.
Features
- OWASP Top 10 testing - Complete coverage of critical web vulnerabilities
- Injection testing - SQL, NoSQL, command, LDAP, template injection
- XSS detection - Reflected, stored, and DOM-based XSS
- Authentication testing - Weak passwords, session management, JWT flaws
- Authorization testing - Privilege escalation, IDOR, access control
- Security misconfiguration - Default credentials, verbose errors, headers
- API security - Rate limiting, CORS, input validation
- Comprehensive reporting - Severity ratings, PoC, remediation steps
Installation
/plugin install security-test-scanner@claude-code-plugins-plusUsage
The security scanner agent activates when discussing security testing:
Test the API for SQL injection vulnerabilities
Generate security tests for the authentication system
Check for OWASP Top 10 vulnerabilities in the application
Scan for XSS vulnerabilities in the comment systemVulnerability Coverage
OWASP Top 10 (2021)
- A01: Broken Access Control - Authorization bypass, privilege escalation
- A02: Cryptographic Failures - Weak encryption, exposed data
- A03: Injection - SQL, NoSQL, command injection
- A04: Insecure Design - Design flaws, missing controls
- A05: Security Misconfiguration - Defaults, verbose errors
- A06: Vulnerable Components - Outdated dependencies, CVEs
- A07: Authentication Failures - Weak passwords, sessions
- A08: Integrity Failures - Insecure deserialization
- A09: Logging Failures - Missing logs, monitoring
- A10: SSRF - Server-side request forgery
Test Examples
SQL Injection Tests
describe('SQL Injection Prevention', () => {
const sqlPayloads = [
"' OR '1'='1",
"'; DROP TABLE users--",
"' UNION SELECT * FROM passwords--",
"admin'--"
];
sqlPayloads.forEach(payload => {
it(`should block SQL injection: ${payload}`, async () => {
const response = await api.get(`/api/users?query=${payload}`);
expect(response.status).not.toBe(200);
expect(response.data).not.toContain('SQL');
});
});
});XSS Prevention Tests
describe('XSS Prevention', () => {
it('should sanitize script tags in user input', async () => {
const xssPayload = '<script>alert("XSS")</script>';
const response = await api.post('/api/comments', { text: xssPayload });
const comment = await api.get(`/api/comments/${response.data.id}`);
expect(comment.data.text).not.toContain('<script>');
});
});Authentication Tests
describe('Authentication Security', () => {
it('should prevent brute force attacks', async () => {
const attempts = Array(10).fill().map(() =>
api.post('/api/auth/login', { email: '[email protected]', password: 'wrong' })
);
const responses = await Promise.all(attempts);
expect(responses[9].status).toBe(429); // Rate limited
});
it('should reject expired JWT tokens', async () => {
const expiredToken = 'expired.jwt.token';
const response = await api.get('/api/users/me', {
headers: { Authorization: `Bearer ${expiredToken}` }
});
expect(response.status).toBe(401);
});
});Authorization Tests
describe('Authorization Security', () => {
it('should prevent horizontal privilege escalation', async () => {
const userAToken = await loginAs('[email protected]');
const response = await api.get('/api/users/user-b-id', {
headers: { Authorization: `Bearer ${userAToken}` }
});
expect(response.status).toBe(403);
});
it('should prevent vertical privilege escalation', async () => {
const userToken = await loginAs('[email protected]');
const response = await api.delete('/api/admin/users', {
headers: { Authorization: `Bearer ${userToken}` }
});
expect(response.status).toBe(403);
});
});Security Report
The plugin generates detailed security reports:
Security Test Report
====================
Date: 2025-10-11
Application: API v2.0
Tests Run: 87
Vulnerabilities: 5
CRITICAL (1)
SQL Injection in /api/users/search
CVSS: 9.8
Impact: Database access, data exfiltration
PoC: GET /api/users/search?query=' OR '1'='1'--
Fix: Use parameterized queries or ORM
HIGH (2)
️ Missing authentication on /api/admin/*
CVSS: 8.5
Impact: Unauthorized admin access
…Severity Ratings
- CRITICAL - Immediate exploitation, severe impact
- HIGH - Easy exploitation, significant impact
- MEDIUM - Moderate difficulty, limited impact
- LOW - Difficult exploitation, minimal impact
- INFO - No direct security impact
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Security Test Scanner?
Security Test Scanner is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Automated security vulnerability testing covering OWASP Top 10, SQL injection, XSS, CSRF, and authentication issues
How do I install Security Test Scanner in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install security-test-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Security Test Scanner in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Security Test Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Security Test Scanner safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Analyze Flow Analyze institutional options flow and detect smart money movements Slash Command · jeremylongshore/tons-of-skills-marketplace
- Analyze Coverage Analyze code coverage metrics and identify untested code Slash Command · jeremylongshore/tons-of-skills-marketplace
- Analyze Trends Analyze price trends with technical indicators, pattern recognition, and Slash Command · jeremylongshore/tons-of-skills-marketplace
- Analyze Pool Analyze liquidity pools for APY, impermanent loss, and optimization Slash Command · jeremylongshore/tons-of-skills-marketplace
- Sentry Pack Claude Code skill pack for Sentry (30 skills) Plugin · jeremylongshore/tons-of-skills-marketplace
- Security Pro Pack Professional security tools for Claude Code: vulnerability scanning, compliance, cryptography audit, container & API security Plugin · jeremylongshore/tons-of-skills-marketplace
- Serpapi Pack Governed SerpAPI workflows for search clients, engines, testing, capacity, privacy, deployment, and operations (18 skills) Plugin · jeremylongshore/tons-of-skills-marketplace
- Security Audit Reporter Generate comprehensive security audit reports Plugin · jeremylongshore/tons-of-skills-marketplace