← ClaudeAtlas

sumo-qa-security-testinglisted

Use when explicit security testing or a grounded security gap needs deeper evidence selection.
sumithr/sumo-qa · ★ 6 · Testing & QA · score 71
Install: claude install-skill sumithr/sumo-qa
# Security Testing Security testing here means turning an already grounded security concern into the smallest evidence that can prove the risk is covered. It is a routed specialist path after normal QA classification, not a replacement for `sumo-qa-deciding-approach`. **Announce at start:** *"Focusing the security test evidence."* ## Output discipline (mandatory) Inherits the global discipline from `using-sumo-qa`: grounded risks only, no internal taxonomy labels in user output, no vulnerability checklist dump, no vendor/tool-name dump, and no external setup without confirmation. ## Output economy (mandatory) Spend output tokens on the security brief: risk, anchor, evidence choice, first action, and residual risk. ## The Iron Law Grounded risk first, tool second. Do not recommend a scanner, external skill, live probe, or dependency install until the concrete security failure mode, source anchor, and native evidence fit have been checked. ## When to Use Use after `sumo-qa-deciding-approach` routes an explicit security-testing request here, or after another sumo-qa workflow has named a material security gap that needs deeper treatment than a normal regression test / review line. Do not use for low-evidence prompts; ask for the missing scope or stop short. ## Checklist 1. Confirm the source anchor: file, flow, config, dependency, data path, or explicit user-stated scope. If none exists, ask one scope question; stop. No hypothetical risks/actions. 2. Load `sumo_qa_loa