# Security Scanner

> Use this tool when you need to identify security vulnerabilities in your codebase, such as hardcoded secrets, SQL injection, and authentication flaws. It analyzes JavaScript, TypeScript, Python, Java, and Go code through static analysis and specialized scanners, providing outputs that highlight potential security risks. Ideal for use during development and testing phases to ensure secure coding practices and prevent common web application vulnerabilities.

Canonical page: https://skillsregistry.net/skills/ongjin-security-scanner  
JSON: https://api.skillsregistry.net/v1/skills/ongjin-security-scanner

## Description

Analyzes code for security vulnerabilities through static analysis patterns and specialized scanners. Provides tools for detecting hardcoded secrets, SQL injection, XSS, command injection, path traversal, cryptographic weaknesses, and authentication flaws. Supports JavaScript, TypeScript, Python, Java (including Spring Boot), and Go codebases.

## Trust

- **Trust score (0–1):** 0.75
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/ongjin-security-scanner)
- **Repository:** <https://github.com/ongjin/security-scanner-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "ongjin-security-scanner"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/ongjin-security-scanner` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/ongjin-security-scanner/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
