ZooWork Market · Skill
local-security-scan
This skill should be used when the user asks to "scan for security issues", "check for CVEs", "look for secrets", "run a SAST scan", "security review this project", "check for vulnerabilities", "audit this code for security", or similar explicit scan phrasing against a concrete project. Runs three local scanners (Semgrep, Gitleaks, OSV-Scanner), writes JSON reports to <project>/.sec-scan/, and produces a prioritized fix list. Primarily local — code never leaves the machine; Semgrep downloads rule packs once and caches. Do NOT activate for conceptual security questions or general code review without an explicit scan request.