security-analyzer

Comprehensive security vulnerability analysis for codebases and infrastructure. Scans dependencies (npm, pip, gem, go, cargo), containers (Docker, Kubernetes), cloud IaC (Terraform, CloudFormation), and detects secrets exposure. Fetches live CVE data from OSV.dev, calculates risk scores, and generates phased remediation plans with TDD validation tests. Use when users mention security scan, vulnerability, CVE, exploit, security audit, penetration test, OWASP, hardening, dependency audit, container security, or want to improve security posture.

$ Installieren

git clone https://github.com/Cornjebus/security-analyzer /tmp/security-analyzer && cp -r /tmp/security-analyzer/.claude/skills/security-analyzer ~/.claude/skills/security-analyzer

// tip: Run this command in your terminal to install the skill