Security Scan Suite
Deterministic SAST + SCA + secret + IaC + container scanners plus DAST (Semgrep, Trivy, Gitleaks, OSV, ZAP, Nuclei), aggregated to SARIF, CI-gated on confirmed severity, and triaged through the security-audit multi-vector discipline. The scanners detect; the model triages.
Expected outcome
Deterministic SAST + SCA + secret + IaC + container scanners plus DAST (Semgrep, Trivy, Gitleaks, OSV, ZAP, Nuclei), aggregated to SARIF, CI-gated on confirmed severity, and triaged through the security-audit multi-vector discipline. The scanners detect; the model triages.
Typical deliverable
An evidence-backed findings report with severity and recommended action.
01
Inspect context
Loads project authority and checks prerequisites.
02
Run the procedure
Executes defined steps and honors safety gates.
03
Return evidence
Produces a reviewable result instead of an unsupported claim.
Licensed implementation
The licensed module adds trigger phrases, CLI aliases, dependency and coordination maps, and its step-by-step governed procedure.
No per-skill purchases: a plan unlocks every skill in its tier, this one included.