Repository
seqra/opentaint agent skills
- skills
- 16
- GitHub stars
- 162
GitHub description: “The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.”
- Stars
- 162 (12 forks)
- Licence
- Apache-2.0
- Last push
- Oct 2026
- Created
- Sep 2025
- Homepage
- opentaint.org
- java
- kotlin
- sast
- security
- security-tools
- spring
- static-analysis
- vulnerabilities
- vulnerability-detection
- vulnerability-scanners
- seqra
- taint-analysis
- skills
- agents
- ai-security
- code-quality
Install all skills
npx skills add seqra/opentaintAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in seqra/opentaint, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks. | seqra/ | 162 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | today |
| 2 | Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes. | seqra/ | 162 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 3 | Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins. | seqra/ | 162 | — | ~806 | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage. | seqra/ | 162 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | today |
| 5 | Build a target project into an opentaint project model. An agent skill from seqra/opentaint. | seqra/ | 162 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 6 | Model a method's taint propagation as a passThrough approximation. | seqra/ | 162 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Author and verify an OpenTaint rule. An agent skill from seqra/opentaint. | seqra/ | 162 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Create an OpenTaint test project with positive/negative samples for verifying a rule or approximation. | seqra/ | 162 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 9 | Classify project-used dependency members and record taint sources as rule-authoring units. | seqra/ | 162 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 10 | 10.Generate Poc Reproduce a true-positive finding against the running application. | seqra/ | 162 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 11 | Triage OpenTaint findings statically. An agent skill from seqra/opentaint. | seqra/ | 162 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 12 | Connect the shared untrusted-data source group to new reusable OpenTaint sink groups. | seqra/ | 162 | — | ~814 | Automated safety check: Pass | Apache-2.0 | today |
| 13 | 13.Debug Rule Debug a rule or approximation that behaves unexpectedly by tracing where taint is dropped. | seqra/ | 162 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 14 | 14.Run Scan Run an OpenTaint scan on project and produces the SARIF report. | seqra/ | 162 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 15 | Mark which of a project's dependency libraries could introduce taint sources. | seqra/ | 162 | — | ~733 | Automated safety check: Pass | Apache-2.0 | today |
| 16 | Write a self-contained OpenTaint engine-issue report from an analysis diagnosis or a full-scan failure. | seqra/ | 162 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
Questions, answered from the data.
What is the best skill in seqra/opentaint?
Analyze External Methods from seqra/opentaint ranks first of the 16 skills in seqra/opentaint listed here, with the highest score: its repository has 162 GitHub stars, its SKILL.md loads about 3.2k tokens and it passes the automated safety check with no findings. Next come Create Dataflow Approximation and Orchestrate Stage.
Are the skills in seqra/opentaint official?
None yet. All 16 skills in seqra/opentaint listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How do I install all skills from seqra/opentaint?
Run npx skills add seqra/opentaint in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.