Screened · automated checks passed

ghost-scan-code

from ghostsecurity/skills · ★ 398 on GitHub · found by our crawler 2026-07-07

What the author says it does

Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS, BOLA, BFLA, SSRF, and other OWASP categories. Supports applications (backend, frontend, mobile) and libraries (prototype pollution, unsafe deserialization, ReDoS, path traversal, zip slip). Use when the user asks for a code security audit, SAST scan, vulnerability scan of source code, or wants to find security flaws in a codebase or library.

Quoted from the skill's own SKILL.md trigger description — this is what tells Claude when to activate it. Not yet verified by us.

Automated screening

90/100 validator score

Scored by the same rules as our free SKILL.md validator: trigger description quality, body substance, structure. Automated — a human bench test is the next step in the pipeline.

Install (unverified — review first)

git clone https://github.com/ghostsecurity/skills
# skill lives at: plugins/ghost/skills/scan-code/SKILL.md

SkillProof status

This skill is in our test queue. We install every skill in a clean environment, run a trigger battery and score output against a baseline before it earns a catalog page — the full protocol is public. Until then, treat it like any unreviewed dependency: read the SKILL.md and any scripts before installing.

Already tested in Design & Frontend

  • Codex GPT Image ★ 10.0/10 Generates gpt-image-2 images via local Codex OAuth, no OPENAI_API_KEY needed.
  • Slide Wright ★ 10.0/10 Proposes an invented theme and a real 2-slide preview before it ever builds the full deck.
  • Compose App Icon ★ 10.0/10 uv-bundled CLI pair that authors and JSON-Schema-validates Apple Icon Composer .icon packages
  • HTML Explainer ★ 10.0/10 Builds polished, source-grounded, playable single-page or slide-deck web explainers with a real quality loop.

Top 10 Design skills, ranked →