Vulnerability Scanner
Comprehensive vulnerability scanning for code, dependencies, and configurations with CVE detection
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 1.24.0
- Author
- Jeremy Longshore
What Vulnerability Scanner is
Vulnerability Scanner is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Vulnerability Scanner adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Vulnerability Scanner
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install vulnerability-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Vulnerability Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/security/vulnerability-scanner/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Comprehensive vulnerability scanning for code, dependencies, and configurations with CVE detection and remediation guidance.
Features
- Static Application Security Testing (SAST) - Scan source code for vulnerabilities
- Dependency Scanning - Check third-party packages for known CVEs
- Configuration Analysis - Review security-sensitive configurations
- Severity Classification - CVSS-based severity scoring
- Remediation Guidance - Actionable fix recommendations
Installation
/plugin install vulnerability-scanner@claude-code-plugins-plusUsage
# Scan current directory
/scan
# Or use shortcut
/vulnWhat It Scans
Code Vulnerabilities
- SQL injection risks
- Cross-site scripting (XSS)
- Command injection
- Path traversal
- Insecure deserialization
- Hardcoded credentials
- Weak cryptography
- Authentication bypasses
Dependencies
- Known CVEs in npm packages
- Known CVEs in pip packages
- Known CVEs in composer packages
- Outdated packages with security patches
- Transitive dependency vulnerabilities
Configuration Issues
- Insecure SSL/TLS settings
- Weak CORS policies
- Missing security headers
- Debug mode in production
- Exposed admin interfaces
Report Output
The plugin generates a detailed vulnerability report with:
- Executive Summary
- Total vulnerabilities found
- Breakdown by severity (Critical, High, Medium, Low)
- Risk score
- Detailed Findings
- Vulnerability description
- Affected files and line numbers
- CVE identifiers (if applicable)
- CVSS score
- Code snippets
- Remediation steps
- Recommendations
- Prioritized fix list
- Security best practices
- Links to security advisories
Example Report
VULNERABILITY SCAN REPORT
=========================
Scan Date: 2025-10-11
Total Vulnerabilities: 12
- Critical: 2
- High: 5
- Medium: 3
- Low: 2
CRITICAL VULNERABILITIES
------------------------
1. SQL Injection in User Authentication
File: src/auth/login.js:45
Severity: Critical (CVSS 9.8)
Vulnerable Code:
const query = `SELECT * FROM users WHERE username='${username}'`
…Security Best Practices
- Run scans regularly (pre-commit, pre-deploy)
- Address Critical and High severity issues immediately
- Keep dependencies updated
- Never commit vulnerability reports to public repositories
- Validate fixes with follow-up scans
- Document false positives for future reference
Requirements
- Read access to codebase
- Access to package manifest files (package.json, requirements.txt, composer.json)
- Network access for CVE database lookups (optional)
License
MIT License - See LICENSE file for details
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Vulnerability Scanner?
Vulnerability Scanner is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Comprehensive vulnerability scanning for code, dependencies, and configurations with CVE detection
How do I install Vulnerability Scanner in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install vulnerability-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Vulnerability Scanner in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Vulnerability Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Vulnerability Scanner safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Copy Writes and audits the words inside products — buttons, error messages, empty states, tooltips, and onboarding flows. Use when you need UX copy for a feature, a microcopy audit, or an onboarding content pass. Trigger with \"write the UX copy\", \"audit the error messages\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Cost Optimize Optimize cloud costs and generate cost reports Slash Command · jeremylongshore/tons-of-skills-marketplace
- Cpu Usage Monitor Monitor and analyze CPU usage patterns in applications Plugin · jeremylongshore/tons-of-skills-marketplace
- Cortex Designs and ships production AI features — LLM integration, prompt engineering, RAG pipelines, evals, and MLOps. Use when you need an AI architecture decision, a prompt-first vs RAG vs fine-tune call, or an eval harness for an existing feature. Trigger with \"build this AI feature\", \"design the RAG pipeline\". Subagent · jeremylongshore/tons-of-skills-marketplace
- Wallet Portfolio Tracker Track crypto wallets across multiple chains with portfolio analytics and transaction history Plugin · jeremylongshore/tons-of-skills-marketplace
- Visual Regression Tester Visual diff testing with Percy, Chromatic, BackstopJS - catch unintended UI changes Plugin · jeremylongshore/tons-of-skills-marketplace
- Wallet Security Auditor Crypto wallet security auditor for reviewing wallet implementations, key management, signing flows, and common vulnerability patterns. Plugin · jeremylongshore/tons-of-skills-marketplace
- Vibe Guide Non-technical progress summaries for Claude Code work (hides diffs/log noise). Plugin · jeremylongshore/tons-of-skills-marketplace