SkillsLib.ai

Owasp Security Scanner

Scan codebases for OWASP Top 10 vulnerabilities with severity ratings and remediation code

4.4(49 reviews)
500+ downloads
Updated Sep 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

You can submit codebases in Python, JavaScript/Node.js, Java, PHP, Go, Ruby, or C# for comprehensive vulnerability scanning. Claude identifies specific vulnerability instances with line numbers, assigns severity ratings (Critical to Low) based on exploitability, and generates secure code alternatives. The skill produces structured reports prioritized by risk, complete with root cause analysis and testing recommendations.

Features

OWASP Top 10 vulnerability detection

scans for all nine categories including injection, broken access control, and cryptographic failures

Multi-language support

analyzes Python, JavaScript, Java, PHP, Go, Ruby, and C# codebases with language-specific pattern recognition

Severity-based prioritization

assigns Critical/High/Medium/Low ratings based on actual exploitability and business impact

Remediation code generation

produces secure code alternatives for each vulnerability with explanations

Context-aware reporting

includes line numbers, code snippets, and root cause analysis for each finding

Authentication & session analysis

detects weak password logic, session hijacking vulnerabilities, and token bypass issues

Dependency risk assessment

identifies known vulnerable components and supply chain risks

Testing recommendations

suggests specific test cases and validation approaches for each vulnerability

Example Output

Critical Vulnerability: SQL Injection (A03) Line 47 in user_handler.py

code
# UNSAFE
query = f"SELECT * FROM users WHERE id = {user_id}"

# REMEDIATED
query = "SELECT * FROM users WHERE id = %s"
cursor.execute(query, (user_id,))

High Vulnerability: Broken Authentication (A07) Line 123 in auth.js

code
// UNSAFE: Password stored in plaintext
users[email] = password;

// REMEDIATED: Use bcrypt with salt
const hashedPassword = await bcrypt.hash(password, 10);
users[email] = hashedPassword;

Medium Vulnerability: Security Misconfiguration (A05) Debug mode enabled in production configuration — recommend disabling debug flags and removing console logging with sensitive data.

What's Included

  • SKILL.md: complete OWASP Security Scanner instruction file with vulnerability scope
  • Vulnerability Checklist: reference guide mapping OWASP Top 10 to detection patterns
  • Remediation Code Templates: secure coding examples for each vulnerability category in common languages
  • Report Template: structured markdown template for organizing findings by severity and category
  • Testing Recommendations Framework: security test cases and validation strategies for each vulnerability type

Who It's For

  • Security Engineers — perform systematic code audits and vulnerability assessments
  • Application Developers — identify and remediate security flaws during development
  • DevSecOps Teams — integrate vulnerability scanning into CI/CD pipelines
  • Security Architects — analyze codebase risk and enforce security standards
  • Code Reviewers — augment manual review with automated OWASP-focused scanning

Best For

  • Codebase security audits before production deployment
  • OWASP Top 10 compliance verification and remediation tracking
  • Legacy code security assessment and modernization planning
  • Security training and vulnerability pattern identification
  • Pre-penetration test vulnerability discovery and scoping

You might also like

Site Monitoring Compliance & Deviation Auditor
$45
Site Monitoring Compliance & Deviation Auditor

This skill enables you to automatically audit your websites against compliance standards and detect deviations from expected baselines. You can track regulatory requirements, identify policy violations, and generate compliance reports with actionable remediation steps. Monitor multiple sites simultaneously and maintain detailed audit trails for compliance documentation.

Chemical Process Safety Analyzer
$40
Chemical Process Safety Analyzer

Analyze chemical processes systematically to identify hazards, assess risks, and generate safety recommendations. You can perform HAZOP analyses, evaluate compliance with industry standards, conduct root-cause analysis of incidents, and develop emergency response procedures. The skill guides you through structured safety reviews that reduce the likelihood of accidents and regulatory violations.

Injectable Formulation Development & Troubleshooting
$40
Injectable Formulation Development & Troubleshooting

You'll develop systematic approaches to injectable formulation design, from API selection through sterilization strategy. Claude helps you troubleshoot failed batches by analyzing root causes, recommends regulatory pathways (505(b)(2), ANDA, NDA), and provides science-backed solutions for stability, compatibility, and manufacturability challenges.

Chemical Process Hazard Analysis and Control Design
$30
Chemical Process Hazard Analysis and Control Design

You can conduct comprehensive hazard analyses for chemical processes using industry-standard methodologies like HAZOP and LOPA. The skill helps you assess risks quantitatively, identify control gaps, design engineered safeguards, and generate formal documentation for regulatory compliance and process safety management.

Git Commit Message Writer
$45
CI/CD4.3(47)
Git Commit Message Writer

Claude analyzes your code diffs and generates standardized commit messages that follow the Conventional Commits specification. The skill automatically determines the correct commit type, scope, and description based on the changes you've made, ensuring your messages are parseable by automation tools while remaining human-readable for code reviewers.

Structured NLP Analysis and Annotation with Claude
$35
NLP3.3(6)
Structured NLP Analysis and Annotation with Claude

You can transform raw text into structured, labeled datasets for machine learning, analysis, and research. This skill performs named entity recognition, sentiment classification, part-of-speech tagging, and dependency parsing—generating consistent, validated annotations at scale. Use it to prepare corpora, extract entities, classify documents, or perform linguistic analysis without manual annotation.

Production ML Deployment Validation & Runbook Automation
$25
Production ML Deployment Validation & Runbook Automation

This skill automates the creation of production-ready deployment validation checklists, infrastructure-as-code templates, and incident response runbooks tailored to your ML stack. You get comprehensive pre-deployment checks covering model validation, data pipeline integrity, infrastructure readiness, and monitoring setup—all customized for your specific models and cloud provider. The skill generates executable runbooks that teams can follow during incidents, including rollback procedures, failover strategies, and diagnostic commands.

IoT Firmware Analysis & Device Debugger
$40
IoT Firmware Analysis & Device Debugger

Rapidly analyze firmware logs and diagnose hardware issues that cause device failures, connectivity problems, and performance degradation. You'll identify root causes from stack traces, crash dumps, and sensor data, then generate specific optimization recommendations. This skill transforms raw device logs into actionable debugging plans that reduce time-to-resolution from hours to minutes.

$30.00