25-security-scanning-vulnerability-research

Analyze codebase vulnerabilities and create Jira security tickets.

1|Updated Apr 30, 2026
One-click install
npx skills add https://github.com/rhpds/claude-code-courseware --skill 25-security-scanning-vulnerability-research
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: 25-security-scanning-vulnerability-research
Source: https://github.com/rhpds/claude-code-courseware/tree/main/lola/ccc/skills/25-security-scanning-vulnerability-research
Command: npx skills add https://github.com/rhpds/claude-code-courseware --skill 25-security-scanning-vulnerability-research

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps developers and security teams understand AI-powered vulnerability scanning, validate findings, and turn security issues into actionable remediation workflows.

Core Features & Use Cases

  • AI Security Scanning Guidance: Learn how Claude Security scanning, multi-stage verification, and vulnerability analysis workflows identify and validate security issues.
  • Finding Triage Workflows: Assess vulnerabilities by severity, exploitability, impact, and remediation priority across Critical, High, Medium, and Low categories.
  • Security Team Integration: Connect scan results with Jira workflows, exports, notifications, and responsible disclosure practices for real-world security operations.

Quick Start

Use the security scanning skill to review my project for vulnerabilities, explain the findings, and help prioritize remediation steps.

Frequently Asked Questions about 25-security-scanning-vulnerability-research

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan my codebase for security vulnerabilities using AI?▼

Finding triage assesses security vulnerabilities by severity, exploitability, impact, and remediation priority across Critical, High, Medium, and Low categories to prioritize remediation steps.

Can I create Jira tickets from SAST and LLM-based vulnerability findings?▼

Yes, security scanning workflows connect validated vulnerability findings with Jira workflows, exports, and notifications to track real-world security operations and remediation planning.

What is the difference between SAST and LLM-based security audits?▼

SAST and LLM-based audits differ in their approach to vulnerability research, with AI-powered scanning applying multi-stage verification workflows to validate security findings and reduce false positives compared to traditional static analysis.

Does Claude Code security review require specific dependencies for vulnerability research?▼

Claude Code security review requires security workflow integrations for validated findings and operational tracking, but operates without external dependencies to perform AI-powered vulnerability scanning and triage.