DevSecOps Guideline Lookup
Reference for OWASP DevSecOps Guideline phases, tools, and security checks.
Pipeline Phases
| Phase |
Activity |
Key Tools |
| Develop |
Pre-commit checks, Secret detection |
Gitleaks, TruffleHog, pre-commit |
| Build |
SAST, SCA, Container, IaC |
Semgrep, Trivy, Hadolint, tfsec |
| Test |
DAST, API Security, IAST |
OWASP ZAP, Nuclei, Postman |
| Deploy |
Security Gates, Config validation |
Policy-as-code, Admission controllers |
| Operate |
Monitoring, Vulnerability management |
CNAPP, SIEM, Pentesting |
Lookup Workflow
Identify the Query Type:
- Pipeline phase (develop, build, test, deploy, operate)
- Tool name (gitleaks, semgrep, trivy, etc.)
- Security activity (SAST, SCA, DAST, etc.)
- CWE reference
Search the Indexes:
# Phase lookup
cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/pipeline-phases-index.json | jq '.phases["build"]'
# Tool lookup
cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/tools-index.json | jq '.tools["semgrep"]'
# Search by keyword
cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/tools-index.json | jq '[.tools | to_entries[] | select(.value.keywords | map(ascii_downcase) | any(contains("sast")))]'
# CWE to phase mapping
cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/pipeline-phases-index.json | jq '[.phases | to_entries[] | select(.value.cwes | any(contains("CWE-798")))]'
Return Results with:
- What it does (summary)
- Installation command
- Usage example
- CI/CD integration pattern
- Official references
Response Format
### [Tool/Activity Name]
**Phase**: [develop|build|test|deploy|operate]
**Category**: [secret-detection|sast|sca|container|iac|dast|misconfig]
**What It Does**:
[1-2 sentence summary]
**Installation**:
\`\`\`bash
[install command]
\`\`\`
**Basic Usage**:
\`\`\`bash
[usage command]
\`\`\`
**CI/CD Integration** (GitHub Actions):
\`\`\`yaml
[workflow snippet]
\`\`\`
**CWE Coverage**: [list of CWEs]
**References**:
- [Tool URL]
- [OWASP DevSecOps Guideline URL]
Quick Reference: Tools by Phase
Develop (Pre-commit)
| Tool |
Purpose |
Install |
| Gitleaks |
Secret detection |
brew install gitleaks |
| pre-commit |
Hook management |
pip install pre-commit |
| detect-secrets |
Secret patterns |
pip install detect-secrets |
Build (CI)
| Tool |
Purpose |
Install |
| Semgrep |
SAST |
pip install semgrep |
| Trivy |
SCA + Container |
brew install trivy |
| Hadolint |
Dockerfile lint |
brew install hadolint |
| tfsec |
Terraform security |
brew install tfsec |
| Checkov |
IaC security |
pip install checkov |
Test (CD/Staging)
| Tool |
Purpose |
Install |
| OWASP ZAP |
DAST |
Docker |
| Nuclei |
Vulnerability scanner |
go install nuclei |
Index Coverage
pipeline-phases-index.json
- All DevSecOps pipeline phases
- Activities per phase
- Recommended tools
- CWE mappings
- OWASP DevSecOps Guideline references
tools-index.json
- 15+ security tools
- Installation commands
- Usage patterns
- CI/CD integration examples
- Output format specifications
Example Queries
User: "How do I scan for secrets in CI?"
You: Look up gitleaks in tools-index.json
User: "What's the build phase?"
You: Look up build in pipeline-phases-index.json
User: "Terraform security scanning?"
You: Look up tfsec or checkov in tools-index.json
User: "CWE-798 prevention?"
You: Search for CWE-798 in phases, return secret detection tools
External Resources
1---2name: devsecops-lookup3description: Looks up OWASP DevSecOps Guideline phases, security tools, and pipeline checks. Returns tool configurations, CWE mappings, and integration patterns for CI/CD security. Use when user asks about "DevSecOps", "SAST", "DAST", "SCA", "container security", "IaC security", "secret detection", "gitleaks", "semgrep", "trivy", "pipeline security", "シークレット検出", "静的解析", "動的解析", "コンテナセキュリティ", "セキュリティゲート".4---5
6# DevSecOps Guideline Lookup
7
8Reference for OWASP DevSecOps Guideline phases, tools, and security checks.
9
10## Pipeline Phases
11
12| Phase | Activity | Key Tools |
13|-------|----------|-----------|
14| Develop | Pre-commit checks, Secret detection | Gitleaks, TruffleHog, pre-commit |
15| Build | SAST, SCA, Container, IaC | Semgrep, Trivy, Hadolint, tfsec |
16| Test | DAST, API Security, IAST | OWASP ZAP, Nuclei, Postman |
17| Deploy | Security Gates, Config validation | Policy-as-code, Admission controllers |
18| Operate | Monitoring, Vulnerability management | CNAPP, SIEM, Pentesting |
19
20## Lookup Workflow
21
221. **Identify the Query Type**:
23 - Pipeline phase (develop, build, test, deploy, operate)
24 - Tool name (gitleaks, semgrep, trivy, etc.)
25 - Security activity (SAST, SCA, DAST, etc.)
26 - CWE reference
27
282. **Search the Indexes**:
29 ```bash
30 # Phase lookup
31 cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/pipeline-phases-index.json | jq '.phases["build"]'
32
33 # Tool lookup
34 cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/tools-index.json | jq '.tools["semgrep"]'
35
36 # Search by keyword
37 cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/tools-index.json | jq '[.tools | to_entries[] | select(.value.keywords | map(ascii_downcase) | any(contains("sast")))]'
38
39 # CWE to phase mapping
40 cat ${CLAUDE_PLUGIN_ROOT}/skills/devsecops-lookup/pipeline-phases-index.json | jq '[.phases | to_entries[] | select(.value.cwes | any(contains("CWE-798")))]'
41 ```
42
433. **Return Results** with:
44 - What it does (summary)
45 - Installation command
46 - Usage example
47 - CI/CD integration pattern
48 - Official references
49
50## Response Format
51
52```markdown
53### [Tool/Activity Name]
54
55**Phase**: [develop|build|test|deploy|operate]
56**Category**: [secret-detection|sast|sca|container|iac|dast|misconfig]
57
58**What It Does**:
59[1-2 sentence summary]
60
61**Installation**:
62\`\`\`bash
63[install command]
64\`\`\`
65
66**Basic Usage**:
67\`\`\`bash
68[usage command]
69\`\`\`
70
71**CI/CD Integration** (GitHub Actions):
72\`\`\`yaml
73[workflow snippet]
74\`\`\`
75
76**CWE Coverage**: [list of CWEs]
77
78**References**:
79- [Tool URL]
80- [OWASP DevSecOps Guideline URL]
81```
82
83## Quick Reference: Tools by Phase
84
85### Develop (Pre-commit)
86| Tool | Purpose | Install |
87|------|---------|---------|
88| Gitleaks | Secret detection | `brew install gitleaks` |
89| pre-commit | Hook management | `pip install pre-commit` |
90| detect-secrets | Secret patterns | `pip install detect-secrets` |
91
92### Build (CI)
93| Tool | Purpose | Install |
94|------|---------|---------|
95| Semgrep | SAST | `pip install semgrep` |
96| Trivy | SCA + Container | `brew install trivy` |
97| Hadolint | Dockerfile lint | `brew install hadolint` |
98| tfsec | Terraform security | `brew install tfsec` |
99| Checkov | IaC security | `pip install checkov` |
100
101### Test (CD/Staging)
102| Tool | Purpose | Install |
103|------|---------|---------|
104| OWASP ZAP | DAST | Docker |
105| Nuclei | Vulnerability scanner | `go install nuclei` |
106
107## Index Coverage
108
109### pipeline-phases-index.json
110- All DevSecOps pipeline phases
111- Activities per phase
112- Recommended tools
113- CWE mappings
114- OWASP DevSecOps Guideline references
115
116### tools-index.json
117- 15+ security tools
118- Installation commands
119- Usage patterns
120- CI/CD integration examples
121- Output format specifications
122
123## Example Queries
124
125**User**: "How do I scan for secrets in CI?"
126**You**: Look up `gitleaks` in tools-index.json
127
128**User**: "What's the build phase?"
129**You**: Look up `build` in pipeline-phases-index.json
130
131**User**: "Terraform security scanning?"
132**You**: Look up `tfsec` or `checkov` in tools-index.json
133
134**User**: "CWE-798 prevention?"
135**You**: Search for CWE-798 in phases, return secret detection tools
136
137## External Resources
138
139- [OWASP DevSecOps Guideline](https://owasp.org/www-project-devsecops-guideline/)
140- [OWASP DevSecOps Guideline (Japanese)](https://coky-t.gitbook.io/owasp-devsecops-guideline-ja/)
141- [CWE/SANS Top 25](https://cwe.mitre.org/top25/)
142- [NIST SSDF](https://csrc.nist.gov/Projects/ssdf)