appsec

Installation
SKILL.md

Every code change passes this gate before it ships: application code, frontend, infrastructure, Terraform, Kubernetes manifests, Dockerfiles, CI config. A change is shippable only after every deterministic gate is green, and the run then records what "green" covered. This skill orchestrates the gates in a fixed order so each run is identical. The commands live in skill-gate, never in prose; the per-gate rationale lives in the pipeline reference. Mechanical scanning sets the floor, and the attestation is the artifact that proves the floor was met. The pipeline subsumes the dependency supply-chain audit, since the sca and secrets gates and the syft SBOM cover dependency vulnerabilities, pinning, and CVE triage; the depth is in supply-chain risk. The pipeline also enforces a repository policy, forbidden patterns held as data in POLICY.md and scanned deterministically so the same regex yields the same verdict every run; the policy model carries that depth.

Steps

  1. Scope the gates. Run skill-gate --list at the repo root to enumerate the gates the detected stacks activate. Confirm the printed list names a gate per supported category across the seven the stack covers (format, lint, types, sast, sca, secrets, test). The step is done when the scope is confirmed against the pipeline reference.

  2. Pass the quality gates. Run skill-gate --category format, then --category lint, then --category types, in that order. A non-zero exit blocks the pipeline; fix the source, then rerun the failing category until its exit code is zero. The step is done when format, lint, and types each exit zero.

  3. Pass the security gates. Run skill-gate --category sast (Semgrep), then --category sca (trivy or pip-audit), then --category secrets (gitleaks), in that order. The sca and secrets gates are the dependency supply-chain audit: sca scans the locked tree for known-vulnerable packages while secrets hunts leaked credentials, and both depend on a committed lockfile so the scanned tree is reproducible; the threat model, the pinning discipline, and the CVE triage method live in supply-chain risk. Record each finding with its severity, rule id, and location; triage each dependency CVE for reachability and a fixed version, then assign one of the four responses (upgrade, pin, patch, accept) from the same reference. A critical or high finding blocks the merge until the finding is fixed or a waiver-log entry is recorded per the pipeline reference. The step is done when each security category exits zero or carries a recorded waiver-log entry that a reviewer has checked.

  4. Enforce the repository policy. Run skills/engineering/appsec/scripts/check-policy.sh at the repo root. The scanner is deterministic: forbidden patterns come from POLICY.md, and a match fails the run (a leaked secret shape, a dangerous call, a banned dependency or license, a missing required header), with no model judgment in the enforcement path. A new hazard lands as one DENY <regex> -- <message> line in the repo-local ./POLICY.md, the file that extends the global one. A repo with no local policy takes the line in the global POLICY.md instead. Then calibrate the regex against real text so it catches the hazard without flagging a safe line. The rule syntax and the layering live in the policy model, along with the failure modes. The step is done once the scanner exits zero or every violation is triaged, and each new hazard maps to exactly one DENY line.

  5. Pass the test gate. Run skill-gate --category test. A failing suite blocks the change; fix the source, then rerun until the suite exits zero. The step is done when the test category exits zero.

  6. Seal the merge gate. Run skill-gate --strict for the final pass. Strict mode counts a missing tool as a failure, where a plain run would skip it silently. A red result stops the line (Jidoka); a green result means every category ran on a present tool. The step is done when skill-gate --strict exits zero.

  7. Produce the attestation. Capture the machine-readable gate record with skill-gate --strict --format json, generate the SBOM with syft (skill-gate has no SBOM capability; the format choice lives in supply-chain risk), and record any waiver-log entry beside them. The SBOM command reads the locked tree:

Installs
1
First Seen
Aug 18, 2026
appsec — lucas-ataides/skills