ThreatLens
Perform evidence-based static security audits for application code, cloud configs, and infrastructure manifests.
$11.99
Works with the AI tools you already use
ThreatLens
Example session with this skill installed
Perform a security audit on this Node.js Express snippet and the associated Dockerfile to check for common web vulnerabilities and misconfigurations.
- Read your context and instructions
- Compiled the threatlens
- Generated the document
I have completed a static security audit of the provided Node.js and Docker configuration. The analysis identified three high-priority findings related to input handling and container permissions.
Security Summary
The audit detected potential SQL injection due to unsanitized input and a container running with elevated privileges. While authentication logic appears sound, the infrastructure layer requires hardening.
Findings
| ID | Severity | Confidence | Area | Location | Finding |
|---|---|---|---|---|---|
| SEC-01 | High | High | Injection | app.js:42 | Direct concatenation of req.query.id into SQL string. |
| SEC-02 | Medium | High | Config | Dockerfile:4 | Container running as root user. |
| SEC-03 | Low | Medium | Headers | app.js:12 | Missing Content-Security-Policy and X-Frame-Options. |
Remediation
SEC-01: SQL Injection
Replace string concatenation with parameterized queries or an ORM.
// Before
const user = await db.query("SELECT * FROM users WHERE id = " + req.query.id);
// After
const user = await db.query("SELECT * FROM users WHERE id = $1", [req.query.id]);
SEC-02: Root Container
Add a non-privileged user to your Dockerfile to follow the principle of least privilege.
RUN groupadd -r nodejs && useradd -r -g nodejs nodejs
USER nodejs
Verification Plan
- Attempt a manual Boolean-based SQL injection on the
/userendpoint. - Run
docker inspecton the built image to verify theUserfield is not empty or root. - Use a browser inspector to verify security headers are present in API responses.
Next steps
- Apply the parameterized query fix to all database interaction logic.
- Update the Dockerfile to use a non-root user.
- Add the
helmetmiddleware to the Express app for automated header management.
threatlens.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Manual security reviews are slow and prone to oversight. This skill automates the detection of critical vulnerabilities in your source code, configuration files, and infrastructure manifests using a structured, evidence-based approach.
What it does
- Vulnerability detection identifies SQL injection, XSS, CSRF, and path traversal risks.
- Access control audit evaluates authentication and authorization logic for bypasses.
- Secret scanning flags hardcoded credentials, API keys, and private tokens.
- Config analysis reviews CORS policies, security headers, and debug settings.
- Remediation mapping provides specific code fixes for every identified risk.
How it works
- Analyze scope by scanning the provided repository, files, or snippets for attack surface.
- Identify flaws across specific categories like input handling and data exposure.
- Classify risks using severity and confidence levels based on code evidence.
- Generate report including a findings table and a structured verification plan.
Frameworks & tools
Works with any language or configuration format including JavaScript/TypeScript, Python, Go, Java, Dockerfiles, Kubernetes manifests, and Terraform HCL.
Why this beats prompting it yourself
Generic prompts often miss context-specific logic flaws or produce vague "hallucinated" vulnerabilities. This skill enforces a strict evidence-based methodology, requiring specific file locations and confidence scores to reduce noise and false positives.
Use cases
- Audit a Pull Request for security regressions before merging to main.
- Review infrastructure-as-code files for overly permissive permissions.
- Conduct a pre-deployment check on API authentication and rate-limiting logic.
- Identify sensitive data leakage in logs or error handling routines.
Known limitations
Static analysis cannot identify runtime-only vulnerabilities or complex multi-step logic exploits. Findings marked with NEEDS VERIFICATION require manual review of execution context.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 8 days ago
- Passed all security checks, Safe to install