hoangnguyen0403/security-test
Fast, continuous DevSecOps pipeline for Pull Requests and active branches. Runs SAST, SCA, and secrets detection to catch vulnerabilities before they merge.
npx skills add https://github.com/HoangNguyen0403/agent-skills-standard --skill security-test
> [!IMPORTANT]
> Fast, continuous DevSecOps pipeline for Pull Requests and active branches. Runs SAST, SCA, and secrets detection to catch vulnerabilities before they merge.
Optional args: slug=<feature>, ticket=<id/url>, mode=interactive|autonomous|channel, channel=<id>, auto_continue=true|false, profile=business|hybrid|technical.
When the user asks to perform this workflow, execute the following steps:
> Goal: Execute a high-speed security audit on a branch or PR delta and stop obvious security regressions before merge.
>
> Policy: Fast execution (< 2 mins). Focus on SAST, SCA, secrets, and trust-boundary regressions. No dynamic exploitation required.
git diff <base>...HEAD.<SKILLS>/common/common-security-audit/references/trust-review-policy.md.reviewContext.promptInjectionRisk to high unless host controls clearly reduce that risk.specialist-aspm-correlator.specialist-security-reviewer in fast mode for normal diffs and deep mode for auth, secrets, agent tools, or external integration changes.design-solution evidence or return BLOCKED with the missing design questions.artifacts/security-review.md with trust class, review context, scope, source provenance, runtime contract, blockers, warnings, finding confidence, exploit path, evidence gaps, and handoff notes.artifacts/security-review.dev.md, artifacts/security-review.appsec.md, or artifacts/security-review.exec.md only when a separate audience needs it.### 🛡️ Security Check: [PASS / FAIL]
**Scan Scope**: [branch/diff size]
**Trust Class**: [trusted|semi-trusted|untrusted]
#### 🔴 Blockers
- [file:line] - [vulnerability] - [exact fix]
#### 🟡 Warnings
- [risk] - [next action]
#### ✅ Verified
- [verified control]
Take hoangnguyen0403/security-test from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.