← ClaudeAtlas

ghas-feature-researchlisted

On-demand Category 1 researcher for a specific GitHub Advanced Security feature — secret scanning push protection, code scanning autofix, security campaigns, dependency review action, security advisories database, custom auto-triage rules. For a chosen feature, produces a research note with current state, rollout caveats, regulated-org applicability, and recommendations. Output at vault/research/ghas/YYYY-MM-DD-{feature-slug}.md. Composes with ghas-config-reviewer (baseline-checking side) and the various GHAS-touching ops skills. Use when the user asks to research a single GHAS feature in depth — adoption, rollout, tuning, regulated-org caveats — producing a fresh, cited research note; not for checking a repo or org config against the baseline (ghas-config-reviewer), Dependabot strategy questions (dependabot-strategy), or platform-wide GitHub questions (github-platform-watch).
themarmack/research-bot · ★ 0 · AI & Automation · score 68
Install: claude install-skill themarmack/research-bot
# ghas-feature-research A focused-on-one-feature research skill. Where `ghas-config-reviewer` checks baseline posture and `github-platform-watch` covers the whole platform, this skill goes deep on a specific GHAS feature when adoption / rollout / tuning needs a research-grade answer. ## When to use - New GHAS feature announced (e.g., code-scanning autofix in 2025; security campaigns in 2026). - Rollout planning for an existing-but-underused GHAS feature. - Deciding default vs advanced for a specific GHAS component on a target repo set. - Pre-procurement / TPRM review when a GHAS feature is a contract dimension. ## Topic taxonomy - `secret-scanning` — push protection, partner patterns, custom patterns - `code-scanning` — default-setup, advanced-setup, autofix - `dependency-review` — PR-time dep review, configuration - `security-campaigns` — newer aggregated-finding workflow - `dependabot` — already covered in detail by `dependabot-strategy`; route there - `auto-triage-rules` — alert-volume management ## Obsidian-first workflow (mandatory) 1. **Query the vault first** via `vault-querier`: - Full-text search the feature's key terms across `vault/research/ghas/**`, `vault/research/github/**`, `vault/facts/github/**`, `vault/facts/ghas-dependabot/**`, and recent `vault/digests/**` (last 90 days — `biweekly-codeql-community-pulse` and `weekly-intelligence-digest` often carry GHAS feature news). - Backlink check on the feature's entity (e.g. `[[secret-scanning]]`, `[[co