What problem does it solve?
This Skill automates the analysis and triage of AI SAST findings, streamlining the process of identifying and remediating security vulnerabilities in code repositories.
Core Features & Use Cases
- AI SAST Finding Analysis: Parses AI SAST findings from Endor and provides a detailed breakdown of each finding.
- Exploit Reproduction: Uses exploit reproduction to prioritize and validate findings.
- Remediation Guidance: Incorporates remediation guidance to create context-aware patches.
- Change Request Creation: Generates change requests with a full context for review.
- Exception Policy Creation: Optionally creates exception policies for false positives or accepted risks.
- Ticket Creation: Optionally creates tickets for further investigation.
- Use Case: After running an AI SAST scan on your code repository, use this Skill to automatically analyze the findings and create change requests for remediation, without manual intervention.
Quick Start
Use the @ai-sast-triage skill to analyze and triage AI SAST findings for this repository. Do not edit files, open a PR/MR, or create an Endor policy unless I approve the specific gate.