Search
Security · Static analysis and SAST
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 2 | Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. | elastic/ | 21k | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 3 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | yesterday |
| 4 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | 2 days ago |
| 5 | 5.Semgrep Run Semgrep static analysis scan on a codebase using parallel subagents. | vigolium/ | 140 | 1 repo | ~2.4k | Automated safety check: Notes | MIT | 19 days ago |
| 6 | 6.C To Ast Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills. | Narwhal-Lab/ | 316 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 7 | Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. | SonarSource/ | 1.2k | — | ~833 | Automated safety check: Pass | Unknown | today |
| 8 | 8.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 844 | — | ~581 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 9 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 24 days ago |
| 10 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 424 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 11 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 12 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 13 | General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. | SunWeb3Sec/ | 287 | — | ~6.2k | Automated safety check: Pass | No licence | 1 mo ago |
| 14 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 844 | — | ~545 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 15 | 15.Sast Semgrep Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. | AgentSecOps/ | 220 | 2 repos | ~2.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 16 | Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. | tradecatlabs/ | 17k | 1 repo | ~738 | Automated safety check: Pass | Apache-2.0 | today |
| 17 | 17.Wp Phpstan A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and… | Automattic/ | 211 | 1 repo | ~1k | Automated safety check: Pass | No licence | 8 mo ago |
| 18 | Safely unpack and investigate existing archives through evidence-first static analysis. | AetherKiri/ | 152 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | today |
| 19 | Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page. | openqa-cn/ | 152 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 20 | Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. | netdata/ | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | today |
| 21 | Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled. | garrytan/ | 136k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 22 | GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release… | samber/ | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | 8 days ago |
| 23 | Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks. | seqra/ | 163 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 24 | 24.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 25 | Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. | telagod/ | 243 | — | ~552 | Automated safety check: Notes | MIT | 2 mo ago |
| 26 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 27 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 28 | Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation. | ptn1411/ | 220 | — | ~917 | Automated safety check: Pass | No licence | 18 days ago |
| 29 | Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to. | arandu-io/ | 281 | — | ~1.2k | Automated safety check: Pass | MIT | 5 days ago |
| 30 | 30.Chipsec Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. | BrownFineSecurity/ | 859 | 1 repo | ~3.9k | Automated safety check: Notes | MIT | 4 mo ago |
| 31 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 4 days ago |
| 32 | 32.Audit A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. | vigolium/ | 140 | — | ~8.7k | Automated safety check: Pass | MIT | 19 days ago |
| 33 | Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. | clone45/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 25 days ago |
| 34 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 35 | 35.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 283 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 36 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 37 | 37.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 129 | — | ~8.5k | Automated safety check: Pass | MIT | today |
| 38 | Runs and interprets Psalm security (taint) analysis on a Laravel project. | cachethq/ | 230 | — | ~4.7k | Automated safety check: Pass | Unknown | 4 days ago |
| 39 | 39.Codeql Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF. | waybarrios/ | 533 | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 3 days ago |
| 40 | Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes. | seqra/ | 163 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 41 | Evidence-based security report generation for firmware assessments. | OrbitCurve/ | 215 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 42 | 42.Fix Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, test failures, and IDE-reported problems. | BUZZARDGTA/ | 104 | — | ~2.7k | Automated safety check: Pass | GPL-3.0 | today |
| 43 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 44 | 44.Semgrep Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis. | waybarrios/ | 533 | — | ~2.4k | Automated safety check: Pass | MIT | 3 days ago |
| 45 | Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting. | Archethect/ | 127 | — | ~5.9k | Automated safety check: Notes | No licence | 7 mo ago |
| 46 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 47 | 47.Bom Evidence Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 48 | Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins. | seqra/ | 163 | — | ~806 | Automated safety check: Pass | Apache-2.0 | yesterday |