# Security Scan · PalmCoast

> Scan a project or codebase for AI agent security issues. Use when reviewing MCP configurations, auditing credential handling, checking for hardcoded API keys, evaluating agent permission scopes, or assessing prompt injection risks. Auto-activates when discussing security, credentials, API keys, secrets, or agent identity.

## Facts
- Page: https://tashan.sh/capability/skill-palmcoast-security-scan
- tashan id: skill:PalmCoast/security-scan
- Source: https://github.com/PalmCoast/clawlock-plugin
- Type: skill
- Category: security
- tashan score: 28.0 / 100
- Adoption: 14.0
- Upkeep: 46.0
- Freshness: 61.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- Official: no

## Install

```sh
cp -r security-scan ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-14 by tashan (https://tashan.sh) from public evidence. Scorer s5.
