Search

Security · Static analysis and SAST

242 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.02 days ago
2
2.CodeqlOfficial

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

elastic/kibana21k—~1.7kAutomated safety check: PassUnknowntoday
3

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknownyesterday
4

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.02 days ago
5

Run Semgrep static analysis scan on a codebase using parallel subagents.

vigolium/piolium1401 repo~2.4kAutomated safety check: NotesMIT19 days ago
6

Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

Narwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT6 mo ago
7

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
8

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~581Automated safety check: PassApache-2.0yesterday
9

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT24 days ago
10

Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

Pa55w0rd/secknowledge-skill424—~2.7kAutomated safety check: PassNo licence3 mo ago
11

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.02 days ago
12

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.02 days ago
13

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

SunWeb3Sec/llm-sast-scanner287—~6.2kAutomated safety check: PassNo licence1 mo ago
14

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos844—~545Automated safety check: PassApache-2.0yesterday
15

Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

AgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassUnknown5 mo ago
16

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

tradecatlabs/vibe-coding-cn17k1 repo~738Automated safety check: PassApache-2.0today
17

A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

Automattic/agent-skills2111 repo~1kAutomated safety check: PassNo licence8 mo ago
18

Safely unpack and investigate existing archives through evidence-first static analysis.

AetherKiri/Aether152—~1.6kAutomated safety check: PassGPL-3.0today
19

Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.

openqa-cn/codexqa152—~1.3kAutomated safety check: PassApache-2.07 days ago
20

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

netdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0today
21

Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

garrytan/gstack136k—~4.5kAutomated safety check: PassMITtoday
22

GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

samber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT8 days ago
23

Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks.

seqra/opentaint163—~3.2kAutomated safety check: PassApache-2.0yesterday
24

Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

RaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0yesterday
25

Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.

telagod/code-abyss243—~552Automated safety check: NotesMIT2 mo ago
26

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0yesterday
27

Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

block/codecrucible117—~1.2kAutomated safety check: PassApache-2.03 days ago
28

Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

ptn1411/skill220—~917Automated safety check: PassNo licence18 days ago
29

Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to.

arandu-io/arandu281—~1.2kAutomated safety check: PassMIT5 days ago
30

Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework.

BrownFineSecurity/iothackbot8591 repo~3.9kAutomated safety check: NotesMIT4 mo ago
31

CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

context-labs/whip1.1k—~3.5kAutomated safety check: PassMIT4 days ago
32

A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.

vigolium/piolium140—~8.7kAutomated safety check: PassMIT19 days ago
33

Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release.

clone45/voxglitch131—~1.2kAutomated safety check: PassGPL-3.025 days ago
34

Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

openqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.07 days ago
35

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT2 mo ago
36

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.02 days ago
37

Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills.

fallow-rs/fallow-skills129—~8.5kAutomated safety check: PassMITtoday
38

Runs and interprets Psalm security (taint) analysis on a Laravel project.

cachethq/core230—~4.7kAutomated safety check: PassUnknown4 days ago
39

Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

waybarrios/opencode-power-pack5332 repos~3.7kAutomated safety check: PassMIT3 days ago
40

Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes.

seqra/opentaint163—~1.9kAutomated safety check: PassApache-2.0yesterday
41

Evidence-based security report generation for firmware assessments.

OrbitCurve/firmware-reverse-engineering215—~4.1kAutomated safety check: PassApache-2.01 mo ago
42
42.Fix

Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, test failures, and IDE-reported problems.

BUZZARDGTA/Session-Sniffer104—~2.7kAutomated safety check: PassGPL-3.0today
43

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.4k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
44

Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

waybarrios/opencode-power-pack533—~2.4kAutomated safety check: PassMIT3 days ago
45

Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.

Archethect/sc-auditor127—~5.9kAutomated safety check: NotesNo licence7 mo ago
46

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
47

Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

cdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0yesterday
48

Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins.

seqra/opentaint163—~806Automated safety check: PassApache-2.0yesterday