CtrlK
BlogDocsLog inGet started
Tessl Logo

testland/multi-tool-finding-triage

Merges two or more security scanner reports into one gate. Use when you need a single BLOCK or PASS decision from multiple scanners instead of reading N separate reports. Normalizes each report into one common finding format (a canonical `Finding`), deduplicates on a per-domain key while recording which scanners agree (`caught_by` consensus), validates a waiver (finding-suppression) file, rejecting any missing `expires:` / `approved_by:` / `reason:` or expired, enriches CVE findings with EPSS (exploit-probability) and CISA KEV (known-exploited catalog), then applies a `fail_on` severity threshold to emit BLOCK or PASS plus a bucketed pull-request comment. Works across static (SAST), dynamic (DAST), secret, dependency (SCA), container, and IaC scanners. To run a single scanner instead use semgrep-rules, codeql-queries, or one of the language-native-sast linters; this runs after them to merge output - the cross-scanner gate, not a single-scanner wrapper.

77

Quality

97%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Low

Low-risk findings worth noting

Overview
Quality
Evals
Security
Files
Low

W011: Third-party content exposure detected (indirect prompt injection risk).

What this means

The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.

Why it was flagged

The required workflow fetches and ingests CISA KEV and EPSS vulnerability feeds over HTTP, which contain outsider-published vulnerability descriptions and data.

Where we found it

epss.empiricalsecurity.com

domain · 2 sites

The plugin's CI workflow fetches the EPSS vulnerability feed from epss.empiricalsecurity.com at runtime and ingests it to enrich CVE findings with exploit probability scores.

SKILL.md

270

curl -sL https://epss.empiricalsecurity.com/epss_scores-current.csv.gz | gunzip > epss.csv

references/cve-enrichment.md

21

curl -sL https://epss.empiricalsecurity.com/epss_scores-current.csv.gz | gunzip > epss.csv

www.cisa.gov

domain · 5 sites

The plugin's CI workflow fetches the CISA KEV vulnerability feed from www.cisa.gov at runtime and ingests it to enrich CVE findings with known-exploited status.

SKILL.md

271

curl -s https://www.cisa.[REDACTED].json -o kev.json

319

(https://www.cisa.[REDACTED].json).

references/cve-enrichment.md

17

(https://www.cisa.[REDACTED].json).

29

curl -s https://www.cisa.[REDACTED].json -o kev.json

references/waiver-schema.md

70

(https://www.cisa.[REDACTED].json).

api.first.org

domain · 1 site

The plugin documents an alternative EPSS per-CVE API endpoint at api.first.org that can be used to fetch exploit probability scores for individual CVEs.

references/cve-enrichment.md

25

curl -s "https://api.first.org/data/v1/epss?cve=CVE-2021-44228"

Report incorrect finding
Audited
Security analysis
Snyk