sk Skill · ericrisco
security-scan
Use when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has to become one deduped, exploitability-ranked report CI can gate on. NOT threat-modeling, OWASP design reasoning, or hand-authoring the fix (that is secure-coding).
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 11
- Connections
- 0
yamlbashJavaScriptowaspsecretsjsonscascanningsastsecurity
- Host repository
- ericrisco/rsc-harness
- Host stars
- 84
- Host language
- JavaScript