Favicon of gh-code-scanning

gh-code-scanning Skill

AI Agent SkillPowerShellOpen source

Retrieves and groups GitHub code scanning alerts by rule and severity using the gh CLI Published by microsoft in hve-core.

What is gh-code-scanning Skill?

Retrieves and groups GitHub code scanning alerts by rule and severity using the gh CLI Published by microsoft in hve-core. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
77/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Security review
  • Data analysis
  • Security review use cases
  • Data analysis use cases

Technical details

Copy skill directory
  • Install or run with Copy skill directory

When to use gh-code-scanning Skill

  • Use it for security review.
  • Use it for data analysis.

Built with

PowerShellCopy skill directory

Editorial notes

Source

  • Creator: microsoft
  • Repository: microsoft/hve-core
  • Skill file: .github/skills/github/gh-code-scanning/SKILL.md

What it does

Retrieves and groups GitHub code scanning alerts by rule and severity using the gh CLI

Skill instructions

GitHub Code Scanning Skill Overview GitHub code scanning alerts are produced by static analysis tools such as CodeQL and Scorecard and surfaced in the GitHub Security tab. The GitHub Security tab is not accessible through the default MCP toolset, so this skill provides scripts for all read operations. Prerequisites | Requirement | Details | |-------------|-------------------------------------------------------------------------| | pwsh | PowerShell 7+; install from <https://learn.microsoft.com/powershell | | gh CLI | Installed and on PATH; install from <https://cli.github.com | | Auth | Run gh auth login or set GHTOKEN; requires securityevents scope | | Scope | securityevents for private repos; publicrepo for public-only | The repo scope also satisfies securityevents. The gh CLI handles authentication automatically; no explicit token passing is needed in commands. Get-CodeScanningAlerts.ps1 validates both prerequisites at startup and aborts with a targeted error message if either check

Explore related resources

Frequently asked questions

What is gh-code-scanning?

gh-code-scanning is a open-source AI agent skill with Copy skill directory. Retrieves and groups GitHub code scanning alerts by rule and severity using the gh CLI

Who is gh-code-scanning best for?

gh-code-scanning is best for reusing agent instructions, scripts, and references, security review workflows, data analysis workflows.

How do I install gh-code-scanning?

Install or run gh-code-scanning using Copy skill directory. Check gh-code-scanning for the latest setup command.

Is gh-code-scanning actively maintained?

gh-code-scanning may need a closer maintenance check before production use.

Share:

Stars
1,263
Forks
229
Last commit
9 days ago
Repository age
9 months
License
MIT

Auto-fetched from GitHub.

Ad
Favicon

 

  
 

Similar to gh-code-scanning

gh-code-scanning: Install, Config & GitHub Signals – SkillIndex