Security Scan
技能 已验证 活跃Run full security scans on the codebase using Ruflo security tools
To provide developers with a reliable and configurable tool for identifying security vulnerabilities and CVEs within their codebase, ensuring a more secure software development lifecycle.
功能
- Run full security scans
- Select scan depth (quick, standard, full)
- Check for known CVEs
- Identify input validation and path traversal issues
- Store scan findings via MCP
使用场景
- Integrate security scanning into CI/CD pipelines
- Proactively identify and remediate vulnerabilities before deployment
- Perform in-depth security audits of codebases
- Ensure compliance with security best practices
非目标
- Performing dynamic application security testing (DAST)
- Acting as a runtime security monitor
- Remediating vulnerabilities automatically
工作流
- Specify scan depth (quick, standard, or full)
- Execute scan using `npx @claude-flow/cli@latest security scan --depth DEPTH`
- Optionally run specific checks like `security cve --check`
- Generate a markdown report using `security report --format markdown`
- Store findings via MCP using `memory_store`
- Train post-task hooks upon successful completion
实践
- Security Auditing
- Vulnerability Management
- Code Quality Assurance
先决条件
- Node.js and npm/npx installed
- Claude Code environment
安装
请先添加 Marketplace
/plugin marketplace add ruvnet/ruflo/plugin install ruflo-security-audit@ruflo质量评分
已验证类似扩展
Semgrep Rule Creator
100Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.
Github
100Use gh for GitHub issues, PR status, CI/logs, comments, reviews, releases, and API queries.
Cli Creator
100Build a composable CLI for Codex from API docs, an OpenAPI spec, existing curl examples, an SDK, a web app, an admin tool, or a local script. Use when the user wants Codex to create a command-line tool that can run from any repo, expose composable read/write commands, return stable JSON, manage auth, and pair with a companion skill.
Migrate Validate
100Validate pending migrations for foreign key consistency, rollback safety, and best practices
Moyu (摸鱼)
100감지된 과잉 엔지니어링 패턴: (1) 사용자가 명시적으로 요청하지 않은 코드나 파일을 수정할 때 (2) 요청되지 않은 새로운 추상화 계층(클래스, 인터페이스, 팩토리, 래퍼)을 생성할 때 (3) 요청되지 않은 주석, 문서, JSDoc, 타입 주석을 추가할 때 (4) 요청되지 않은 새로운 종속성을 도입할 때 (5) 최소 편집 대신 파일 전체를 다시 작성할 때 (6) diff 범위가 사용자의 요청을 명백히 초과할 때 (7) 사용자가 "너무 많아", "거기는 건드리지 마", "X만 변경해", "간단하게", "그만"과 같은 신호를 보낼 때 (8) 발생할 수 없는 시나리오에 대한 오류 처리, 유효성 검사, 방어적 코드를 추가할 때 (9) 요청되지 않은 테스트, 설정 스캐폴딩, 문서를 생성할 때
Safe Mode
100Prevent destructive operations using Claude Code hooks. Three modes — cautious (warn on dangerous commands), lockdown (restrict edits to one directory), and clear (remove restrictions). Uses PreToolUse matchers for Bash, Edit, and Write.