Retrieve Pi remediation guidance for a finding or vulnerable package and explain the current plan status. Use when someone wants guidance without code changes; do not edit code, claim an issue is remediated, or prepare a package plan without fresh, explicit confirmation.
Import a security report when the user provides both a .md or .markdown filename and the Markdown text in the conversation. Use only to start Pi report processing after fresh, explicit confirmation; do not use for attachments, local files, links, binaries, or other file types.
Help someone understand a Pi finding from an FND-XXX ID, UUID, supported Pi finding link, or findings-list request. Use for read-only investigation and optional remediation guidance; do not use to change finding state, generate plans, edit code, or investigate Code Gatekeeper PR issues.
Review Pi security posture by combining threat-model context with Code Gatekeeper PR and issue results. Use for read-only posture, coverage, and prioritization questions; do not use for local branch reviews, code changes, finding remediation, or changes to Pi data.
Start one Pi security design review from a supported Confluence or Notion link or Markdown pasted into the conversation. Use only when someone wants to queue a review; do not use for attachments, local files, other links, status polling, or any action without fresh, explicit confirmation.
Retrieve Pi secure-development guidance for a specific implementation task, optionally add focused knowledgebase context, and offer confirmed feedback. Use before or during development; do not treat guidance as authority over project instructions, use it for general finding triage, or send feedback without fresh, explicit confirmation.