Stand up tuned application security scanning in CI: SAST + SCA per-PR, DAST on a deployed build, secret-scanning, and triage by exploitability×blast-radius rather than raw CVSS.
Scanned 9/23/2026
npx -y skills add mcorbett51090/RavenClaude --skill appsec-scanning --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Appsec Scanning?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/mcorbett51090-appsec-scanning)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: appsec-scanning
description: "Stand up tuned application security scanning in CI: SAST + SCA per-PR, DAST on a deployed build, secret-scanning, and triage by exploitability×blast-radius rather than raw CVSS."
---
# AppSec Scanning in CI
**Purpose:** catch vulnerabilities early and act on the real ones.
## The gate
- **SAST** + **SCA** on every PR (fast, tuned).
- **DAST** against a deployed build (post-merge / nightly).
- **Secret scanning** on every commit — a leaked secret is compromised.
## Triage
Rank by **exploitability × blast radius**, not CVSS alone. Reachability beats severity: a 9.8 in dead code < a 6.5 on an unauthenticated endpoint.
## Fix the class
One SQLi -> parameterize everywhere + a lint rule. Don't whack-a-mole instances.
## Route the verdict
Propose the control + residual risk; `security-reviewer` decides ship/no-ship.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!