StackHawk HawkScan
Configures and runs HawkScan against your own running app, then turns findings into ordered fix tasks.
Install
OfficialShips scriptsClaude Code: /plugin marketplace add anthropics/claude-plugins-official → /plugin install stackhawk-hawkscan@claude-plugins-official
Kendi uygulamanı yetkili biçimde DAST ile tararken ve çıkan bulguları düzeltme görevine çevirirken
- Author
- StackHawk
- License
- MIT
The gap it targets is specific: an agent writes an endpoint and nothing checks whether that endpoint is exploitable on the app that is actually running. The main skill generates the stackhawk.yml, launches the scanner through the CLI or Docker, parses the results into prioritized remediation tasks, then rescans to confirm the fix held — a loop rather than a report. Separate skills query the platform API for posture across applications, graduate a working local scan into CI by detecting the provider and patching the workflow file, and seed test data so authenticated paths get scanned instead of bouncing off a login screen. Hooks fire on session start, skill activation and post-commit, so scanning is attached to the workflow rather than remembered.
Similar skills
Signed Audit Trails
SkillA single cookbook skill that explains signed tool-call receipts before you commit to running them.
PostHog
SkillDozens of narrow skills for PostHog analytics, flags and experiments — and a channel back the other way.
Skill Seekers
SkillTurns documentation sites, repos and PDFs into agent skills.

Comments(0)
Sign in to comment