snyk

GitHub

用于运行 Snyk 安全扫描,检查依赖漏洞和源代码安全问题。通过优先级排序生成修复计划,协助用户解决关键和高危风险,确保项目安全性。

.claude/skills/snyk/SKILL.md slackapi/slack-cli

Trigger Scenarios

需要检查项目依赖或代码的安全漏洞 执行月度安全审查 发现新的潜在安全风险

Install

npx skills add slackapi/slack-cli --skill snyk -g -y
More Options

Non-standard path

npx skills add https://github.com/slackapi/slack-cli/tree/main/.claude/skills/snyk -g -y

Use without installing

npx skills use slackapi/slack-cli@snyk

指定 Agent (Claude Code)

npx skills add slackapi/slack-cli --skill snyk -a claude-code -g -y

安装 repo 全部 skill

npx skills add slackapi/slack-cli --all -g -y

预览 repo 内 skill

npx skills add slackapi/slack-cli --list

SKILL.md

Frontmatter
{
    "name": "snyk",
    "description": "Run Snyk security scans to find dependency vulnerabilities and source code issues. Use for monthly security reviews or when checking for new vulnerabilities."
}

Run a Snyk security scan on this project.

1. Check prerequisites

Run which snyk to verify Snyk is installed. If not found, tell the user to install it with brew install snyk or npm install -g snyk.

Run snyk auth check or snyk whoami to verify authentication. If not authenticated, tell the user to run ! snyk auth to log in interactively.

2. Run snyk test (dependency vulnerabilities — primary scan)

Run snyk test to scan Go module dependencies for known vulnerabilities.

This is the most important scan. Summarize the results:

  • Group vulnerabilities by severity: Critical > High > Medium > Low
  • For each vulnerability, note:
    • The affected package and version
    • Whether a fix is available (upgrade path exists) or requires waiting on the upstream maintainer
  • For fixable issues, propose the specific go get upgrade commands
  • For unfixable issues, note them as "waiting on upstream" — these are deferred

3. Run snyk code test (source code analysis — secondary scan)

Run snyk code test to scan the project's own Go source code for security issues.

This scan is optional and secondary. Summarize the results:

  • Group findings by severity
  • Identify which issues are simple/quick to fix vs. complex
  • Focus on simple fixes that can be resolved quickly

4. Present a prioritized action plan

Combine both scan results into a single prioritized plan:

  1. Fix now — dependency upgrades with available fixes (propose commands)
  2. Fix now — simple source code issues from snyk code test
  3. Defer — dependency vulnerabilities waiting on upstream fixes
  4. Defer — complex source code issues that need more investigation

Ask the user which items they'd like to tackle, then help resolve them.

Version History

  • 2369f3e Current 2026-07-25 08:42

Same Skill Collection

.claude/skills/record-demo/SKILL.md

Metadata

Files
0
Version
b5982b9
Hash
39aa7177
Indexed
2026-07-25 08:42

inicio - Wiki
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-22 05:40
浙ICP备14020137号-1 $mapa de visitantes$