Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,12 +1,6 @@
---
name: integrating-sast-into-github-actions-pipeline
description: 'This skill covers integrating Static Application Security Testing (SAST)
tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines. It addresses configuring
automated code scanning on pull requests and pushes, tuning rules to reduce false
positives, uploading SARIF results to GitHub Advanced Security, and establishing
quality gates that block merges when high-severity vulnerabilities are detected.
'
description: Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and merge-blocking quality gates for high-severity findings. Use when adding automated code vulnerability detection to CI, enforcing consistent SAST org-wide, or producing SOC 2/PCI DSS/NIST SSDF compliance evidence.
domain: cybersecurity
subdomain: devsecops
tags: