Search

Java · Static analysis and SAST

16 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
2

Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

dotnet/skills5.6k1 repo~3.3kAutomated safety check: PassMITtoday
3

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
4

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~581Automated safety check: PassApache-2.0today
5

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~545Automated safety check: PassApache-2.0today
6

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0yesterday
7

Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

ArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.01 mo ago
8
8.CodeqlOfficial

Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

github/awesome-copilot40k1 repo~3.4kAutomated safety check: PassMITtoday
9

Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination…

mukul975/Anthropic-Cybersecurity-Skills34k—~620Automated safety check: PassApache-2.01 mo ago
10

A skill your agent uses when you need to add or evaluate Maven dependencies that improve code quality or domain modeling — including nullness annotations (JSpecify), static analysis (Error Prone +…

jabrena/plinth446—~1.5kAutomated safety check: PassApache-2.0yesterday
11

Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user…

utkusen/sast-skills1.3k—~7.5kAutomated safety check: PassMIT6 mo ago
12

Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
13

Validate API consistency between two versions of Java libraries.

ArabelaTso/Skills-4-SE253—~660Automated safety check: PassApache-2.01 mo ago
14

Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

LeoYeAI/openclaw-master-skills2.2k—~5.1kAutomated safety check: PassApache-2.02 mo ago
15

Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

dslsdzc/rev-skills125—~2kAutomated safety check: PassApache-2.03 days ago
16

Guide for resolving NullAway static analysis errors. An agent skill from nwjs/chromium.src.

nwjs/chromium.src160—~3kAutomated safety check: PassBSD-3-Clause5 days ago