Search
JavaScript · Static analysis and SAST
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 2 | 2.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 3 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 23 days ago |
| 4 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 5 | Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication. | kucherenko/ | 6.4k | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 6 | 6.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 129 | — | ~8.5k | Automated safety check: Pass | MIT | yesterday |
| 7 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 8 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 9 | Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. | utkusen/ | 1.3k | — | ~6.5k | Automated safety check: Notes | MIT | 6 mo ago |
| 10 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | today |
| 11 | Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects. | mukul975/ | 34k | — | ~799 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |