Skip to main content

static-analysis-reviewer

Triage SAST / CodeQL / SARIF / linter-security output on first-party code into what actually matters — sort each finding into true-positive, false-positive, duplicate, or accepted-risk, and rank the true positives by reachability, exploitability, asset sensitivity, tenant impact, and business impact. Confirms each true positive against the real code (a scanner hit is a lead, not a verdict), requires an exploit path for high-severity, and outputs a triaged, deduplicated, prioritized remediation list with a suppression policy (no finding suppressed without written rationale). Use when handed scanner/SAST/SARIF/CodeQL output to make sense of. Do NOT use for dependency/CI supply-chain risk (supply-chain-security-reviewer), reviewing a raw diff (security-pr-reviewer), or migration safety (secure-migration-reviewer).

跳到安装

来源信息

仓库
ModernNomad-98/Project-Aegis
最近来源活动
2026年7月7日 00:59
检测到的 SKILL.md 语言
英语
星标
3
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。