performing-web-application-vulnerability-triage
Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP.
What this skill does for you
Triages web application vulnerability findings from DAST/SAST scanners such as Burp Suite and ZAP, using the OWASP Risk Rating Methodology to confirm true positives, dismiss false positives, and prioritize remediation. Use when reviewing scanner output to reduce alert fatigue and rank vulnerabilities for development teams to fix.
Quoted from the skill description in the pinned sourceWho made it
Use it with Edge
Set up Edge for me: read getedge.cc/SKILL.md and follow it. Then use Edge to load the performing-web-application-vulnerability-triage skill from mukul975/anthropic-cybersecurity-skills.
Paste it into Claude, ChatGPT, Codex or Cursor.
Or read the skill source first.
Security evidence
| Scanner | Date | Result | Findings |
|---|---|---|---|
| Edge static checks | 2026-09-27 | Pass | 0 |
| Cisco skill-scanner | 2026-09-27 | Pass | 0 |
| Semgrep Edge rules | 2026-09-27 | Pass | 0 |
Static scans check the code, not how well the skill works.
Scanner scope, raw findings and mirrored provider records
Socket (skills.sh mirror): Version unavailable. Scope: Not supplied by the mirrored record. Revision: not supplied. Raw findings: not supplied. Counted findings: Not supplied.
Snyk (skills.sh mirror): Version unavailable. Scope: Not supplied by the mirrored record. Revision: not supplied. Raw findings: not supplied. Counted findings: Not supplied.
Edge static checks (Edge-run): edge-static/1.0.1. Scope: Static patterns for remote execution, credentials with network sends, obfuscation, prompt overrides, hidden Unicode, binaries and persistence. Revision: 54a798831d2266a3ca61ce68a7acb80b81160d57. Raw findings: . Counted findings: .
Cisco skill-scanner (Edge-run): cisco-skill-scanner/2.1.0. Scope: Local static, YARA, pipeline and behavioral analyzers; no LLM or AI Defense analysis. Revision: 54a798831d2266a3ca61ce68a7acb80b81160d57. Raw findings: . Counted findings: .
Semgrep Edge rules (Edge-run): semgrep/1.178.0+edge-rules.c15016a36fd3+offline-v1. Scope: Six Edge-authored static rules with Semgrep CE; offline execution and metrics disabled. Semgrep-maintained rules excluded. Revision: 54a798831d2266a3ca61ce68a7acb80b81160d57. Raw findings: . Counted findings: .
Source and licence
- Repository
- https://github.com/mukul975/anthropic-cybersecurity-skills
- Pinned skill file
- View source at revision
- Revision
- 54a798831d2266a3ca61ce68a7acb80b81160d57
- Package hash
- sha256:25826da0992618673d8f7c98bb15b4daf5d4fdf1de64ccdd9e57a95fb614b6c1
- Licence
- Apache-2.0