ops-suppress-correctly

Apply compliant AEGIS suppressions with rationale, owner, and review dates.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/RideMatch1/a.e.g.i.s --skill ops-suppress-correctly
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ops-suppress-correctly
Source: https://github.com/RideMatch1/a.e.g.i.s/tree/main/packages/skills/skills/ops/aegis-native/suppress-correctly
Command: npx skills add https://github.com/RideMatch1/a.e.g.i.s --skill ops-suppress-correctly

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Suppression runbooks enable teams to manage when and how to suppress scanner findings in a controlled, auditable manner, ensuring false positives are handled appropriately without masking real issues.

Core Features & Use Cases

  • Per-finding suppressions with explicit rationale and ownership.
  • Config-level suppressions for centralized auditability.
  • Pattern-level suppressions for canonical platform-wide controls.
  • Clear decay/review cadence and audit-trail expectations to stay compliant.

Quick Start

Create a suppression entry only after verification and documentation of rationale, owner, and review date.

Frequently Asked Questions about ops-suppress-correctly

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I suppress false positives in AEGIS scanner findings?

Config-level suppressions provide centralized auditability for AEGIS findings, while per-finding suppressions target individual scanner alerts. Both approaches require explicit rationale, designated ownership, and defined review dates to maintain compliant audit trails across workflows.

What are the anti-patterns to avoid when suppressing security auditing findings?

A primary anti-pattern when suppressing security auditing findings is masking real issues by omitting required metadata. Suppressing findings without verifying them first or missing the decay window and review date compromises audit trails and creates dangerous security blind spots.

How do I apply pattern-level suppressions for platform-wide security controls?

Pattern-level suppressions apply canonical controls across platform-wide security findings. To apply them safely, you must enforce explicit rationale, assign an owner, and configure a decay window to ensure the suppression expires and receives mandatory future review.

Why should I include a decay window and review date for security suppressions?

Including a decay window and review date for security suppressions ensures findings are periodically re-evaluated rather than permanently ignored. This prevents outdated false positive suppressions from masking newly introduced real vulnerabilities over time, maintaining strict auditing compliance.