25-security-scanning-vulnerability-research

Analyze codebase vulnerabilities and create Jira security tickets.

1|Updated Apr 30, 2026
One-click install
npx skills add https://github.com/rhpds/claude-code-courseware --skill 25-security-scanning-vulnerability-research
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: 25-security-scanning-vulnerability-research
Source: https://github.com/rhpds/claude-code-courseware/tree/main/lola/ccc/skills/25-security-scanning-vulnerability-research
Command: npx skills add https://github.com/rhpds/claude-code-courseware --skill 25-security-scanning-vulnerability-research

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps developers and security teams understand AI-powered vulnerability scanning, validate findings, and turn security issues into actionable remediation workflows.

Core Features & Use Cases

  • AI Security Scanning Guidance: Learn how Claude Security scanning, multi-stage verification, and vulnerability analysis workflows identify and validate security issues.
  • Finding Triage Workflows: Assess vulnerabilities by severity, exploitability, impact, and remediation priority across Critical, High, Medium, and Low categories.
  • Security Team Integration: Connect scan results with Jira workflows, exports, notifications, and responsible disclosure practices for real-world security operations.

Quick Start

Use the security scanning skill to review my project for vulnerabilities, explain the findings, and help prioritize remediation steps.

Frequently Asked Questions about 25-security-scanning-vulnerability-research

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan my codebase for security vulnerabilities using AI?

Finding triage assesses security vulnerabilities by severity, exploitability, impact, and remediation priority across Critical, High, Medium, and Low categories to prioritize remediation steps.

Can I create Jira tickets from SAST and LLM-based vulnerability findings?

Yes, security scanning workflows connect validated vulnerability findings with Jira workflows, exports, and notifications to track real-world security operations and remediation planning.

What is the difference between SAST and LLM-based security audits?

SAST and LLM-based audits differ in their approach to vulnerability research, with AI-powered scanning applying multi-stage verification workflows to validate security findings and reduce false positives compared to traditional static analysis.

Does Claude Code security review require specific dependencies for vulnerability research?

Claude Code security review requires security workflow integrations for validated findings and operational tracking, but operates without external dependencies to perform AI-powered vulnerability scanning and triage.