Turn security scan noise into actionable findings

Ingests SARIF output from CodeQL, Semgrep, or any static analyzer; deduplicates false positives, groups by severity and type, and surfaces the real vulnerabilities worth fixing first.

Best for: Engineers triaging security scan results without drowning in duplicate alerts.

Engineering / debugging-investigationatomicfor-engineerslight-setupfrom-file

Topics

agent-skills

Source

Creator's repository · trailofbits/skills

View on GitHub

License: CC-BY-SA-4.0