GitLab Dependency Scanning Triage Agent Report
Provides a weekly compliance report on the agent runs inside the Ghost Agent Factory for GitLab dependency scanning triage and recheck agents, with vulnerabilities dismissed, vulnerabilities reverted, and analyst time saved.
What this agent does
This read-only agent reports each week on the runs of the Ghost Agent Factory agents that triage and recheck dependency scanning vulnerabilities in a GitLab project. It reads every run from the last 7 days, with its status, cost, metrics, and evidence files. It totals the vulnerabilities dismissed and reverted and estimates the analyst time saved.
The challenge
An automated triage agent dismisses vulnerabilities without a person reviewing each one. Security leaders and auditors need a record of what it dismissed, what it reverted, and whether it ran at all. Run logs answer those questions one run at a time. Nobody reads them all, so nobody sees the trend or the missed runs.
The solution
The agent computes every figure from the run records, so every number can be traced to a specific run. It fails the report when a read fails, instead of publishing zeros. It adds one short executive summary that states the value delivered and the open-risk trend, with no advice. Provides a weekly record of what the triage automation did and what it cost.
Workflow
- 01
Read runs
Read every triage and recheck run from the last 7 days, with its status, trigger, duration, cost, metrics, and evidence files.
- 02
Total the results
Sum the vulnerabilities dismissed and reverted, and read the reachable open vulnerability count as a series across the week.
- 03
Summarize
Write a short executive summary that leads with the value delivered and states the open-risk trend.
- 04
Publish
Publish one report with the summary, the totals, a row per run, and each evidence file by hash.
Agent template
# GitLab Dependency Scanning Triage Agent Report
## Measurable outcomes
Every triage and recheck run on a project appears in one weekly report. Every figure in the report traces to a run record. Track the number of runs each report covers.
## Procedure
For a given GitLab project, read the triage and recheck agents' runs from the last 7 days. Include each run's status, trigger, duration, token use, metrics, and evidence files. Sum the vulnerabilities dismissed, the vulnerabilities reverted to detected, and the dismissals rechecked. Treat the reachable open vulnerability count as a gauge: report the latest value and the full series across the week. Estimate analyst time saved at 5 minutes per dismissed vulnerability, unless I set another rate. List each run with its metrics, and each evidence file by its hash without its contents. Flag each completed run that recorded no metrics. Fail the report when any read fails, because a report of zeros from a refused read is worse than no report. Compute every figure from the run records. The only written prose is a 2 to 3 sentence executive summary. It leads with the value delivered and reads the whole reachable open series, not only its ends. A rising reachable open count means real vulnerabilities surfaced, not a regression. The summary states facts and gives no advice.
## Requirements
It reads the triage and recheck agents' runs, metrics, and outputs through the Ghost Agent Factory MCP with a read-only API key, and needs nothing more. It never reads or changes the project or its vulnerabilities. Schedule it after the week's triage and recheck runs. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools