Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Fast, continuous DevSecOps pipeline for Pull Requests and active branches. Runs SAST, SCA, and secrets detection to catch vulnerabilities before they merge.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-04 | ✗→✓ | ▲ Improved | -11% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -51% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 12% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -1% | 0% |
| case-16 | ✗→✓ | ▲ Improved | -33% | 0% |
> !IMPORTANT] > Fast, continuous DevSecOps pipeline for Pull Requests and active branches. Runs SAST, SCA, and secrets detection to catch vulnerabilities before they merge.
Optional args: slug=<feature>, ticket=<id/url>, mode=interactive|autonomous|channel, channel=<id>, auto_continue=true|false, profile=business|hybrid|technical.
When the user asks to perform this workflow, execute the following steps:
> Goal: Execute a high-speed security audit on a branch or PR delta and stop obvious security regressions before merge. > > Policy: Fast execution (< 2 mins). Focus on SAST, SCA, secrets, and trust-boundary regressions. No dynamic exploitation required.
git diff <base>...HEAD.<SKILLS>/common/common-security-audit/references/trust-review-policy.md.reviewContext.promptInjectionRisk to high unless host controls clearly reduce that risk.specialist-aspm-correlator.specialist-security-reviewer in fast mode for normal diffs and deep mode for auth, secrets, agent tools, or external integration changes.design-solution evidence or return BLOCKED with the missing design questions.artifacts/security-review.md with trust class, review context, scope, source provenance, runtime contract, blockers, warnings, finding confidence, exploit path, evidence gaps, and handoff notes.artifacts/security-review.dev.md, artifacts/security-review.appsec.md, or artifacts/security-review.exec.md only when a separate audience needs it.markdown### 🛡️ Security Check: [PASS / FAIL] **Scan Scope**: [branch/diff size] **Trust Class**: [trusted|semi-trusted|untrusted] #### 🔴 Blockers - [file:line] - [vulnerability] - [exact fix] #### 🟡 Warnings - [risk] - [next action] #### ✅ Verified - [verified control]
Other measured skills in the registry, with their headline benchmark lift.