analyze-findings

Installation
SKILL.md

Skill: Analyze Findings

A finding file bundles all of one rule's results. Read each result's code flow, split the bundle into distinct vulnerabilities, and give each a TP/FP verdict on its own evidence

Inputs

Provided by the caller, fall back to the default value when omitted. Ask back only when a required input is missing and has no sensible default

  • project-root (optional) — root of the target project. Opentaint keeps all analysis artifacts under the fixed <project-root>/.opentaint/ directory, so every .opentaint/... path below resolves there. Default: current directory
  • language (required) — target language for this project and language-specific instructions
  • findings (required) — the finding file(s) to triage, each .opentaint/tracking/findings/<name>.yaml bundling one rule's SARIF results in sarif_hashes

Workflow

1. Reconcile before judging

A finding whose notes open with a reconcile line is a rescan result under a rule whose other findings are already triaged — most often the same vulnerability with a shifted hash, not a new one. Before judging it fresh, read the rule's already-triaged finding files and compare flows (source → sink, same essential path): if one matches, move this finding's sarif_hashes into that finding, drop this file, and let the inherited verdict stand — don't re-judge a flow already triaged. Only when no triaged finding matches do you treat it as new and continue below.

2. One result at a time — STOP checklist

Installs
55
Repository
seqra/opentaint
GitHub Stars
157
First Seen
Jun 11, 2026
analyze-findings — seqra/opentaint