All skills
hardw00t avatar

/sca-security

@f9bb3b2

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sca-security

This session only. Nothing lands on disk.

referencesphp_composer.md

≈767 tokens on demand. Your agent reads this file only when SKILL.md points to it.

PHP / Composer Reference

Manifest + lockfile files

File Purpose
composer.json manifest
composer.lock lockfile
vendor/ installed deps
auth.json private registry creds (never commit)

SBOM generation

# CycloneDX Composer plugin
composer global require cyclonedx/cyclonedx-php-composer
composer CycloneDX:make-sbom --output-format=JSON --output-file=sbom.cdx.json

# Syft
syft dir:. -o cyclonedx-json=sbom.cdx.json

Vulnerability scanning

# Composer built-in (Composer >= 2.4)
composer audit
composer audit --format=json > audit.json
composer audit --locked                  # scan composer.lock

# Local PHP Security Checker (Symfony / FriendsOfPHP DB)
symfony security:check
# or standalone:
# https://github.com/fabpot/local-php-security-checker
local-php-security-checker

# OSV-Scanner
osv-scanner --lockfile=composer.lock

# Snyk
snyk test --file=composer.lock

Dependency inspection

composer show                        # flat
composer show --tree
composer show --outdated
composer why <vendor/pkg>            # who depends on this?
composer why-not <vendor/pkg> <ver>  # why can't I upgrade?

License extraction

composer licenses
composer licenses --format=json > licenses.json

Common vulnerability patterns

Class Example DB
Deserialization (unserialize) many FriendsOfPHP
SQL injection (raw PDO misuse) framework-specific FriendsOfPHP
Laravel RCE CVE-2024-52301 FriendsOfPHP
Symfony HTTP foundation bypass various FriendsOfPHP
Twig sandbox escape CVE-2022-23614 FriendsOfPHP
Guzzle cookie-jar issues various FriendsOfPHP

Vulnerability database: FriendsOfPHP

The authoritative PHP advisory DB: https://github.com/FriendsOfPHP/security-advisories

Maintained as YAML files keyed by package. Composer's built-in audit and local-php-security-checker both consume this feed. OSV also mirrors it.

Gotchas

  • composer.json "scripts" run during install/update — audit before enabling a new dep (equivalent to npm postinstall).
  • Private Packagist / Satis repos defined in composer.json "repositories" bypass default registry trust. Audit URL + auth.
  • Composer has no built-in package-signing; rely on HTTPS + vendor trust. Sigstore integration is not mainstream yet.
  • replace keyword in composer.json claims to provide another package — supply chain risk if misused to shadow legit packages.

Dependency confusion

PHP is especially exposed because:

  • composer.json repositories can include internal Satis URLs.
  • Resolver picks highest version across repos unless constrained.
  • Pin with:
{
  "repositories": [
    {"type": "composer", "url": "https://satis.internal.example.com"},
    {"packagist.org": false}
  ]
}

Disabling packagist.org ensures internal-only.

Tool minimums (2026-04)

  • PHP >= 8.2
  • Composer >= 2.7
  • local-php-security-checker >= 2.0
  • cyclonedx/cyclonedx-php-composer >= 5.0

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    A highly comprehensive and professional Software Composition Analysis (SCA) skill designed for auditing dependencies, generating SBOMs, and detecting supply chain attacks. The skill correctly identifies and provides detection workflows for sophisticated attack vectors such as typosquatting, dependency confusion, and malicious install scripts. No malicious patterns or security risks were detected in the skill's own operation.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sca-security