ghas-feature-researchlisted
Install: claude install-skill themarmack/research-bot
# ghas-feature-research
A focused-on-one-feature research skill. Where `ghas-config-reviewer` checks baseline posture and `github-platform-watch` covers the whole platform, this skill goes deep on a specific GHAS feature when adoption / rollout / tuning needs a research-grade answer.
## When to use
- New GHAS feature announced (e.g., code-scanning autofix in 2025; security campaigns in 2026).
- Rollout planning for an existing-but-underused GHAS feature.
- Deciding default vs advanced for a specific GHAS component on a target repo set.
- Pre-procurement / TPRM review when a GHAS feature is a contract dimension.
## Topic taxonomy
- `secret-scanning` — push protection, partner patterns, custom patterns
- `code-scanning` — default-setup, advanced-setup, autofix
- `dependency-review` — PR-time dep review, configuration
- `security-campaigns` — newer aggregated-finding workflow
- `dependabot` — already covered in detail by `dependabot-strategy`; route there
- `auto-triage-rules` — alert-volume management
## Obsidian-first workflow (mandatory)
1. **Query the vault first** via `vault-querier`:
- Full-text search the feature's key terms across `vault/research/ghas/**`, `vault/research/github/**`, `vault/facts/github/**`, `vault/facts/ghas-dependabot/**`, and recent `vault/digests/**` (last 90 days — `biweekly-codeql-community-pulse` and `weekly-intelligence-digest` often carry GHAS feature news).
- Backlink check on the feature's entity (e.g. `[[secret-scanning]]`, `[[co