Skill collection
utkusen/sast-skills agent skills
- skills
- 16
- GitHub stars
- 1.3k
GitHub description: “Collection of agent skills to find vulnerabilities inside your web/mobile apps.”
- Stars
- 1,331 (64 forks)
- Licence
- MIT
- Last push
- Apr 2026
- Created
- Mar 2026
- ai-security
- claude
- claude-code
- sast
Install all skills
npx skills add utkusen/sast-skillsAdd --skill <name> for a single skill and -a <agent> to choose the agent (see the agent guides).
Skills in utkusen/sast-skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Perform codebase analysis and architecture mapping as the first phase of a security assessment. | utkusen/ | 1.3k | — | ~1k | Automated safety check: Pass | MIT | 6 mo ago |
| 2 | Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input… | utkusen/ | 1.3k | — | ~4.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 3 | Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3… | utkusen/ | 1.3k | — | ~4.9k | Automated safety check: Pass | MIT | 6 mo ago |
| 4 | Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. | utkusen/ | 1.3k | — | ~1.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 5 | Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel… | utkusen/ | 1.3k | — | ~5.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 6 | Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel… | utkusen/ | 1.3k | — | ~7.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 7 | Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. | utkusen/ | 1.3k | — | ~6.5k | Automated safety check: Notes | MIT | 6 mo ago |
| 8 | 8.Sast JWT Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 9 | Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 10 | Detect path traversal vulnerabilities in a codebase using a three-phase approach: recon (find file-loading sinks with dynamic paths), batched verify (trace user input and mitigations in parallel… | utkusen/ | 1.3k | — | ~6.8k | Automated safety check: Pass | MIT | 6 mo ago |
| 11 | 11.Sast Rce Detect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in parallel… | utkusen/ | 1.3k | — | ~8.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 12 | 12.Sast Sqli Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 13 | 13.Sast Ssrf Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel… | utkusen/ | 1.3k | — | ~6.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 14 | 14.Sast Ssti Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user… | utkusen/ | 1.3k | — | ~7.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 15 | 15.Sast Xss Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 16 | 16.Sast Xxe Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
Questions, answered from the data.
What is the best skill in utkusen/sast-skills?
Sast Analysis from utkusen/sast-skills ranks first of the 16 skills in utkusen/sast-skills listed here, with the highest score: its repository has 1.3k GitHub stars, its SKILL.md loads about 1k tokens and it passes the automated safety check with no findings. Next come Sast Graphql and Sast Idor.
Are the skills in utkusen/sast-skills official?
None yet. All 16 skills in utkusen/sast-skills listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How do I install all skills from utkusen/sast-skills?
Run npx skills add utkusen/sast-skills in your project: the open-source skills CLI installs the repository's skills into your coding agent's skills folder. To install a single skill, open its page here for the exact command.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.