概要
This skill provides specialized guidance for implementing and managing Static Application Security Testing (SAST) tools like Semgrep, SonarQube, and CodeQL. It enables Claude to assist developers in setting up automated security scans, creating custom vulnerability detection rules, and integrating security quality gates directly into CI/CD pipelines. By automating the identification of security flaws early in the software development lifecycle, this skill helps teams maintain high security standards, reduce technical debt, and ensure compliance with industry frameworks such as PCI-DSS and SOC 2.