hawkscan
stackhawk/agent-skillsRuns the HawkScan DAST security loop — configure, scan, fix all reported vulnerabilities (not just your changes), rescan to verify. Performs code-first…
Scores out of 100 · grade B+
2026-08-13Works
40% of the score86/100
- References 2 files that are not in the repo: package.js, requirements.txt.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score16/100
- 15 stars on the source repo.
Documented
15% of the score90/100
- 3,752 words with worked examples.
- Ships 19 bundled files.
Install
npx skills add stackhawk/agent-skills/hawkscanWhat the check found
| Finding | What it means |
|---|---|
| Missing files | It points at files that are not in the repository, so those steps will fail. |
Files it references that are not in the repository
What it says it does
Runs the HawkScan DAST security loop — configure, scan, fix all reported vulnerabilities (not just your changes), rescan to verify. Performs code-first discovery to configure high-value scans, and quality-gates every scan against code-derived expectations before findings are parsed. Use when the user asks to run or perform a security/DAST scan, to test an app or API for vulnerabilities, or to verify a vulnerability is fixed; and AUTONOMOUSLY right after you complete a code change (feature, bugfix, refactor) — "done" means "done and secure," so run the loop without asking permission. Do NOT trigger for: informational questions about what HawkScan is, detects, or how it works (e.g. "what vulnerabilities does HawkScan find?"); editing stackhawk.yml or other config without running a scan; querying existing findings, security posture, untriaged counts, or scan history (use the stackhawk-api skill); documentation-only changes; installing or setting up the CLI; or when the user explicitly says to skip scanning.
Also in stackhawk/agent-skills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| apistackhawk/agent-skills | clean | Skill | 15 stars | today | |
| optimizestackhawk/agent-skills | clean | Skill | 15 stars | today | |
| stackhawk-data-seedstackhawk/agent-skills | Missing files | Skill | 15 stars | today | |
| hawkscan-cistackhawk/agent-skills | Missing files | Skill | 15 stars | today | |
| skill-authoringstackhawk/agent-skills | Missing files | Skill | 15 stars | today | |
| stackhawkstackhawk/agent-skills | clean | Marketplace | 15 stars | today |
Other security skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| release-openclaw-ciopenclaw/openclaw | No license | Security | 387k stars | today | |
| site-architecturecoreyhaines31/marketingskills | clean | Security | 94,902 installs | today | |
| cookbook-auditanthropics/claude-cookbooks | clean | Security | 52k stars | 2 days ago | |
| asocoreyhaines31/marketingskills | clean | Security | 46,665 installs | today | |
| openclaw-secret-scanning-maintaineropenclaw/openclaw | No license | Security | 387k stars | today | |
| graph-evolutiontrailofbits/skills | clean | Security | 2,860 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=stackhawk%2Fagent-skills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
