
Owasp Security Scanner
Scan codebases for OWASP Top 10 vulnerabilities with severity ratings and remediation code
What You Can Do
You can submit codebases in Python, JavaScript/Node.js, Java, PHP, Go, Ruby, or C# for comprehensive vulnerability scanning. Claude identifies specific vulnerability instances with line numbers, assigns severity ratings (Critical to Low) based on exploitability, and generates secure code alternatives. The skill produces structured reports prioritized by risk, complete with root cause analysis and testing recommendations.
Features
scans for all nine categories including injection, broken access control, and cryptographic failures
analyzes Python, JavaScript, Java, PHP, Go, Ruby, and C# codebases with language-specific pattern recognition
assigns Critical/High/Medium/Low ratings based on actual exploitability and business impact
produces secure code alternatives for each vulnerability with explanations
includes line numbers, code snippets, and root cause analysis for each finding
detects weak password logic, session hijacking vulnerabilities, and token bypass issues
identifies known vulnerable components and supply chain risks
suggests specific test cases and validation approaches for each vulnerability
Example Output
Critical Vulnerability: SQL Injection (A03)
Line 47 in user_handler.py
# UNSAFE
query = f"SELECT * FROM users WHERE id = {user_id}"
# REMEDIATED
query = "SELECT * FROM users WHERE id = %s"
cursor.execute(query, (user_id,))
High Vulnerability: Broken Authentication (A07)
Line 123 in auth.js
// UNSAFE: Password stored in plaintext
users[email] = password;
// REMEDIATED: Use bcrypt with salt
const hashedPassword = await bcrypt.hash(password, 10);
users[email] = hashedPassword;
Medium Vulnerability: Security Misconfiguration (A05) Debug mode enabled in production configuration — recommend disabling debug flags and removing console logging with sensitive data.
What's Included
- SKILL.md: complete OWASP Security Scanner instruction file with vulnerability scope
- Vulnerability Checklist: reference guide mapping OWASP Top 10 to detection patterns
- Remediation Code Templates: secure coding examples for each vulnerability category in common languages
- Report Template: structured markdown template for organizing findings by severity and category
- Testing Recommendations Framework: security test cases and validation strategies for each vulnerability type
Who It's For
- Security Engineers — perform systematic code audits and vulnerability assessments
- Application Developers — identify and remediate security flaws during development
- DevSecOps Teams — integrate vulnerability scanning into CI/CD pipelines
- Security Architects — analyze codebase risk and enforce security standards
- Code Reviewers — augment manual review with automated OWASP-focused scanning
Best For
- Codebase security audits before production deployment
- OWASP Top 10 compliance verification and remediation tracking
- Legacy code security assessment and modernization planning
- Security training and vulnerability pattern identification
- Pre-penetration test vulnerability discovery and scoping







