Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,11 +1,10 @@
---
name: implementing-devsecops-security-scanning
description: 'Integrates Static Application Security Testing (SAST), Dynamic Application
Security Testing (DAST), and Software Composition Analysis (SCA) into CI/CD pipelines
using open-source tools. Covers Semgrep for SAST, Trivy for SCA and container scanning,
OWASP ZAP for DAST, and Gitleaks for secrets detection. Activates for requests involving
DevSecOps pipeline setup, automated security scanning in CI/CD, SAST/DAST/SCA integration,
or shift-left security implementation.
description: 'Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for
SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for
secrets detection. Use when setting up automated security scanning in CI/CD, shifting
security left, meeting compliance mandates (SOC 2, PCI-DSS, ISO 27001), or gating
deployments on critical vulnerabilities.
'
domain: cybersecurity