导入 Code Scanning 告警
SkillMonitoring & opsLets your agent turn a code scanning alert into a tracked fix task without changing code.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the 导入 Code Scanning 告警 skill
About this skill
Import Code Scanning alerts and create fix tasks. Use when a Code Scanning alert needs to be converted into a tracked fix task.
What this skill tells your AI
The instructions your AI receives, as published by fitlab-ai/agent-infra in .agents/skills/import-codescan/SKILL.md and read by ahel’s review.
导入指定的 Code Scanning(CodeQL)告警并创建修复任务。
行为边界 / 关键规则
- 本技能仅负责导入告警并创建任务骨架 —— 不直接修改业务代码或关闭告警
- 不要自动提交。绝不自动执行
git commit或git add - 执行本技能后,你必须立即更新 task.md 中的任务状态
任务入参短号别名
如果
{task-id}入参匹配^[#]?[0-9]+$(裸数字或带#前缀),先读取.agents/rules/task-short-id.md的「SKILL 入参解析」段执行解析;后续命令视{task-id}为解析后的全长TASK-YYYYMMDD-HHMMSS形式。
步骤开始:记录开始时间
本技能会创建 task.md,开始时尚无文件可写。先在内存记录开始时间 started_at(date "+%Y-%m-%d %H:%M:%S%z" | sed 's/\([+-][0-9][0-9]\)\([0-9][0-9]\)$/\1:\2/');在最后写活动日志时一次性补两条——started 行用 started_at、done 行用完成时间,二者同基名(started 行 action 加 [started] 后缀、note 用 started):
- {started_at} — **Import Codescan [started]** by {agent} — started
- {done_at} — **Import Codescan** by {agent} — {完成说明}
ai task log 会按基名把两条配对成一行(进行中 → 已完成)。约定见 .agents/rules/task-management.md 的「Activity Log started / done 双标记约定」。
执行流程
1. 获取告警信息
执行前先读取 .agents/rules/security-alerts.md,然后运行 agent-infra-internal platform-security read --kind code-scanning --number {alert-number},解析其 JSON 结果获取告警详情。
提取关键信息:
number:告警编号state:状态(open/dismissed/fixed)rule:规则信息(id、severity、description、security_severity_level)tool:扫描工具信息(name、version)most_recent_instance:位置(path、start_line、end_line)、消息html_url:平台告警链接
2. 创建任务目录和文件
检查是否已存在该告警的任务。如果不存在,创建:
目录:.agents/workspace/active/TASK-{yyyyMMdd-HHmmss}/
任务元数据:
id: TASK-{yyyyMMdd-HHmmss}
codescan_alert_number: <alert-number>
3. 更新任务状态
获取当前时间:
date "+%Y-%m-%d %H:%M:%S%z" | sed 's/\([+-][0-9][0-9]\)\([0-9][0-9]\)$/\1:\2/'
更新 task.md:current_step -> requirement-analysis。
- 追加到
## Activity Log(不要覆盖之前的记录):- {YYYY-MM-DD HH:mm:ss±HH:MM} — **Import Codescan** by {agent} — Code Scanning alert #{alert-number} imported
4. 完成校验
先调用短号分配(保证注册表 entry 已分配;完成校验阶段会读取):
node .agents/scripts/task-short-id.js alloc "$task_id"
如失败(退出码非 0),按提示「归档若干任务」或「调高 task.shortIdLength」处理;不要继续执行后续步骤。
运行完成校验,确认任务产物和同步状态符合规范:
agent-infra-internal task-verify {task-id} import-codescan.completed --format text
处理结果:
- 退出码 0(全部通过)-> 继续到「告知用户」步骤
- 退出码 1(校验失败)-> 根据输出修复问题后重新运行校验
- 退出码 2(网络中断)-> 停止执行并告知用户需要人工介入
按 .agents/rules/validation-output.md 展示当次校验摘要;没有当次校验输出,不得声明完成。
5. 告知用户
仅在校验通过后执行本步骤。
渲染下一步前先读取
.agents/rules/next-step-output.md,仅为已选场景调用统一 helper,并将 stdout 填入{next-step-commands}。
使用 agent-infra-internal agent-client next-steps --skill analyze-task --task-ref {task-ref} 生成本场景的 {next-step-commands}。
Code Scanning 告警 #{alert-number} 已导入。
告警信息:
- 严重程度:{severity}
- 规则:{rule-id}
- 位置:{file-path}:{line-number}
任务信息:
- 任务 ID:{task-id}(短号 {task-ref})
下一步:
{next-step-commands}
完成检查清单
- 获取并记录了告警关键信息
- 创建或确认了对应的任务目录与任务文件
- 更新了 task.md 中的
current_step为 requirement-analysis - 更新了 task.md 中的
updated_at为当前时间 - 追加了 Activity Log 条目到 task.md
- 已通过统一 helper 渲染已选场景的下一步命令
错误处理
- 告警未找到:提示 "Code Scanning alert #{number} not found"
- 告警已关闭:默认仍继续创建/复用任务,并在告知用户中明确该告警当前状态(dismissed/fixed);用户可视情况手动归档任务
- 网络/权限错误:提示相应信息
Signals
- GitHub stars
- 86
- Forks
- 5
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
import-codescan- Source
- github.com/fitlab-ai/agent-infra
github.com/fitlab-ai/agent-infra
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptinternal-comms
Skill · anthropics
More in Monitoring & opsagent-eval
Skill · affaan-m
More in Monitoring & opsarchitecture-decision-records
Skill · affaan-m
More in Monitoring & opsbabysit
Skill · thedotmack
More in Monitoring & ops