# How do I run a security scan with the ZeroTwo Security plugin?

> Install the Security plugin, ask for a repository, folder or change scan, approve subagents, then read the report and review comments.

Source: https://help.zerotwo.ai/en/articles/20001107-how-do-i-run-a-security-scan-with-the-zerotwo-security-plugin
Section: Code
Last updated: 2026-10-07

The Security plugin gives ZeroTwo skills for security review: scans of a repository or a folder, security review of a pull request or other change, threat models, and fixes for findings. It is a plugin, not a separate product. You install it, ask for a scan in a chat, and ZeroTwo runs it as an agent task that ends in a written report.

## Install it and start a scan

1. Install **Security** from **Customize** > **Plugins**. See [Add, use and manage plugins in ZeroTwo](https://help.zerotwo.ai/en/articles/20001256-add-use-and-manage-plugins-in-zerotwo) for the steps.
2. Open a Code task on the repository you want to check. The skills read the checked-out repository, so the code has to be in the task's workspace. See [How do I run Code in the cloud with ZeroTwo?](https://help.zerotwo.ai/en/articles/20001545-how-do-i-run-code-in-the-cloud-with-zerotwo) for a task that runs in the cloud.
3. Ask in your own words. The plugin suggests three prompts: "Scan this repo for common security issues.", "Explain this CVE and whether we are affected." and "Draft a remediation plan for the top findings."

## Choose the kind of scan

| You want | Skill | What it covers |
| --- | --- | --- |
| A whole repository, or one folder or package in it | security-scan | A repository-wide or scoped-path scan. |
| A pull request, commit, branch or uncommitted patch | security-diff-scan | A security review of a Git-backed change set. |
| A threat model | threat-model | Create, update or save a repository threat model. |
| A fix | fix-finding | Fix and verify a finding you point to. |

The plugin also has **finding-discovery**, **validation** and **attack-path-analysis** skills. Scans use them as phases, and you can ask for one directly, for example to check whether a candidate finding is valid.

## What happens during a scan

1. ZeroTwo builds or reuses a threat model of the repository.
2. It discovers candidate findings against that model.
3. It validates each candidate. It tries to reproduce or disprove the finding when that is practical, and otherwise traces the code.
4. It analyzes the attack path and calibrates severity.
5. It writes the final report.

Before a repository or path scan, ZeroTwo stops and asks you to authorize subagents, because the scan depends on them. If a goal tool is available it sets a goal for the scan, so the work continues until the files in scope and the candidates have been accounted for. A scan of a change stops early and writes its report right away if discovery finds nothing plausible.

## Read the results

ZeroTwo writes `report.html`, the main readable report, and `report.md`, the source it was generated from, into the scan's folder, and gives you both paths in its reply. If you give a different location for an output, ZeroTwo uses it. A report has these parts:

- **Scope**, with a scan summary, and the **Threat Model** the scan used.
- **Findings**, ordered from critical to low, with a summary table and a confidence scale. Each finding lists its severity, confidence, category, CWE and affected lines, then **Summary**, **Validation**, **Dataflow**, **Reachability**, **Severity** and **Remediation**.
- **Reviewed Surfaces**, for repository and path scans, listing what was inspected and whether each surface was **Reported**, found to have **No issue found**, **Rejected**, **Not applicable** or marked **Needs follow-up**.

In the chat, each surviving finding also appears as a code comment card. The title starts with a priority from P0 for critical to P3 for low, and the card shows the file and line range. Select it to open the file at those lines.

## Fix a finding

Ask ZeroTwo to fix a finding and it reproduces the problem where it can, makes the smallest change that enforces the missing check, adds a regression test and confirms the original issue no longer reproduces. If the issue is already fixed, it shows the evidence and makes no change. A fix edits files in your repository, so review the changes before you keep them.

## Good to know

The plugin has no connection of its own to GitHub or any other service. It works on the code in the task's workspace. Each finding states a confidence and the reason for it, and a surface that was not fully closed is marked Needs follow-up, so treat a finding as a lead to check before you act on it.
