security-workflow

Convert security findings into backlog tasks with severity-based priorities and acceptance criteria.

50|9|Updated Oct 15, 2025
One-click install
npx skills add https://github.com/jpoley/flowspec --skill security-workflow
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-workflow
Source: https://github.com/jpoley/flowspec/tree/main/.claude/skills/security-workflow
Command: npx skills add https://github.com/jpoley/flowspec --skill security-workflow

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill translates security findings into actionable backlog tasks, enabling seamless remediation tracking within development workflows.

Core Features & Use Cases

  • Task creation from security findings: Convert vulnerabilities into well-scoped backlog tasks with clear acceptance criteria.
  • Workflow integration: Map findings into existing flow states and automations to drive remediation.
  • Prioritization & labeling: Apply severity-based priorities and labels to tasks for effective triage and assignment.
  • AC generation: Produce verifiable acceptance criteria and references for each security remediation.

Quick Start

Use the security-workflow skill to triage a security finding and create a backlog task.

Frequently Asked Questions about security-workflow

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I convert security findings into backlog tasks?

Security findings convert to backlog tasks by mapping vulnerabilities into well-scoped work items with severity-based priorities, acceptance criteria, and labels. This automation streamlines remediation tracking within your development workflow and ensures consistent task formatting across your backlog.

Can I automate security task creation from vulnerability scans?

Yes. Security scanning results automatically generate backlog tasks with acceptance criteria, priority mapping tied to severity levels, and labels for triage. Integration hooks connect to flowspec workflows to drive remediation through your existing processes.

What's the best way to prioritize security remediation work?

Prioritization maps vulnerability severity directly to task priority levels, ensuring high-risk findings surface first in your backlog. Combined with labeling and acceptance criteria generation, this approach standardizes how security work gets triaged and assigned across teams.

How do security findings flow into workflow automation?

Security findings integrate into flowspec workflows through configurable automation hooks that transition tasks through defined flow states. This connects vulnerability remediation to your existing development workflow, enabling tracking from discovery through resolution.

Do I need acceptance criteria for security tasks?

Acceptance criteria are auto-generated for each security remediation task, providing verifiable conditions and references tied to the original finding. This ensures clear scope and measurable completion standards for remediation work.

Can I label and track security tasks within my backlog?

Security tasks receive automatic labels and severity-based priorities that make them discoverable and sortable within your backlog. This enables effective triage, assignment routing, and progress tracking on security remediation work.