🛡️
QualityPython

CVE Scan

by softspark

CVE Scan is a Quality skill for Claude Code, published by softspark in ai-toolkit.

170 stars20 forkson softspark/ai-toolkitAdded 2026/09/08+2% in starsRepository updated 2026/09/07
ai-agentsai-skillsanthropicclaudeclaude-codeclinecodexcopilotcursorgeminimcpopencodetoolkitwindsurf
Install in seconds
Install CVE Scan
Copy CVE Scan into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/softspark/ai-toolkit/tree/main/app/skills/cve-scan ~/.claude/skills/cve-scan

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/softspark/ai-toolkit.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
app/skills/cve-scan/SKILL.md in softspark/ai-toolkit
Installs to
~/.claude/skills/cve-scan
Collection
One of 25 skills cataloged from this repository
Category
Quality1897 skills

What CVE Scan does

CVE Scan detects project ecosystems and runs native audit tools to report known dependency vulnerabilities. Use it to check npm, pip, Cargo, Go, Composer, Bundler, or Dart projects and optionally auto-fix supported issues.

CVE Scan is cataloged under Quality on DirSkills. CVE Scan comes from a repository tagged ai-agents, ai-skills, anthropic, claude and claude-code.

Documentation

README

/cve-scan - Dependency CVE Scanner

$ARGUMENTS

Detect project ecosystems and scan dependencies for known vulnerabilities using native audit tools. Zero external dependencies — uses tools already installed in the project environment.

Usage

/cve-scan                        # Auto-detect all ecosystems, scan all
/cve-scan --ecosystem npm        # Force specific ecosystem
/cve-scan --fix                  # Auto-fix where possible (npm audit fix, etc.)
/cve-scan --json                 # Machine-readable JSON output

This is the opening of the README. Read the full README on GitHub.

Commands CVE Scan provides

Slash commands named in this skill’s SKILL.md, listed in the order they first appear.

  • /cve-scan

Frequently asked about CVE Scan

  • What else does softspark publish alongside CVE Scan?

    CVE Scan is one of 25 skills that DirSkills catalogs from softspark/ai-toolkit, the repository it ships in. Its siblings there include API Patterns, Accessibility Validator and Agent Creator. Each one is a separate skill with its own page in this directory, installs the same way CVE Scan does, and is maintained by softspark in that same repository. The rest of the collection is listed on the softspark/ai-toolkit page.

  • How does CVE Scan compare to other Quality skills?

    CVE Scan ranks #1754 by stars among the 1897 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of CVE Scan against them. Open each page to compare what they document and how they install.

More from softspark/ai-toolkit

CVE Scan is one of 25 skills cataloged on DirSkills from softspark/ai-toolkit.

See all 25 skills
🔌
1h ago

API Patterns

API Patterns covers REST and GraphQL API design, including resource naming, versioning, pagination, idempotency, OpenAPI, error contracts, and safe retries. Use it when designing or reviewing API endpoints and failure responses.
AI Engineering
17020
1h ago

Accessibility Validator

Accessibility Validator scans a codebase for WCAG 2.1 AA, EN 301 549, and EAA issues without changing files. Use it to check contrast, keyboard support, ARIA, media, forms, and accessibility-statement compliance.
Quality
17020
🤖
1h ago

Agent Creator

Agent Creator creates new specialized agents with frontmatter, tools, model choice, and delegated skills. Use it when defining a new agent, routing triggers, or validating an agent scaffold.
AI Engineering
17020
🧩
1h ago

App Builder

App Builder scaffolds new projects for web, mobile, API, CLI, and AI apps using stacks like Next.js, Vite, Nuxt, Astro, FastAPI, Django, Laravel, React Native, and Flutter. Use it when starting a new app or choosing a starter architecture.
Automation
17020
🏗️
1h ago

Architecture Audit

Architecture Audit explores a codebase for architectural friction, shallow modules, and tight coupling. It surfaces candidates, compares interface designs, and files an RFC issue when you need to deepen a module boundary.
Quality
17020
🏗️
1h ago

Architecture Decision

Architecture Decision documents ADR, RFC, or RFD choices with context, constraints, options, trade-offs, recommendation, and consequences. Use it when deciding between architectural approaches or recording why a choice was made.
Writing
17020