ClaudeSuperPower

app-security-scan

Skill

DAST-first NightVision scan for an app you just built or changed. Use when a user (or an org CLAUDE.md rule) wants a local, private, staging, or internal web app/API security-scanned. Drives the NightVision MCP `run-app-security-scan` harness.

Install

git clone https://github.com/nvsecurity/nightvision-skills.git ~/.claude/skills/app-security-scan

What is app-security-scan?

DAST-first NightVision scan for an app you just built or changed. Use when a user (or an org CLAUDE.md rule) wants a local, private, staging, or internal web app/API security-scanned. Drives the NightVision MCP `run-app-security-scan` harness.

What this can do

Capabilities declared in this component's own frontmatter — not inferred.

Run shell commands

Declares Bash

~61 tokens of context used while enabled, before you invoke anything

All declared tools (10)
BashGrepReadmcp__nightvision__auth-statusmcp__nightvision__export-sarifmcp__nightvision__get-scan-statusmcp__nightvision__preflight-appmcp__nightvision__run-app-security-scanmcp__nightvision__summarize-scan-findingsmcp__nightvision__wait-for-scan

Documentation

README · ~7 min read

NightVision App Security Scan

Run a real DAST scan against an app you just built or changed. API Discovery runs first when the backend language is supported, because it improves coverage and lets findings trace back to a source file and line (Code Traceback). DAST is the expected outcome on every run, not just a generated spec.

Requirements: this skill drives the NightVision MCP server's app-security-scan harness, so it needs a server build that provides run-app-security-scan, preflight-app, wait-for-scan, summarize-scan-findings, and export-sarif with the project_path argument. On an older server these tools are missing (the call returns an unknown-tool error) or export-sarif ignores project_path and silently drops source-linking. If any of the listed tools is unavailable, update the NightVision MCP server before using this skill; running preflight-app first is the cheapest way to confirm the harness is present.

Best-supported languages and frameworks

API Discovery uses deterministic static analysis to generate an OpenAPI spec for supported codebases. Source-linked results are strongest for the empirically verified languages and frameworks below:

  • Python: Django, Django REST Framework, Flask, Flask-RESTful, FastAPI
  • JavaScript/TypeScript: Express, NestJS, Fastify
  • Java: Spring Boot, JAX-RS/Jersey, Micronaut, Java EE/Jakarta EE
  • C#: ASP.NET Core controllers and minimal APIs
  • Go: Gin, httprouter, and experimental net/http support

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just skills.

Skillssimilar to this one

All skills