Search
Development · Static analysis and SAST
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Turns natural-language code queries into ast-grep rules for structural search, testing each rule against an example file before running it on a codebase. | warp-drive-data/ | 3.2k | 5 repos | ~2.4k | Automated safety check: Pass | MIT | today |
| 2 | Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script. | code-yeongyu/ | 70k | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 3 | A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures. | biomejs/ | 26k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 5 | Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. | SonarSource/ | 1.2k | — | ~833 | Automated safety check: Pass | Unknown | today |
| 6 | 6.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 844 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 844 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 8 | Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex. | openqodex/ | 470 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | today |
| 9 | Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration. | ozgurcd/ | 228 | — | ~4.8k | Automated safety check: Notes | MIT | yesterday |
| 10 | Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page. | openqa-cn/ | 152 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 11 | GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release… | samber/ | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | 7 days ago |
| 12 | Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication. | kucherenko/ | 6.4k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 13 | Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to. | arandu-io/ | 281 | — | ~1.2k | Automated safety check: Pass | MIT | 4 days ago |
| 14 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 4 days ago |
| 15 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 16 | Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode. | redhat-et/ | 2.4k | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 17 | 17.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 129 | — | ~8.5k | Automated safety check: Pass | MIT | today |
| 18 | 18.Fix Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, test failures, and IDE-reported problems. | BUZZARDGTA/ | 104 | — | ~2.7k | Automated safety check: Pass | GPL-3.0 | today |
| 19 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 20 | Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle. | apache/ | 2.9k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | today |
| 21 | Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request. | hermes-labs-ai/ | 138 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 22 | Master ShellCheck static analysis configuration and usage for shell script quality. Use when setting up linting infrastructure, fixing code issues… | wshobson/ | 40k | 11 repos | ~403 | Automated safety check: Pass | MIT | 4 days ago |
| 23 | 23.Ship Release The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main. | ibuilder/ | 122 | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 24 | Scans a Power Pages site project for security issues in source code and dependencies. | microsoft/ | 979 | — | ~3.4k | Automated safety check: Notes | MIT | today |
| 25 | Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories. | waynesutton/ | 628 | — | ~1.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 26 | 26.Code Quality Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector. | bonny/ | 317 | — | ~519 | Automated safety check: Notes | No licence | yesterday |
| 27 | Reduce technical debt and improve code quality by systematically resolving static analysis warnings. | flutter/ | 2k | — | ~429 | Automated safety check: Pass | BSD-3-Clause | today |
| 28 | Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness. | affaan-m/ | 276k | 4 repos | ~1.1k | Automated safety check: Notes | MIT | 4 days ago |
| 29 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | today |
| 30 | Methodology for root-causing hard concurrency / memory-ordering bugs (intermittent races, use-after-free, RCU/lock-free publish-order defects, "impossible" stale reads) with LTTng flight-recorder… | isc-projects/ | 780 | — | ~2.5k | Automated safety check: Pass | MPL-2.0 | today |
| 31 | Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. | cloudposse/ | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 32 | Review code for refactorability — surface concrete, prioritized refactoring opportunities grounded in Martin Fowler's smell catalog and SOLID, augmented with static analysis tools (gocyclo… | meain/ | 285 | — | ~2k | Automated safety check: Pass | MIT | yesterday |
| 33 | 33.PHP Pro Writes strictly typed modern PHP 8.3+ for Laravel, Symfony and plain projects, with PHPStan level 9, PHPUnit or Pest tests, typed DTOs and secure defaults. | Jeffallan/ | 12k | — | ~1.6k | Automated safety check: Notes | MIT | 5 days ago |
| 34 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 35 | Get a path in the call graph from a source function to a specified destination function in the codebase. | opensage-agent/ | 127 | — | ~272 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 36 | Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. | AratKruglik/ | 155 | 8 repos | ~2.3k | Automated safety check: Pass | No licence | 5 mo ago |
| 37 | GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). | secondsky/ | 227 | — | ~4k | Automated safety check: Notes | MIT | 11 days ago |
| 38 | Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an… | openqa-cn/ | 152 | — | ~7.2k | Automated safety check: Warn | Apache-2.0 | 6 days ago |
| 39 | Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. | openqa-cn/ | 152 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 40 | Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification. | aftermathlabs/ | 438 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | 5 days ago |
| 41 | Run static analysis on Common Lisp projects with the Mallet command-line linter. | ultralisp/ | 258 | — | ~771 | Automated safety check: Pass | No licence | 26 days ago |
| 42 | Automatic quality control, linting, and static analysis procedures. | xenitV1/ | 130 | 6 repos | ~432 | Automated safety check: Notes | MIT | 8 mo ago |
| 43 | 43.Lint Run and fix the repository static analysis suite. An agent skill from ethereum/execution-specs. | ethereum/ | 1.2k | — | ~286 | Automated safety check: Pass | CC0-1.0 | today |
| 44 | 44.Bug Hunter A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and… | WrongStack/ | 370 | — | ~3.7k | Automated safety check: Pass | MIT | today |
| 45 | 45.Signals Lint Standardized compiler diagnostics, static analysis lints, and automated IDE quick-fixes. | rodydavis/ | 819 | — | ~712 | Automated safety check: Pass | Apache-2.0 | 25 days ago |
| 46 | 46.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 47 | Scan C source files for hard-to-test static dependencies — DateTime.Now/UtcNow, File., Directory., Environment., HttpClient, Console., Process., and other untestable statics. | microsoft/ | 1k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 48 | You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices. | aiskillstore/ | 430 | 7 repos | ~3.9k | Automated safety check: Pass | No licence | today |