Answer questions about DefectDojo security findings, products, engagements, tests, and risk posture, and produce a security brief. Use for questions like how many critical findings are open, what is our riskiest application, show me open SQL injection…
Diagnose and repair the connection between Claude Code and DefectDojo Pro. Use when DefectDojo tools are missing or failing, when setting up or configuring DefectDojo for the first time, when a token is rejected or expired, when the user asks whether…
Upload scanner output or an SBOM into DefectDojo Pro. Use when the user has results from a security scanner and wants them in DefectDojo, or says import this scan, upload these results, push the Semgrep or Trivy or ZAP or Snyk or Nuclei or Burp output to…
Add DefectDojo scan upload to a repository's CI pipeline. Use when the user wants scan results pushed to DefectDojo automatically on every build or pull request, asks to add DefectDojo to GitHub Actions or GitLab CI or Jenkins, wants to automate scan upload,…
Build a security report from DefectDojo Pro data for an executive, board, engineering leadership, or audit audience. Use when the user asks for a security report, board deck material, quarterly or monthly security summary, exec summary of vulnerability…
Change the state of DefectDojo findings and annotate them, including close, reopen, verify, mark false positive, mark out of scope, risk accept, add notes, add or remove tags, and merge duplicates. Use when the user wants to triage, dispose of, clean up, or…