DefectDojo serves as one place for findings from scanners such as Semgrep, Bandit, ZAP, Trivy, Grype, Gitleaks, Nuclei, Checkov and Horusec. The skill explains its model: a Product is an application, an Engagement is a time-boxed activity such as a sprint or pipeline, a Test is one scanner run, and a Finding is a deduplicated issue that moves from Active through Mitigated to Closed.
The workflow starts with running DefectDojo locally through docker compose and creating an API key in the UI. You then create a product and engagement over the API and import each scanner's JSON with scripts/import_findings.py, using the right --scan-type. references/tool-parser-map.md maps every tool to its parser name and output format, and an engagement template JSON is included for CI/CD setups. A GitHub Actions import step after each scanner is shown for pipelines.
The description positions it for tracking SLA compliance, merging overlapping findings, managing a vulnerability backlog and producing reports for SOC2, PCI-DSS and GDPR audits.