security-testing - Automate security testing across CI/CD
Automates SAST, DAST, SCA, secret, IaC, container, and abuse testing with ASVS checks, CVSS triage, and severity-based CI/CD gates.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Define ASVS testing scope
- Map threats to controls
- Select seven testing layers
- Embed scans into CI/CD
- Write security abuse tests
- Set severity-based gates
- Triage findings with CVSS
- Manage audited suppressions
- Assign owners and SLAs
- Produce security gate reports
Inputs
- ASVS target level
- Technology stack
- Application artifacts
- CI/CD platform
- Threat model inputs
- Risk appetite
- Severity SLAs
- Security ownership
- Existing scanners
- Baseline files
- Suppression files
- Open findings
Outputs
- CI/CD security test stages
- Severity gating policy
- Security scan findings
- CVSS triage register
- ASVS checklist
- SBOM artifacts
- Suppression audit trail
- Security gate report
- Finding ownership assignments
- Remediation tracking status
Requirements
- CI/CD platform access
- Repository history access
- Deployed staging environment
- Security scanner integration
- ASVS reference
- Threat model availability
