Search

Development · Static analysis and SAST

64 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Turns natural-language code queries into ast-grep rules for structural search, testing each rule against an example file before running it on a codebase.

warp-drive-data/warp-drive3.2k5 repos~2.4kAutomated safety check: PassMITtoday
2

Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.

code-yeongyu/oh-my-openagent70k—~3.3kAutomated safety check: PassMITtoday
3

A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures.

biomejs/biome26k—~1.4kAutomated safety check: PassApache-2.0today
4

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0yesterday
5

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
6

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~581Automated safety check: PassApache-2.0today
7

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~545Automated safety check: PassApache-2.0today
8

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

openqodex/openqodex470—~2.4kAutomated safety check: PassApache-2.0today
9

Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration.

ozgurcd/gograph228—~4.8kAutomated safety check: NotesMITyesterday
10

Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.

openqa-cn/codexqa152—~1.3kAutomated safety check: PassApache-2.06 days ago
11

GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

samber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT7 days ago
12

Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication.

kucherenko/jscpd6.4k—~4.5kAutomated safety check: PassMITtoday
13

Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to.

arandu-io/arandu281—~1.2kAutomated safety check: PassMIT4 days ago
14

CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

context-labs/whip1.1k—~3.5kAutomated safety check: PassMIT4 days ago
15

Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

openqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.06 days ago
16

Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

redhat-et/ripwire2.4k—~1.1kAutomated safety check: NotesApache-2.0today
17

Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills.

fallow-rs/fallow-skills129—~8.5kAutomated safety check: PassMITtoday
18
18.Fix

Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, test failures, and IDE-reported problems.

BUZZARDGTA/Session-Sniffer104—~2.7kAutomated safety check: PassGPL-3.0today
19

Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

trailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0yesterday
20

Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle.

apache/grails-core2.9k—~3.9kAutomated safety check: PassApache-2.0today
21

Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request.

hermes-labs-ai/lintlang138—~1.8kAutomated safety check: PassApache-2.0today
22

Master ShellCheck static analysis configuration and usage for shell script quality. Use when setting up linting infrastructure, fixing code issues…

wshobson/agents40k11 repos~403Automated safety check: PassMIT4 days ago
23

The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main.

ibuilder/massing122—~2.3kAutomated safety check: PassMITtoday
24
24.Scan CodeOfficial

Scans a Power Pages site project for security issues in source code and dependencies.

microsoft/power-platform-skills979—~3.4kAutomated safety check: NotesMITtoday
25

Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.

waynesutton/markdown-site628—~1.9kAutomated safety check: PassMIT4 mo ago
26

Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector.

bonny/WordPress-Simple-History317—~519Automated safety check: NotesNo licenceyesterday
27

Reduce technical debt and improve code quality by systematically resolving static analysis warnings.

flutter/flutter-intellij2k—~429Automated safety check: PassBSD-3-Clausetoday
28

Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness.

affaan-m/ECC276k4 repos~1.1kAutomated safety check: NotesMIT4 days ago
29

Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

axelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0today
30

Methodology for root-causing hard concurrency / memory-ordering bugs (intermittent races, use-after-free, RCU/lock-free publish-order defects, "impossible" stale reads) with LTTng flight-recorder…

isc-projects/bind9780—~2.5kAutomated safety check: PassMPL-2.0today
31

Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch.

cloudposse/atmos1.4k—~1.3kAutomated safety check: PassApache-2.0today
32

Review code for refactorability — surface concrete, prioritized refactoring opportunities grounded in Martin Fowler's smell catalog and SOLID, augmented with static analysis tools (gocyclo…

meain/dotfiles285—~2kAutomated safety check: PassMITyesterday
33

Writes strictly typed modern PHP 8.3+ for Laravel, Symfony and plain projects, with PHPStan level 9, PHPUnit or Pest tests, typed DTOs and secure defaults.

Jeffallan/claude-skills12k—~1.6kAutomated safety check: NotesMIT5 days ago
34

Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

trailofbits/skills7.4k—~4.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
35

Get a path in the call graph from a source function to a specified destination function in the codebase.

opensage-agent/opensage-adk127—~272Automated safety check: PassApache-2.02 mo ago
36

Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability.

AratKruglik/claude-laravel1558 repos~2.3kAutomated safety check: PassNo licence5 mo ago
37

GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL).

secondsky/claude-skills227—~4kAutomated safety check: NotesMIT11 days ago
38

Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an…

openqa-cn/codexqa152—~7.2kAutomated safety check: WarnApache-2.06 days ago
39

Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.

openqa-cn/codexqa152—~1.2kAutomated safety check: PassApache-2.06 days ago
40

Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification.

aftermathlabs/llvm-msvc438—~1.8kAutomated safety check: PassAGPL-3.05 days ago
41

Run static analysis on Common Lisp projects with the Mallet command-line linter.

ultralisp/ultralisp258—~771Automated safety check: PassNo licence26 days ago
42

Automatic quality control, linting, and static analysis procedures.

xenitV1/Antigravity-Workflows1306 repos~432Automated safety check: NotesMIT8 mo ago
43
43.Lint

Run and fix the repository static analysis suite. An agent skill from ethereum/execution-specs.

ethereum/execution-specs1.2k—~286Automated safety check: PassCC0-1.0today
44

A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

WrongStack/WrongStack370—~3.7kAutomated safety check: PassMITtoday
45

Standardized compiler diagnostics, static analysis lints, and automated IDE quick-fixes.

rodydavis/signals.dart819—~712Automated safety check: PassApache-2.025 days ago
46

Automated code review and security linting integration for CI/CD pipelines using reviewdog.

AgentSecOps/SecOpsAgentKit2201 repo~3kAutomated safety check: PassUnknown5 mo ago
47

Scan C source files for hard-to-test static dependencies — DateTime.Now/UtcNow, File., Directory., Environment., HttpClient, Console., Process., and other untestable statics.

microsoft/testfx1k—~1.9kAutomated safety check: PassMITtoday
48

You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices.

aiskillstore/marketplace4307 repos~3.9kAutomated safety check: PassNo licencetoday