qa-security-testing

Installation
SKILL.md

QA Security Testing

Automated security testing pipelines that integrate scanners into CI/CD, enforce vulnerability gates, and drive findings through remediation. This skill covers the testing automation side of security; for secure design, threat modeling, and architecture review, use software-security-appsec.

Start with the quick start workflow below, then dive into specific reference guides. Use current official sources from data/sources.json for tool documentation.

Quick Start

  1. Run a lightweight threat model to identify attack surface and risk areas.
  2. Select tools per category (SAST, SCA, DAST, secrets, container/IaC).
  3. Integrate into CI with clear gate policies per stage.
  4. Establish a triage workflow: confirm, classify, assign, track.
  5. Define vulnerability SLAs as a starting policy, then tune them to exploitability, business impact, and compliance obligations.
  6. Add security regression tests for every confirmed vulnerability.

Inputs to Gather

Installs
15
GitHub Stars
89
First Seen
Aug 12, 2026
qa-security-testing — vasilyu1983/ai-agents-public