Vulnerability Scanning & Assessment
Audits dependency manifests and server configs for CVEs, scores them with CVSS/EPSS/KEV, and produces a prioritized remediation report.
Security & ReviewIntermediate★ 460⑂ 87AI score 9/10Last updated: Sep 7, 2026
What it does
- Parses
requirements.txt,package.json,go.mod,pom.xml,Cargo.toml, lockfiles and more to map each package+version to known CVEs. - Audits nginx, sshd_config, Dockerfile and Kubernetes manifests against concrete hardening checklists.
- Calculates CVSS v3.1/4.0 scores and vectors, then re-ranks findings using EPSS exploit probability and CISA KEV membership.
- Consumes Nmap output to map service versions to CVEs and suggests targeted NSE scripts for deeper checks.
- Emits a structured report: executive summary, severity table, per-finding detail (CVE, evidence, safe version), and a remediation roadmap. Also covers SBOM/VEX and reachability analysis.
Who it's for
- Security engineers, pentesters, and DevSecOps practitioners.
- Developers who want recurring dependency risk checks on their own repos.
- Infra owners reviewing container and server hardening.
Example uses
- "Audit this package.json and list only high/critical issues with minimum safe versions."
- "Review my nginx.conf" → flags legacy TLS, missing HSTS/CSP, exposed server tokens.
- "Score AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H and explain the patch priority."
· · · Install guide · · ·
Try it now, no install
Paste this into Claude to use the skill without installing anything.
Read the instructions in this file and follow them to help me: https://raw.githubusercontent.com/Masriyan/Claude-Code-CyberSecurity-Skill/HEAD/skills/02-vulnerability-scanner/SKILL.md What I want: (describe your task here)
If Claude can't open the link, open it yourself and paste the contents instead.
↓ If it works for you, download the ZIP below and install it. Then it runs on its own — no pasting each time.
Install in the Claude app (no terminal)
- Download the ZIP with the button below.
- In Claude, open Settings → Capabilities and turn on 'Code execution and file creation'. (one time)
- Go to Customize → Skills → + → 'Upload a skill' and upload the ZIP.
Install in Claude Code
Let Claude do it — paste this into Claude Code
Install the skill I found on Claude Skill Mart. Copy the skills/02-vulnerability-scanner folder from the GitHub repo Masriyan/Claude-Code-CyberSecurity-Skill into my ~/.claude/skills/vulnerability-scanning-assessment/. When it's done, tell me in one line what this skill can do.
Install with a command instead
git clone https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill.git /tmp/cc-cybersec && mkdir -p ~/.claude/skills && cp -r /tmp/cc-cybersec/skills/02-vulnerability-scanner ~/.claude/skills/vulnerability-scanner⚠ This is a third-party skill. Check the source repository before installing.
- Open a terminal and cd into a working directory.
- Clone the repo:
git clone https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill.git - Copy the skill into Claude's skills folder:
mkdir -p ~/.claude/skills && cp -r Claude-Code-CyberSecurity-Skill/skills/02-vulnerability-scanner ~/.claude/skills/vulnerability-scanner - Install Python dependencies:
pip install requests packaging jinja2 pyyaml - Optional: install
trivy,nuclei, ornmapfor deeper scanning. - Restart Claude Code and try: "Audit the dependencies in this requirements.txt."
- Important: only run network scans against systems you own or have written authorization to test.
View source on GitHub ↗License: MIT