# fortify

> Open-source publisher. Listings imported from github.com/fortify — credited to the original author with their license.

- **Listings:** 9
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/fortify
- **Website:** https://github.com/fortify

## Published listings

- [Fcli Common](https://agentstack.voostack.com/l/skill-fortify-skills-fcli-common) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fcli-common`
  Generic reference for the Fortify CLI (fcli). Install, upgrade, authenticate, fcli environment variables, output formats, SpEL query syntax, variable chaining and custom action framework.
- [Fortify Ssc](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-ssc) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-ssc`
  Perform tasks against Fortify SSC (Software Security Center): query applications/application versions; query & triage existing security issues in SSC; start & monitor full ScanCentral SAST/DAST scans or upload FPR artifacts; create app versions; policy and portfolio analysis. NOT for lightweight AI review of local code changes/diffs (use fortify-change-review).
- [Fortify Cicd Integration](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-cicd-integration) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-cicd-integration`
  Integrate Fortify application security (SAST, SCA, DAST) with GitHub Actions, GitLab Pipelines, Azure DevOps, Jenkins & other CICD/DevSecOps pipelines.
- [Fortify Remediate](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-remediate) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-remediate`
  Remediate SAST (static) and DAST (dynamic) security vulnerabilities ALREADY detected by Fortify in FoD or SSC — fix specific issues, categories, or reduce issue counts, including applying SAST Aviator fixes. For SCA / open source dependency findings (vulnerable third-party components, CVEs), use fortify-dependency-upgrade instead. NOT for discovering or reviewing new issues (use fortify-change-re…
- [Fortify Create App](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-create-app) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-create-app`
  Create new Fortify application(s) in Fortify on Demand (FoD) or Application Security Center (SSC).
- [Fortify Exploitability Analysis](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-exploitability-analysis) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-exploitability-analysis`
  >-
- [Fortify Change Review](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-change-review) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-change-review`
  Lightweight, AI-powered security review of code CHANGES (a diff, PR, or in-session edits) using the agent's own analysis — no Fortify scan engine or platform needed. Use when the user asks to "run a Fortify security review" / "Fortify change review", or when adding/modifying code touching authentication, authorization, input handling, output encoding, data access, file operations, outbound HTTP,…
- [Fortify Fod](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-fod) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-fod`
  Perform tasks against Fortify on Demand (FoD): query applications/releases; query & triage existing security issues in FoD; start & monitor full SAST/DAST/SCA/open source scans of the codebase; create releases; import FPR/SARIF/CycloneDX artifacts; policy and portfolio analysis. NOT for lightweight AI review of local code changes/diffs (use fortify-change-review).
- [Fortify Dependency Upgrade](https://agentstack.voostack.com/l/skill-fortify-skills-fortify-dependency-upgrade) — Skill · Free · security-reviewed — `agentstack add skill-fortify-skills-fortify-dependency-upgrade`
  Perform dependency upgrade impact assessment, code fixes, and migration work. Use to remediate Fortify SCA / open source / software composition analysis findings — vulnerable third-party dependencies, CVEs/GHSAs, components flagged by FoD or SSC — by upgrading to a safe version and fixing any resulting breakage. Also use when the user asks what will break after a version change, hits compile/test…

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
