Skip to content

feat: add SAST/SCA Security Analyzer agent and audit-integrity skill#1458

Open
vijay-kr-bandi wants to merge 1 commit intogithub:stagedfrom
vijay-kr-bandi:feat/sast-sca-security-analyzer
Open

feat: add SAST/SCA Security Analyzer agent and audit-integrity skill#1458
vijay-kr-bandi wants to merge 1 commit intogithub:stagedfrom
vijay-kr-bandi:feat/sast-sca-security-analyzer

Conversation

@vijay-kr-bandi
Copy link
Copy Markdown

Pull Request Checklist

  • I have read and followed the CONTRIBUTING.md guidelines.
  • I have read and followed the Guidance for submissions involving paid services.
  • My contribution adds a new instruction, prompt, agent, skill, or workflow file in the correct directory.
  • The file follows the required naming convention.
  • The content is clearly structured and follows the example format.
  • I have tested my instructions, prompt, agent, skill, or workflow with GitHub Copilot.
  • I have run npm start and verified that README.md is up to date.
  • I am targeting the staged branch for this pull request.

Description

This PR adds two related contributions:

Agent — sast-sca-security-analyzer
A specialized AppSec agent that performs enterprise-grade Static Application Security Testing (SAST) and Software Composition Analysis (SCA). It detects CWE-mapped security flaws with file/line precision across C#, JavaScript/TypeScript, Python, Java, and PowerShell codebases using taint-flow analysis, and audits dependency manifests for CVEs, license risk, and supply chain threats. Produces structured reports with policy compliance evaluation (OWASP Top 10 2025, PCI-DSS v4.0, NIST SP 800-53, GDPR). References the bundled audit-integrity skill for shared quality gate enforcement.

Skill — audit-integrity
A reusable shared integrity framework for security analysis agents. Provides 7 components: Clarification Protocol, Anti-Rationalization Guard, Self-Critique Loop, Retry Protocol, Non-Negotiable Behaviors, Self-Reflection Quality Gate (1–10 scoring, ≥8 threshold), and a Self-Learning System with lesson/memory governance templates. Designed to be extended by any AppSec agent (threat modelers, code review agents, SAST/SCA agents).


Type of Contribution

  • New instruction file.
  • New prompt file.
  • New agent file.
  • New plugin.
  • New skill file.
  • New agentic workflow.
  • Update to existing instruction, prompt, agent, plugin, skill, or workflow.
  • Other (please specify):

Additional Notes

The audit-integrity skill is designed to be reused by any future threat modeling or code quality agents contributed to this repo.
README.agents.md and README.skills.md were regenerated via npm run build.


By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.

Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ This PR targets main, but PRs should target staged.

The main branch is auto-published from staged and should not receive direct PRs.
Please close this PR and re-open it against the staged branch.

You can change the base branch using the Edit button at the top of this PR,
or run: gh pr edit 1458 --base staged

@vijay-kr-bandi vijay-kr-bandi changed the base branch from main to staged April 20, 2026 21:38
@vijay-kr-bandi
Copy link
Copy Markdown
Author

⚠️ This PR targets main, but PRs should target staged.

The main branch is auto-published from staged and should not receive direct PRs. Please close this PR and re-open it against the staged branch.

You can change the base branch using the Edit button at the top of this PR, or run: gh pr edit 1458 --base staged

Done

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant