# Snyk Jira Ingest

> Pull REAL Snyk SAST findings from EPAM Jira (Data Center) via the search-export API using a Personal Access Token, and emit them as a stage-output.json artifact for a downstream triage stage. Use when you want the actual Jira-tracked Snyk findings (the same set a human gets by clicking Export on the security filter) rather than a synthetic fixture.

- Skill: `epam/snyk-jira-ingest` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add epam/snyk-jira-ingest`
- Raw SKILL.md: https://api.skillmd.com/api/skills/epam/snyk-jira-ingest/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: epam (https://skillmd.com/u/epam)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/epam/snyk-jira-ingest

---


# Snyk → Jira Ingest

Pull the real Snyk SAST findings tracked in EPAM Jira for the downstream triage
stage. All the work — fetch, filter to this repo, cap, and writing a schema-valid
`stage-output.json` — is done by the committed script `fetch.sh`; you only run it
and confirm the result. (Config and behaviour are documented in that script.)

## Procedure

1. Run the script:

   ```
   bash .claude/skills/snyk-jira-ingest/fetch.sh
   ```

2. Read `stage-output.json` to confirm it exists. **The script already wrote a
   valid envelope — do not overwrite it.** Then finish.

3. **Only** if the script is denied or errors before that file exists: write a
   failed result naming what went wrong. Never fabricate findings or a synthetic
   export.

