finding-discovery
Security Finding Discovery
Objective
Investigate the proposed code or code changes for technically plausible security vulnerabilities using the threat model as context.
Artifact Resolution
The path references in this skill are the default locations for this phase.
If the user explicitly provides a different path for a required input or output, use the user-provided path instead of the corresponding default path referenced in this skill.
If a required input is still missing, stop and ask the user for it before continuing.
Use the shared scan artifact path conventions in ../../references/scan-artifacts.md.
SECURITY.md Guidance Gate
Read ../../references/security-guidance.md and resolve the applicable policy before inspecting each source file. A delegated file-review worker must do the same before reading its assigned source.
Code Diff Workflow
If the scan target is for a targeted code-diff: