Mmcp.market

security-scanning skill

by a5c-ai·a5c-ai/babysitter·1.8k stars·MIT

AgentShield security audit with 5 scanning categories, 102 static analysis rules, and optional red-team simulation.

A100/100content scan

Is the security-scanning skill safe?

Clean: nothing in its files matched our rules. We read 2 files in the folder on 2026-09-28.

No findings.

Install the security-scanning skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/a5c-ai/babysitter.git /tmp/babysitter
mkdir -p ~/.claude/skills
cp -r /tmp/babysitter/library/methodologies/everything-claude-code/skills/security-scanning ~/.claude/skills/security-scanning
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

  • AWS access keys (AKIA pattern)
  • GitHub tokens (ghp, gho, ghs, ghr)
  • Generic API keys and bearer tokens
  • Database connection strings with credentials
  • Private keys (RSA, EC, SSH)
  • JWT secrets and signing keys
  • OAuth client secrets
  • Slack tokens and webhooks
  • Cloud provider credentials (GCP, Azure)

2. Permission Auditing

  • File system read/write scope
  • Network calls and protocols
  • Process execution (child_process)
  • File permissions (777, world-writable)
  • CORS and CSP headers
  • Docker privilege escalation

3. Hook Injection Analysis

  • Git hooks for command injection
  • npm lifecycle scripts (preinstall, postinstall)
  • Claude Code hooks for unsafe patterns
  • eval()/Function()/dynamic code execution
  • Unvalidated user input in shell commands

4. MCP Risk Profiling

  • Tool permission inventory
  • Data exposure risk mapping
  • Transport security (stdio vs SSE vs HTTP)
  • Prompt injection via tool descriptions
  • Rate limiting verification

5. Agent Config Review

  • Model settings integrity
  • Prompt injection resistance
  • Tool allowlist scoping
  • Output validation and sanitization
  • Information leakage in error messages

Optional: Red Team Simulation

  • Attack simulation against found vulnerabilities
  • Exploitability rating: trivial, moderate, difficult, theoretical
  • Blue-team defense recommendations

When to Use

  • Pre-deployment security review
  • New dependency introduction
  • Hook or plugin configuration changes
  • Agent or MCP server setup

Agents Used

  • security-reviewer (primary consumer)

More skills from a5c-ai/babysitter

  • Aadversarial-reviewFresh adversarial code review with binary PASS/FAIL verdicts, evidence citations, and anchoring bias prevention via fresh reviewer spawning.
  • Aagent-boosterWASM-based instant code transforms for simple tasks, achieving 352x speedup over LLM inference with zero cost.
  • Aagent-coordinationCoordinate Crew (persistent) and Polecat (transient) agents using Gas Town's hook-based work distribution and GUPP principle.
  • Aagent-dispatch
  • Aanti-driftHierarchical coordination and drift detection with frequent checkpoints, shared memory coherence validation, role specialization enforcement, and short task cycles.
  • Aarchitecture-design
  • Aarchitecture-patternsSystem and API design guidance covering component boundaries, data flow, integration patterns, and scalability considerations.
  • Aassimilate-popular-workflowsThis skill should be used when the user asks to "find skills in the wild", "assimilate popular workflows", "discover SKILL.md files in repos", "research external skills", "find workflow patterns", "survey the skill landscape", "what skills exist out there", or wants to investigate public repositories for extractable processes, babysitter plugins, and reusable procedural insights. Searches GitHub for SKILL.md files, classifies repos by archetype, and maintains structured research under docs/reference-repos/.
  • Aaudit-trail
  • AbabysitOrchestrate via @babysitter. Use this skill when asked to babysit a run, orchestrate a process or whenever it is called explicitly. (babysit, babysitter, orchestrate, orchestrate a run, workflow, etc.)
  • Ababysit-babysitter-issuesThis skill should be used when the user asks to "babysit issues", "work on assigned issues", "check a5c-agent issues", "process babysitter issues", or wants to find and work on open GitHub issues assigned to a5c-agent in the babysitter repo.
  • Abehavior-contractBug condition/postcondition formalization as testable Behavior Contracts. Defines invariants that must be preserved across fixes.

All agent skills → · MCP servers