ghost-scan-code

ghost scan code

ghostsecurity ↓ 3.2k
Claude Code
View source ↗

What it does

  • depth: quick (default), balanced, or full — override via $ARGUMENTS
  • Loop script: scripts/loop.sh
  • Scan criteria: criteria/index.yaml
  • arguments: <relevant argument overrides if any, otherwise omit>" 1 $cachedir
  • [ ] <basepath> (<type>) | <agent> | <vector>
  • [ ] <basepath> (<type>) | <agent> | <vector>
  • arguments: <relevant argument overrides if any, otherwise omit>" 5 $cachedir

Requirements & configuration

Configuration: ARGUMENTSHOME

Derived from the skill's own SKILL.md documentation · extracted 2026-07-23

ghost scan code

Source

Repository: https://github.com/ghostsecurity/skills

ghost-scan-code FAQ

What does the ghost-scan-code skill do?

Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS, BOLA, BFLA, SSRF, and other OWASP categories. Supports applications (backend, frontend, mobile) and libraries (prototype pollution, unsafe deserialization, ReDoS, path traversal, zip slip). Use when the user asks for a code security audit, SAST scan, vulnerability scan of source code, or wants to find security flaws in a codebase or library. depth: quick (default), balanced, or full — override via $ARGUMENTS Loop script: scripts/loop.sh

How do I install ghost-scan-code?

Run: npx -y skills add https://github.com/ghostsecurity/skills --skill ghost-scan-code --agent claude-code — the source lives at github.com/ghostsecurity/skills.

Maintain ghost-scan-code?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

[ghost-scan-code on getagentictools](https://getagentictools.com/skills/ghostsecurity-skills-ghost-scan-code?ref=badge)
npx agentictools info skills/ghostsecurity-skills-ghost-scan-code

The second line is the CLI lookup for this page — handy in READMEs and docs.