ThreatLens

    1

    Perform evidence-based static security audits for application code, cloud configs, and infrastructure manifests.

    $11.99

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    ThreatLens

    Example session with this skill installed

    Perform a security audit on this Node.js Express snippet and the associated Dockerfile to check for common web vulnerabilities and misconfigurations.

    • Read your context and instructions
    • Compiled the threatlens
    • Generated the document

    I have completed a static security audit of the provided Node.js and Docker configuration. The analysis identified three high-priority findings related to input handling and container permissions.

    Security Summary

    The audit detected potential SQL injection due to unsanitized input and a container running with elevated privileges. While authentication logic appears sound, the infrastructure layer requires hardening.

    Findings

    IDSeverityConfidenceAreaLocationFinding
    SEC-01HighHighInjectionapp.js:42Direct concatenation of req.query.id into SQL string.
    SEC-02MediumHighConfigDockerfile:4Container running as root user.
    SEC-03LowMediumHeadersapp.js:12Missing Content-Security-Policy and X-Frame-Options.

    Remediation

    SEC-01: SQL Injection
    Replace string concatenation with parameterized queries or an ORM.

    // Before
    const user = await db.query("SELECT * FROM users WHERE id = " + req.query.id);
    
    // After
    const user = await db.query("SELECT * FROM users WHERE id = $1", [req.query.id]);
    

    SEC-02: Root Container
    Add a non-privileged user to your Dockerfile to follow the principle of least privilege.

    RUN groupadd -r nodejs && useradd -r -g nodejs nodejs
    USER nodejs
    

    Verification Plan

    1. Attempt a manual Boolean-based SQL injection on the /user endpoint.
    2. Run docker inspect on the built image to verify the User field is not empty or root.
    3. Use a browser inspector to verify security headers are present in API responses.

    Next steps

    • Apply the parameterized query fix to all database interaction logic.
    • Update the Dockerfile to use a non-root user.
    • Add the helmet middleware to the Express app for automated header management.

    threatlens.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Audit PRs for SQL injection and XSS vulnerabilities before merging.Identify hardcoded secrets and API keys in source code or environment files.Review Docker and K8s manifests for privilege escalation risks.Check API endpoints for missing authentication or rate-limiting.

    About this skill

    Manual security reviews are slow and prone to oversight. This skill automates the detection of critical vulnerabilities in your source code, configuration files, and infrastructure manifests using a structured, evidence-based approach.

    What it does

    • Vulnerability detection identifies SQL injection, XSS, CSRF, and path traversal risks.
    • Access control audit evaluates authentication and authorization logic for bypasses.
    • Secret scanning flags hardcoded credentials, API keys, and private tokens.
    • Config analysis reviews CORS policies, security headers, and debug settings.
    • Remediation mapping provides specific code fixes for every identified risk.

    How it works

    1. Analyze scope by scanning the provided repository, files, or snippets for attack surface.
    2. Identify flaws across specific categories like input handling and data exposure.
    3. Classify risks using severity and confidence levels based on code evidence.
    4. Generate report including a findings table and a structured verification plan.

    Frameworks & tools

    Works with any language or configuration format including JavaScript/TypeScript, Python, Go, Java, Dockerfiles, Kubernetes manifests, and Terraform HCL.

    Why this beats prompting it yourself

    Generic prompts often miss context-specific logic flaws or produce vague "hallucinated" vulnerabilities. This skill enforces a strict evidence-based methodology, requiring specific file locations and confidence scores to reduce noise and false positives.

    Use cases

    • Audit a Pull Request for security regressions before merging to main.
    • Review infrastructure-as-code files for overly permissive permissions.
    • Conduct a pre-deployment check on API authentication and rate-limiting logic.
    • Identify sensitive data leakage in logs or error handling routines.

    Known limitations

    Static analysis cannot identify runtime-only vulnerabilities or complex multi-step logic exploits. Findings marked with NEEDS VERIFICATION require manual review of execution context.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 8 days ago

    • Passed all security checks, Safe to install

    Listed8 days ago

    What's inside

    Frequently Asked Questions