fortify

14 mods across 1 repository, 19 stars between them.

fortify

01

fortify/skills

Plugin Claude Code

Plugin marketplace listing 1 plugin: fortify-skills.

19 1mo ago A tokens not measured original MIT

fortify

02

fortify/skills

Plugin Claude Code

OpenText Fortify AppSec skills. Use for SAST/DAST/SCA scanning, vulnerability triage, audit workflows, CI/CD pipeline integration, and FCLI commands. Supports Fortify on Demand (FoD) and Software Security Center (SSC).

19 1mo ago A tokens not measured original MIT

fortify/skills

Instructions file GitHub Copilot

Instructions for fortify/skills, covering fortify skills repository, structure, conventions, workflow terminology and reference path rules (per agent skills spec).

19 1mo ago A 1,613 tokens original MIT

fortify/skills

Agent

Orchestrate batch CVE exploitability analysis across many known advisories. Activate to triage a list of CVEs/GHSAs for reachability in a codebase — sourced from an SBOM, a Fortify on Demand release, a Fortify SSC application version, a local file (CSV/JSON/text), or an explicitly provided list. Never discovers CVEs…

19 1mo ago A 121 tokens original MIT

fortify-onboarding

05

fortify/skills

Agent

Orchestrate end-to-end onboarding of new applications into Fortify (FoD or SSC). Activate to create one or more new Fortify applications, set up a project or repo for Fortify scanning, or onboard an entire GitHub/GitLab/Azure DevOps organization. Handles app creation and optional CI/CD pipeline setup (PR included).

19 1mo ago A 74 tokens original MIT

fcli-common

06

fortify/skills

Skill Claude CodeCodex

Generic reference for the Fortify CLI (fcli). Install, upgrade, authenticate, fcli environment variables, output formats, SpEL query syntax, variable chaining and custom action framework.

19 1mo ago A 41 tokens original MIT

fortify/skills

Skill Claude CodeCodex

Lightweight, AI-powered security review of code CHANGES (a diff, PR, or in-session edits) using the agent's own analysis — no Fortify scan engine or platform needed. Use when the user asks to "run a Fortify security review" / "Fortify change review", or when adding/modifying code touching authentication…

19 1mo ago A 161 tokens original MIT

fortify/skills

Skill Claude CodeCodex

Integrate Fortify application security (SAST, SCA, DAST) with GitHub Actions, GitLab Pipelines, Azure DevOps, Jenkins & other CICD/DevSecOps pipelines.

19 1mo ago A 49 tokens original MIT

fortify-create-app

09

fortify/skills

Skill Claude CodeCodex

Create new Fortify application(s) in Fortify on Demand (FoD) or Application Security Center (SSC).

19 1mo ago A 28 tokens original MIT

fortify/skills

Skill Claude CodeCodex

Perform dependency upgrade impact assessment, code fixes, and migration work. Use to remediate Fortify SCA / open source / software composition analysis findings — vulnerable third-party dependencies, CVEs/GHSAs, components flagged by FoD or SSC — by upgrading to a safe version and fixing any resulting breakage. Also…

19 1mo ago C 209 tokens original MIT

fortify/skills

Skill Claude CodeCodex

Triage whether a known CVE/GHSA vulnerability is actually exploitable in this project. Use when the user wants a reachability verdict on a specific advisory — is the project really affected, or is the advisory noise? Analysis only; for fixes, hand off to fortify-dependency-upgrade.

19 1mo ago A 68 tokens original MIT

fortify-fod

12

fortify/skills

Skill Claude CodeCodex

Perform tasks against Fortify on Demand (FoD): query applications/releases; query & triage existing security issues in FoD; start & monitor full SAST/DAST/SCA/open source scans of the codebase; create releases; import FPR/SARIF/CycloneDX artifacts; policy and portfolio analysis. NOT for lightweight AI review of local…

19 1mo ago A 88 tokens original MIT

fortify-remediate

13

fortify/skills

Skill Claude CodeCodex

Remediate SAST (static) and DAST (dynamic) security vulnerabilities ALREADY detected by Fortify in FoD or SSC — fix specific issues, categories, or reduce issue counts, including applying SAST Aviator fixes. For SCA / open source dependency findings (vulnerable third-party components, CVEs), use…

19 1mo ago A 117 tokens original MIT

fortify-ssc

14

fortify/skills

Skill Claude CodeCodex

Perform tasks against Fortify SSC (Software Security Center): query applications/application versions; query & triage existing security issues in SSC; start & monitor full ScanCentral SAST/DAST scans or upload FPR artifacts; create app versions; policy and portfolio analysis. NOT for lightweight AI review of local…

19 1mo ago A 76 tokens original MIT