Reference

Scanning from an AI agent

Install the ScanSuite skill in Claude, OpenAI Codex or GitHub Copilot and have the assistant run scans and read the results for you.

ScanSuite ships an agent skill: a small package that teaches an AI coding assistant to run ScanSuite scans and read the results on its own. Ask it to "scan this repository" or "find what's exposed for example.com", and it picks the scan, runs it through the ScanSuite client, waits, and reports what matters. The skill is the same open SKILL.md format that Claude, OpenAI Codex and GitHub Copilot all load, so one package works across the three. It is published in the public repository github.com/cepxeo/scansuite-ci.

ScanSuite Teams

The skill uses the team API, which is part of ScanSuite Teams.

What it can do: static analysis of code (SAST, AI SAST, secrets, dependencies, IaC), dynamic scans of web applications (DAST), and infrastructure scans (network and port discovery, OSINT and subdomains, Nuclei, container-image CVEs, and more); chaining them, for example an OSINT sweep of a domain followed by a port scan of the hosts it finds; and reading or triaging what a scan produced. The full client reference is in CI/CD and automation.

Before you start

The skill talks to your ScanSuite server with a service-account token, the same kind a pipeline uses. It reads the token from a file and never puts it in the chat or on a command line.

  1. 01
    Create a token

    In ScanSuite: Teams page, People tab, Automation and API tokens. Create a service account with the Operator role, then a token with the CI pipeline preset.

  2. 02
    Save it to a file

    Put the token in ~/.scansuite-token and keep it private.

    Shell
    printf '%s' 'YOUR_TOKEN' > ~/.scansuite-token && chmod 600 ~/.scansuite-token
  3. 03
    Tell the agent the server and team

    Give it SCANSUITE_URL (your server) and SCANSUITE_TEAM (the team slug), or just answer when it asks.

The agent needs bash, curl, python3, and either Docker (to run the client image) or the Python client — the skill falls back to the client your server publishes and checks its checksum.

Treat the token as a credential. The skill keeps it in the file and out of the conversation, but anyone who can read ~/.scansuite-token can scan as you. A CI pipeline token can run scans and read results; it cannot change team settings.

Install it in your assistant

A skill is a folder containing a SKILL.md file. Each tool loads it from its own location, so the install is "put the folder where the tool looks". In the repository the skill lives at plugins/scansuite/skills/scansuite/ — copy that folder.

Claude Code

The repository is also a Claude Code plugin marketplace, so you can install without copying files. In a Claude Code session:

text
/plugin marketplace add cepxeo/scansuite-ci
/plugin install scansuite@scansuite-ci

Or copy the folder into a skills directory — ~/.claude/skills/ for every project, or .claude/skills/ inside one repository:

bash
git clone https://github.com/cepxeo/scansuite-ci
cp -r scansuite-ci/plugins/scansuite/skills/scansuite ~/.claude/skills/scansuite

Claude (claude.ai and the desktop app)

Open Settings → Customize → Skills and upload the skill as a .zip whose contents are the scansuite/ folder (so the archive holds scansuite/SKILL.md). It syncs to your account across claude.ai, the desktop app and Claude Code.

OpenAI Codex

Codex reads skills from .agents/skills/ in your project (every folder from the working directory up to the repository root) and from ~/.agents/skills/ for personal use. Copy the folder there:

bash
cp -r scansuite-ci/plugins/scansuite/skills/scansuite ~/.agents/skills/scansuite

In Codex, type $ to mention a skill or run /skills; invoke this one as $scansuite. See OpenAI's Codex skills guide.

GitHub Copilot

Copilot reads skills from .github/skills/ in a repository (it also accepts .claude/skills/ and .agents/skills/) and from ~/.copilot/skills/ for personal use. Copy the folder there:

bash
cp -r scansuite-ci/plugins/scansuite/skills/scansuite .github/skills/scansuite

Then manage it with /skills in a Copilot CLI session (/skills list, /skills to enable), or copilot skill enable scansuite from the terminal. See GitHub's Copilot skills documentation.

Codex and Copilot both read .agents/skills/, so one copy there serves both. Support and exact paths are the vendors' own — check their documentation for your version, since these features are recent and still changing.

Use it

Ask in plain language; the agent picks the scan and runs it. For example:

You sayWhat runs
"Scan this repo for exploitable vulnerabilities and tell me what is reachable."AI SAST of the working directory, findings by severity
"Run OSINT on example.com, then a full-TCP port scan of the hosts it finds (no ping)."OSINT, then network discovery of the addresses that resolve
"Scan registry.example.com/app:1.4 for CVEs."Container-image scan
"Check staging.example.com for web vulnerabilities behind our login."DAST with an authentication header
"Show me the critical findings from the last scan of the payments product."Reads the results through the team API

The skill keeps a scan safe and useful: it resolves the names an OSINT scan finds and leaves out ones you don't own, checks a scanner is available on your server before promising it, asks before anything intrusive or costly, and reads low-severity results from the report archive when they aren't stored as findings. It gives you a short summary per scan, not raw output.

For the full list of scan types, options and the team API the skill uses, see CI/CD and automation.

Last reviewed 2026-10-03