Security Scan

Use when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on. NOT threat-modeling, OWASP design reasoning, or hand-authoring the fix (that is `secure-coding`).

ericrisco 3898d95 6 files · 26.6 KB Updated

File contents

ericrisco/rsc-harness/tree/main/skills/security-scan commit 3898d95e4a

Frequently asked questions

npx skillmds@latest add ericrisco/security-scan