Merges two or more security scanner reports into one gate. Use when you need a single BLOCK or PASS decision from multiple scanners instead of reading N separate reports. Normalizes each report into one common finding format (a canonical `Finding`), deduplicates on a per-domain key while recording which scanners agree (`caught_by` consensus), validates a waiver (finding-suppression) file, rejecting any missing `expires:` / `approved_by:` / `reason:` or expired, enriches CVE findings with EPSS (exploit-probability) and CISA KEV (known-exploited catalog), then applies a `fail_on` severity threshold to emit BLOCK or PASS plus a bucketed pull-request comment. Works across static (SAST), dynamic (DAST), secret, dependency (SCA), container, and IaC scanners. To run a single scanner instead use semgrep-rules, codeql-queries, or one of the language-native-sast linters; this runs after them to merge output - the cross-scanner gate, not a single-scanner wrapper.
77
97%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
Low
Low-risk findings worth noting
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The required workflow fetches and ingests CISA KEV and EPSS vulnerability feeds over HTTP, which contain outsider-published vulnerability descriptions and data.
epss.empiricalsecurity.com
domain · 2 sites
The plugin's CI workflow fetches the EPSS vulnerability feed from epss.empiricalsecurity.com at runtime and ingests it to enrich CVE findings with exploit probability scores.
SKILL.md
270
curl -sL https://epss.empiricalsecurity.com/epss_scores-current.csv.gz | gunzip > epss.csv
references/cve-enrichment.md
21
curl -sL https://epss.empiricalsecurity.com/epss_scores-current.csv.gz | gunzip > epss.csv
www.cisa.gov
domain · 5 sites
The plugin's CI workflow fetches the CISA KEV vulnerability feed from www.cisa.gov at runtime and ingests it to enrich CVE findings with known-exploited status.
SKILL.md
271
curl -s https://www.cisa.[REDACTED].json -o kev.json
319
(https://www.cisa.[REDACTED].json).
references/cve-enrichment.md
17
(https://www.cisa.[REDACTED].json).
29
curl -s https://www.cisa.[REDACTED].json -o kev.json
references/waiver-schema.md
70
(https://www.cisa.[REDACTED].json).
api.first.org
domain · 1 site
The plugin documents an alternative EPSS per-CVE API endpoint at api.first.org that can be used to fetch exploit probability scores for individual CVEs.
references/cve-enrichment.md
25
curl -s "https://api.first.org/data/v1/epss?cve=CVE-2021-44228"