Search
Static analysis and SAST
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed… | BankrBot/ | 1.2k | — | ~858 | Automated safety check: Pass | No licence | yesterday |
| 242 | 242.Slither Analysis A skill your agent uses when running Slither static analysis on Solidity contracts. | ccashwell/ | 131 | — | ~1.5k | Automated safety check: Pass | MIT | 11 days ago |
| 243 | 243.Binary Re This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work. | aiskillstore/ | 433 | 1 repo | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 244 | 244.Semgrep Triage Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle | deonmenezes/ | 503 | — | ~312 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 245 | 245.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 180 | — | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 246 | Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices | Hack23/ | 239 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 247 | 247.Sicurezza GitHub Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 970 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 248 | Validate API consistency between two versions of Java libraries. | ArabelaTso/ | 253 | — | ~660 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 249 | Validate API consistency between two versions of Python libraries. | ArabelaTso/ | 253 | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 250 | Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 251 | MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file… | LeoYeAI/ | 2.2k | — | ~969 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 252 | 252.Clawsec Scanner Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 253 | 253.Phy Regex Audit Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. | LeoYeAI/ | 2.2k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 254 | CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 255 | 255.Warden Scan Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~750 | Automated safety check: Notes | MIT | yesterday |
| 256 | 256.Static Analysis Static analysis skill for C/C++ codebases. An agent skill from mohitmishra786/low-level-dev-skills. | mohitmishra786/ | 252 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 257 | 257.Nullaway Guide for resolving NullAway static analysis errors. An agent skill from nwjs/chromium.src. | nwjs/ | 160 | — | ~3k | Automated safety check: Pass | BSD-3-Clause | yesterday |
| 258 | Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification. | ArabelaTso/ | 253 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 259 | Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource… | ArabelaTso/ | 253 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 260 | Applies abstract interpretation using different abstract domains (intervals, octagons, polyhedra, sign, congruence) to statically analyze program variables and infer invariants, value ranges, and… | ArabelaTso/ | 253 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 261 | Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program. | ArabelaTso/ | 253 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 262 | Explain why counterexamples violate specifications by analyzing formal specifications (temporal logic, invariants, pre/postconditions, code contracts), informal requirements (user stories… | ArabelaTso/ | 253 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 263 | Subagent for figma-from-code Phase 0b. An agent skill from bitovi/ai-enablement-prompts. | bitovi/ | 121 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 264 | 264.Security Auditor Security vulnerability scanner and OWASP compliance auditor for codebases. | curiositech/ | 244 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 265 | Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff. | InternationalColorConsortium/ | 183 | — | ~1.4k | Automated safety check: Pass | BSD-3-Clause | yesterday |
| 266 | 266.Skillui Reverse-engineer any website's, repo's, or local project's design system into a Claude-ready skill via the SkillUI CLI. | CraftOS-dev/ | 392 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 267 | Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy | Hack23/ | 239 | — | ~5.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 268 | Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis. | EmeaAppGbb/ | 100 | — | ~2.2k | Automated safety check: Pass | MIT | 5 mo ago |
| 269 | 269.Php Tooling Configure PHP ecosystem tooling, dependency management, and static analysis. | HoangNguyen0403/ | 572 | — | ~615 | Automated safety check: Pass | MIT | yesterday |
| 270 | 270.Joern Slice Tool to get the program slice for a given function using Joern. | opensage-agent/ | 127 | — | ~189 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 271 | 271.Search Function Tool to search for a function in the codebase. An agent skill from opensage-agent/opensage-adk. | opensage-agent/ | 127 | — | ~153 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 272 | 272.Security Audit 2 Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or… | sundial-org/ | 663 | — | ~875 | Automated safety check: Pass | No licence | 7 mo ago |
| 273 | For a batch of findings from a non-security audit tool (<audit-tool — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer / equivalent; full list in the body) against <upstream… | apache/ | 114 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 274 | A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now… | OneWave-AI/ | 336 | — | ~836 | Automated safety check: Pass | MIT | 9 days ago |
| 275 | 275.Security Audit Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Notes | MIT | 2 mo ago |
| 276 | Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. | seb1n/ | 206 | — | ~2.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 277 | This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work… | bitwarden/ | 155 | — | ~2.2k | Automated safety check: Pass | Unknown | yesterday |
| 278 | A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source… | mtarcure/ | 165 | — | ~1.4k | Automated safety check: Pass | MIT | 20 days ago |
| 279 | 279.Security Auditor MASTER SECURITY: OWASP Top 10, SAST/DAST, PenTest. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI. | Dokhacgiakhoa/ | 508 | — | ~440 | Automated safety check: Pass | Unknown | 4 mo ago |
| 280 | DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization… | Mindrally/ | 271 | — | ~2.2k | Automated safety check: Notes | Apache-2.0 | 2 days ago |
| 281 | 安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告) | langbyyi/ | 129 | — | ~6k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 282 | 282.Quality Checks Run code quality tools: PHP-CS-Fixer for style, PHPStan for static analysis, and type safety checks | dev-toolings/ | 223 | — | ~381 | Automated safety check: Notes | MIT | 5 days ago |