Use this skill when the user asks to add security scanning (SAST, secret scan, dependency scan, image scan, SBOM) to their CI pipeline.