security-testing

Orchestrate SAST, DAST, and SCA workflows in CI/CD pipelines.

Updated Mar 29, 2026
One-click install
npx skills add https://github.com/marquesfelip/agents-and-skills --skill security-testing-marquesfelip
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-testing
Source: https://github.com/marquesfelip/agents-and-skills/tree/main/skills/security-testing
Command: npx skills add https://github.com/marquesfelip/agents-and-skills --skill security-testing-marquesfelip

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automate security validation across applications to consistently detect and mitigate vulnerabilities before they reach production.

Core Features & Use Cases

  • Design and implement automated SAST/DAST/SCA pipelines to cover codebases, containers, and cloud configurations.
  • Provide security-focused test planning, gap analysis against OWASP Top 10, and pre-release gate checks for compliance.
  • Prepare for penetration testing and security audits by generating structured evidence, test cases, and remediation guidance.

Quick Start

Configure your CI pipeline to run SAST, DAST, and SCA checks against your application, using Semgrep, Trivy, and OWASP ZAP.

Frequently Asked Questions about security-testing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate SAST, DAST, and SCA workflows in a CI/CD pipeline?

Automate security validation in your CI/CD pipeline by orchestrating SAST, DAST, and SCA workflows using tools like Semgrep, OWASP ZAP, and Trivy to enforce automated security gates across codebases and deployments.

What is the best way to perform OWASP Top 10 gap analysis for microservices?

Perform OWASP Top 10 gap analysis for microservices by automating security-focused test planning and validation across REST and GraphQL APIs, ensuring consistent detection and mitigation of vulnerabilities before production.

Can I integrate Snyk and Burp Suite for automated security testing of containers?

Yes, you can integrate Snyk and Burp Suite alongside Semgrep and Trivy to automate security testing across applications, containers, and cloud configurations within your automated validation pipelines.

How do I generate structured evidence and remediation guidance for a security audit?

Generate structured evidence, test cases, and remediation guidance for security audits by automating pre-release gate checks and vulnerability scanning workflows to prepare for penetration testing.

Does automated security testing support both REST and GraphQL APIs?

Yes, automated security validation supports testing both REST and GraphQL APIs, covering codebases, deployments, and third-party dependencies within your orchestrated SAST, DAST, and SCA workflows.