From file to useful result
How to ask with this skill installed
Installing the skill gives your AI a method. Your request still has to provide the case-specific facts, constraints and expected output.
Describe the decision or deliverable, not just the topic.
Add source material, audience, limits and known facts.
Set format, quality criteria and checks.
When to use it
Use this skill when:
- Reading or interpreting static analysis scan results in SARIF format
- Aggregating findings from multiple security tools
- Deduplicating or filtering security alerts
- Extracting specific vulnerabilities from SARIF files
- Integrating SARIF data into CI/CD pipelines
- Converting SARIF output to other formats
When not to use it
Do NOT use this skill for:
- Running static analysis scans (use CodeQL or Semgrep skills instead)
- Writing CodeQL or Semgrep rules (use their respective skills)
- Analyzing source code directly (SARIF is for processing existing scan results)
- Triaging findings without SARIF input (use variant-analysis or audit skills)