| name | sarif-parsing |
| description | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplicate alerts", or "process sarif output". Handles filtering, deduplication, format conversion, and CI/CD integration of SARIF data. Does NOT run scans — use the Semgrep or CodeQL skills for that. |
| source_skill_id | trailofbits-skills-plugins-static-analysis-skills-sarif-parsing-skill-md |
| category | Security, compliance & risk |
| source_mirror | ../../../../../skills/by-category/security-compliance-risk/security-reference/sarif-parsing/SKILL.md |
| benchmark_status | artifact_gated |
sarif-parsing
Use this skill when the task matches the description above or the source path clearly applies. Start with this concise entrypoint; open ../../../../../skills/by-category/security-compliance-risk/security-reference/sarif-parsing/SKILL.md only when implementation details, commands, assets, or references are needed.
Workflow
- Confirm the task matches this skill's scope.
- Read the local source mirror if more detail is required.
- Follow repository-level
AGENTS.md; use one AI session only.
- Keep claims tied to files, commands, citations, or benchmark artifacts.
Verification
- Source mirror:
../../../../../skills/by-category/security-compliance-risk/security-reference/sarif-parsing/SKILL.md
- Source commit:
e8cc5baf9329ccb491bfa200e82eacbac83b1ead
- Static benchmark results: see
docs/benchmark-results.md
- Runtime artifacts recorded by this entrypoint:
0
- Assigned scenarios:
skill-proof-trailofbits-skills-plugins-static-analysis-skills-sarif-parsing-skill-md, security-compliance-and-risk-owasp-benchmark, security-compliance-and-risk-owasp-juice-shop, security-compliance-and-risk-kubernetes-examples
Do not claim this skill passed a runtime benchmark until a validated artifact exists.