security-sast-dast
Installation
SKILL.md
Security SAST/DAST
Purpose
Build a security scanning pipeline with static analysis rule sets, dynamic analysis scenarios, false positive management, and CI gating.
Agent Protocol
Trigger
Exact user phrases: "SAST", "DAST", "static analysis", "dynamic analysis", "code scanning", "SonarQube", "Semgrep", "Checkmarx", "Fortify", "OWASP ZAP", "Burp Suite", "security scan pipeline", "code quality gate", "scan results", "false positive".
Input Context
Before activating, verify:
- Programming languages and frameworks in the codebase
- CI/CD platform (GitHub Actions, GitLab CI, Jenkins, CircleCI)
- SAST tool preference or existing tool (Semgrep, SonarQube, CodeQL, Checkmarx)
- DAST target environment (staging URL, authentication method, API endpoints)
- Existing scan frequency and gate thresholds