Research: security-scanner

Cached research evidence for security-scanner (not authority).

Back to catalog page

Problem: Proactive security assessment with SAST, secrets detection, dependency scanning, and compliance checks. Use for pre-deployment audit. NOT for code review (review) or pen testing.

Stack / assumptions: portable skill scripts under scripts/; on-demand references; eval fixtures

Comparable alternative: review for code review

Repo summary:

Proactive pre-deployment security assessment. SAST pattern matching, secrets detection, dependency scanning, OWASP/CWE mapping, and compliance heuristics.

> Grounded in repository skills/security-scanner/SKILL.md; treat as evidence, not authority.