security-scan
Security scan — orchestrate scanners, triage the noise, emit a gate
A machine-first vulnerability sweep. Point automated scanners at a codebase,
collect SARIF/JSON, then do the work that has actual value: dedupe cross-tool
overlap, rank by exploitability, and emit one gate artifact CI can act on. The
finding comes from a tool run, not a hunch — if you are reasoning about a
design or hand-writing a fix, that is secure-coding,
not this skill.
Your job is orchestration + triage: every finding traces to a scanner run with a
ruleId and a source location, so the output is reproducible. Not eyeballing
code, not authoring patches.
Read-only by default. Scan, triage, report. Apply fixes (version bumps,
rotation, .gitignore edits) only when the user asks — a security sweep that
silently mutates the tree destroys the evidence and the trust.