Favicon of security-analysis

security-analysis Skill

AI Agent SkillSecurityPythonOpen source

Dependabot and security analysis skill for HASTE. Parse alerts, group related vulnerabilities, apply severity rules, and produce structured reports. Use when: 'Dependabot alert', 'security scan', 'vulnerability triage', 'dependency audit', 'npm audit', 'pip audit', 'CVE analysis'. Published by microsoft in haste.

What is security-analysis Skill?

Dependabot and security analysis skill for HASTE. Parse alerts, group related vulnerabilities, apply severity rules, and produce structured reports. Use when: 'Dependabot alert', 'security scan', 'vulnerability triage', 'dependency audit', 'npm audit', 'pip audit', 'CVE analysis'. Published by microsoft in haste. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
41/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Security review
  • Data analysis
  • Design and media
  • Security review use cases
  • Data analysis use cases

Technical details

Copy skill directory
  • Install or run with Copy skill directory

When to use security-analysis Skill

  • Use it for security review.
  • Use it for data analysis.
  • Use it for design and media.

Built with

PythonCopy skill directory

Editorial notes

Source

  • Creator: microsoft
  • Repository: microsoft/haste
  • Skill file: .github/skills/security-analysis/SKILL.md

What it does

Dependabot and security analysis skill for HASTE. Parse alerts, group related vulnerabilities, apply severity rules, and produce structured reports. Use when: 'Dependabot alert', 'security scan', 'vulnerability triage', 'dependency audit', 'npm audit', 'pip audit', 'CVE analysis'.

Skill instructions

Security Analysis Overview Structured process for triaging Dependabot alerts, grouping related vulnerabilities, applying severity rules, and producing actionable reports for HASTE's Python and JavaScript dependency stacks. Key Concepts HASTE Dependency Landscape | Stack | Location | Tool | Key Risks | |-------|----------|------|-----------| | Python (API) | api/hastefuncapi/requirements.txt | pip audit | GDAL parsing, Azure SDK, rasterio | | Python (Queues) | api/hastefuncqueues/requirements.txt | pip audit | Same as API | | Python (Core) | hastelib/pyproject.toml | pip audit | Geospatial libs, ML deps | | JavaScript (UI) | ui/package.json | npm audit | FluentUI, MSAL, build tools | | JavaScript (Root) | package.json | npm audit | Azurite (dev only) | Severity Rules | Severity | Action | SLA | |----------|--------|-----| | Critical | Investigate immediately, create issue | Same day | | High | Investigate promptly, create issue | 3 business days | | Medium | Queue for next sprint | Next

Explore related resources

Frequently asked questions

What is security-analysis?

security-analysis is a open-source AI agent skill with Copy skill directory. Dependabot and security analysis skill for HASTE. Parse alerts, group related vulnerabilities, apply severity rules, and produce structured reports.

Who is security-analysis best for?

security-analysis is best for reusing agent instructions, scripts, and references, security review workflows, data analysis workflows, design and media workflows.

How do I install security-analysis?

Install or run security-analysis using Copy skill directory. Check security-analysis for the latest setup command.

Is security-analysis actively maintained?

security-analysis may need a closer maintenance check before production use.

Share:

Stars
43
Forks
5
Last commit
9 days ago
Repository age
3 months
License
MIT

Auto-fetched from GitHub.

Similar to security-analysis