All skills
hardw00t avatar

/sca-security

@f9bb3b2

Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to suppress unexploitable findings. Use when scanning package dependencies (npm, PyPI, Maven, Cargo, Go, RubyGems, Composer), reviewing PR lockfile diffs, generating SBOMs, auditing licenses, hunting malicious packages, or auditing the software supply chain. Triggers on requests to scan dependencies, check vulnerable packages, generate SBOM, license compliance, typosquat/dependency-confusion review, or reachability-based vuln triage.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sca-security

This session only. Nothing lands on disk.

templatessca_report.md

≈505 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Software Composition Analysis Report

Executive Summary

  • Project: <name>
  • Commit / tag scanned: <sha> / <tag>
  • Scan date: YYYY-MM-DD
  • SBOM format: CycloneDX 1.6 (attached)
  • Total components: X (direct: Y, transitive: Z)
  • Findings by severity: Critical (C) / High (H) / Medium (M) / Low (L)
  • Findings by reachability: Reachable (R) / Unreachable (U) / Unknown (?)
  • License: permissive (P) / copyleft-weak (W) / copyleft-strong (S) / denied (D) / unknown (?)

Reachable + exploitable (P0)

# Pkg Version CVE GHSA CVSS EPSS KEV Fixed Reachable symbol Reason
1 lodash 4.17.20 CVE-2021-23337 GHSA-35jh-r3h4-6jhm 7.2 0.62 no 4.17.21 template() at src/email/renderer.ts:42 user-controlled subject

Reachable (P1/P2)

# Pkg Version CVE Severity Fixed Call sites

Unreachable (P3 — backlog)

# Pkg Version CVE Severity Fixed Notes

License violations

# Pkg Version License Policy Action

Supply chain flags

# Pkg Indicator Confidence Evidence

SBOM

  • CycloneDX: sbom.cdx.json (attached)
  • SPDX: sbom.spdx.json (attached, optional)

Remediation plan

Priority Action Owner Due
P0 Upgrade lodash 4.17.20 → 4.17.21 <team> immediate
P1 Replace GPL-licensed foo <team> 30d
P2 Enforce --ignore-scripts in CI <team> 60d

Methodology

Tools used (with versions): syft 1.14, grype 0.87, osv-scanner 2.1, govulncheck 1.1, codeql <ver>, ...

SBOM generated per workflows/sbom_generation.md; vuln correlation per workflows/vuln_correlation.md; reachability per workflows/reachability_analysis.md.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    A highly comprehensive and professional Software Composition Analysis (SCA) skill designed for auditing dependencies, generating SBOMs, and detecting supply chain attacks. The skill correctly identifies and provides detection workflows for sophisticated attack vectors such as typosquatting, dependency confusion, and malicious install scripts. No malicious patterns or security risks were detected in the skill's own operation.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer7mo

    1/1 file flagged

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sca-security