warden-scan
Automated SAST + dependency vulnerability scan. Runs Semgrep (code vulnerabilities) and pip-audit (CVE-matched dependencies) and writes a structured JSON report. Use when asked to "scan for vulnerabilities", "run a security scan", "check for CVEs", or "audit dependencies".
What this skill does
# Warden Scan — Automated SAST + Dependency Audit
You are Warden. Run a real security scan using Semgrep and pip-audit, then display the findings.
## Step 1: Locate the scanner
Find the scan.py entry point:
```bash
find . -path "*/warden_agent/scan.py" -not -path "*/__pycache__/*" 2>/dev/null | head -3
```
If not found, tell the user:
> `scan.py` not found. Run `pip install semgrep pip-audit` and ensure the tonone plugin is installed.
## Step 2: Determine target
If the user specified a path, use it. Otherwise use `.` (current directory).
## Step 3: Run the scan
```bash
python <path-to-scan.py> <target> --out .reports/warden-latest.json
```
The script:
- Runs Semgrep SAST (`semgrep --config auto`)
- Runs pip-audit on `requirements*.txt` files (falls back to current env)
- Writes a JSON report and prints a summary line
Capture stdout + stderr. If the script exits with code 2, that means critical/high findings were found (expected, not an error).
## Step 4: Display results
Parse and render the report using the tonone output kit format (40-line CLI budget, box-drawing skeleton):
```
┌─────────────────────────────────────────────┐
│ warden-scan <target> │
└─────────────────────────────────────────────┘
CRITICAL <N> HIGH <N> MEDIUM <N> LOW <N>
── SAST Findings ───────────────────────────────
[C] <title> <location>
<detail — 1 line>
Fix: <recommendation>
[H] <title> <location>
<detail — 1 line>
Fix: <recommendation>
── Dependency Findings ─────────────────────────
[H] <CVE-ID> in <pkg>==<ver> <requirements-file>
Fix: <recommendation>
── Summary ─────────────────────────────────────
Report: .reports/warden-latest.json
```
Severity indicators: `[C]` critical, `[H]` high, `[M]` medium, `[L]` low.
Show all CRITICAL and HIGH findings. Collapse MEDIUM/LOW into a count if there are more than 5.
If 0 findings: show a clean pass banner.
## Step 5: Exit guidance
If critical or high findings exist, end with:
> **Action required.** Review findings above. Run `/warden-harden` for remediation steps or `/warden-threat` for a full threat model.
If only medium/low:
> **Passed with warnings.** No critical issues found. Consider `/warden-audit` for a broader manual review.
If clean:
> **Clean scan.** No issues found by Semgrep or pip-audit.
Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose. If findings exceed 40 lines, emit a summary table and invoke `/atlas-report` to write the full report.
Related in Security
mac-ops
IncludedComprehensive macOS workstation operations — diagnose kernel panics, identify failing drives, audit launchd startup items, decode wake reasons, triage TCC permission denials, manage APFS snapshots, recover from no-boot. Use for: Mac is slow, slow bootup, won't boot, kernel panic, kernel_task hot, mds_stores CPU, photoanalysisd, cloudd, login loop, gray screen, sleep wake failure, drive failing, IO errors, APFS snapshots eating space, Time Machine local snapshots, Spotlight indexing, launchd, LaunchAgent, LaunchDaemon, login items, TCC permissions, Full Disk Access, Screen Recording denied, Gatekeeper, quarantine, com.apple.quarantine, app is damaged, helper tool, /Library/PrivilegedHelperTools, pmset, wake reasons, dark wake, sysdiagnose, panic.ips, DiagnosticReports, configuration profile, MDM profile, remote diagnostics over SSH.
a11y-audit
IncludedRun accessibility audits on web projects combining automated scanning (axe-core, Lighthouse) with WCAG 2.1 AA compliance mapping, manual check guidance, and structured reporting. Output is configurable: markdown report only, markdown plus machine-readable JSON, or markdown plus issue tracker integration. Use this skill whenever the user mentions "accessibility audit", "a11y audit", "WCAG audit", "accessibility check", "compliance scan", or asks to check a web project for accessibility issues. Also trigger when the user wants to verify WCAG conformance or map findings to a specific standard (CAN-ASC-6.2, EN 301 549, ADA/AODA).
erpclaw
IncludedAI-native ERP system with self-extending OS. Full accounting, invoicing, inventory, purchasing, tax, billing, HR, payroll, advanced accounting (ASC 606/842, intercompany, consolidation), and financial reporting. 413 actions across 14 domains, 43 expansion modules. Constitutional guardrails, adversarial audit, schema migration. Double-entry GL, immutable audit trail, US GAAP.
assess
IncludedAssesses and rates quality 0-10 across multiple dimensions (correctness, maintainability, security, performance, testability, simplicity) with pros/cons analysis. Compares against project conventions and prior decisions from memory. Produces structured evaluation reports with actionable improvement suggestions. Use when evaluating code, designs, architectures, or comparing alternative approaches.
spring-boot-security-jwt
IncludedProvides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
code-hardcode-audit
IncludedDetect hardcoded values, magic numbers, and leaked secrets. TRIGGERS - hardcode audit, magic numbers, PLR2004, secret scanning.