Shield Security Orchestrator

Łączy Semgrep, gitleaks i npm audit w jeden punktowany raport bezpieczeństwa

Autor: alissonlinneker · alissonlinneker/shield-claude-skill

Testowano · Działa ★ 8.0/10

Shield Security Orchestrator — Łączy Semgrep, gitleaks i npm audit w jeden punktowany raport bezpieczeństwa

Co robi ten skill

Opakowuje Semgrep SAST, gitleaks secret scanning, package audits i dependency-freshness checks za jednym workflow, a następnie łączy wyniki każdego narzędzia w jeden normalised JSON, przypisuje SHIELD-XXX ids i oblicza 0-100 risk score z CWE i OWASP mapping. Uruchamia się, gdy user asks for a security scan, a vulnerability audit, a secrets check or a dependency CVE review before shipping. Full autonomous pentest mode additionally requires Docker i a local clone of the Shannon engine.

Raport z testu

Uruchomiono pełny bundled pipeline live against a deliberately vulnerable Express app: npm audit surfaced 9 vulnerable packages including a CRITICAL minimist prototype-pollution, i gitleaks pulled a Slack bot token out of a commit whose file had already been deleted from HEAD, neither of which is reachable by reading the working tree. The Semgrep layer is noisier: its catch-all NoSQL rule flagged app.listen(3000) as a HIGH CWE-943 injection and fired six times on ordinary Express calls, while the dedicated SQL-injection and path-traversal rules missed the real ones because the query was assigned to a variable first. Consolidation and scoring worked end to end (18 findings, 0/100 CRITICAL), although the false positives alone are enough to bottom out the score. The repo's own 61 unit tests all pass. The outdated checker reports every package as 'unknown' versions behind despite the docs promising major/minor/patch counts, and the plugin copy of SKILL.md points at a ${CLAUDE_SKILL_DIR} variable that does not exist in Claude Code.

Testowano: 2026-07-30 · Claude Code 2.x (agent harness)

Instalacja

git clone https://github.com/alissonlinneker/shield-claude-skill.git
mkdir -p ~/.claude/skills/shield
cd shield-claude-skill && cp -r SKILL.md scripts templates configs ~/.claude/skills/shield/

Komendy i przykładowe prompty

  • /shieldŁączy Semgrep, gitleaks i npm audit w jeden punktowany raport bezpieczeństwa

Skille uruchamiają się na zwykłe polecenia — bez komend do zapamiętania. Po instalacji aktywują go prompty takie jak te (po angielsku):

  • Scan this repo for security vulnerabilities before we deploy to production
  • Check if there are any hardcoded secrets or API keys in this codebase
  • Audit our npm dependencies for known CVEs and give me a risk score