Audit asks why a known secret still landed on main. The Gitleaks JSON is in a ticket; the pipeline job is green. Do not treat SKIPPED as pass. The CLI maps only FAILED to exit 1 today.
What is AngusSecurity?
The Secure product in Xiaocan Cloud’s AngusKit. One job covers SAST, secrets, and SCA, emitting PASSED / FAILED / ERROR / SKIPPED. Engines are OpenGrep, Gitleaks, and Trivy. What is unified is governance, not a replacement kernel.
Which engines run in one check?
OpenGrep (SAST), Gitleaks (secrets), and Trivy (SCA / images).
How is this different from wiring Gitleaks + Trivy yourself?
A DIY mix usually yields three JSON files with mismatched severity. AngusSecurity normalizes findings so console, CLI, and API share one model. The engines are not claimed to beat Trivy.
What gate states exist?
PASSED, FAILED, ERROR, SKIPPED. ERROR means the result is not trustworthy; SKIPPED means no verdict. Neither should count as pass by default.
Do console, CLI, and API share one result model?
Yes. CLI and REST share the job and Finding model.
Can it run offline / on an intranet?
Yes. Engines support offline install. Do not assume a cloud scanning SaaS works on an intranet. Check the Tools page or tools/bin/doctor.sh on the node.
How do we fold this into AngusGit merges?
Git’s Security page is read-only four-state. If branch protection requires the check, FAILED cannot merge. Jobs are created in Security, not by a Git-built engine.
How does this split from repository scanning?
AngusRepo in-repo scan covers stored packages and download blocking. AngusSecurity owns cross-repo jobs, SAST/secrets, and release four-state.
How are findings suppressed with an audit trail?
Suppress on a Finding row is job-scoped and needs Findings:SUPPRESS. Historical findings remain; activity is auditable. Do not suppress HIGH/CRITICAL just because you are not ready to fix them.
What read-only / governance tools does MCP provide?
Read-only: security_list_findings filters findings; security_explain_finding returns rule text and fix hints. Writes: security_scan_repo starts a scan; security_triage_finding marks false positive or accepted risk—both need confirmation. Changing global thresholds, bulk-ignore, and deleting projects are not on the tool surface. Community does not include MCP.
What does doctor check when engines are not ready?
The Tools page can run a self-check; on the node use tools/bin/doctor.sh. The angus-security CLI has no tools doctor command. Suite angusctl doctor printing OK is the install gate; missing engines are WARN — not a failed install, and not proof that engines are present.
Where should we start in the docs?
Start with the AngusSecurity introduction and quick start. Gates are in the policy chapter; engine health is in tools.