Generate consolidated security report

sast-reportskillsetup L10
reasonless-throne486/sast-skills
What it does

Rank and consolidate SAST vulnerability findings by severity

Best for

Executive-facing security report consolidating 10+ vulnerability types into one prioritized list

Inputs
  • · sast/*-results.md (all scan output files)
Outputs
  • · sast/final-report.md (ranked by Critical/High/Medium/Low + confidentiality)
Requires
  • · SAST scan results (RCE, SQLi, SSRF, XSS, IDOR, XXE, etc.)
  • · severity scoring table
Preconditions

At least one sast/*-results.md file exists, all scans completed first

Failure modes
  • · Missing scan result files (incomplete run)
  • · Inconsistent severity naming across scan types
  • · Duplicate findings across scans (manual dedup needed)
  • · Missing architectu re.md context
Trust signals
  • · Severity ranking table provided (RCE=Critical, SSTI=Critical, SQLi=High-Critical, IDOR=Medium-High)
  • · Confidentiality impact as tiebreaker
  • · Appendix shows scan coverage
  • · Sample report format matches real SAST output