Search

Python · Static analysis and SAST

31 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0yesterday
2

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknownyesterday
3

Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

dotnet/skills5.6k1 repo~3.3kAutomated safety check: PassMITtoday
4

Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

Narwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT6 mo ago
5

Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed…

DougTrajano/pydantic-ai-skills377—~2.2kAutomated safety check: PassMIT4 days ago
6

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~581Automated safety check: PassApache-2.0today
7

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT23 days ago
8

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0yesterday
9

A skill your agent uses when writing or reviewing AI agent configs, system prompts, or tool definitions (JSON/YAML/Python) and you need to catch ambiguous tool descriptions, missing stop conditions…

hermes-labs-ai/lintlang1371 repo~719Automated safety check: PassApache-2.0yesterday
10

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~545Automated safety check: PassApache-2.0today
11

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

tradecatlabs/vibe-coding-cn17k1 repo~738Automated safety check: PassApache-2.0today
12

Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request.

hermes-labs-ai/lintlang1371 repo~1.8kAutomated safety check: PassApache-2.0yesterday
13

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT2 mo ago
14
14.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.4k4 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
15

Lint AI agent instruction files (SKILL.md, CLAUDE.md, AGENTS.md, GEMINI.md), tool definitions, system prompts, and agent configs with the deterministic LintLang CLI.

hermes-labs-ai/lintlang137—~1.7kAutomated safety check: PassApache-2.0yesterday
16

Audit a named AI agent config, system prompt, tool definition, or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI in GitHub Copilot CLI.

hermes-labs-ai/lintlang137—~1.9kAutomated safety check: PassApache-2.0yesterday
17

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack505—~510Automated safety check: PassApache-2.05 days ago
18

Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

luongnv89/skills131—~4.5kAutomated safety check: PassMITyesterday
19

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0yesterday
20

Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

ArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.01 mo ago
21

Automatic quality control, linting, and static analysis procedures.

xenitV1/Antigravity-Workflows1306 repos~432Automated safety check: NotesMIT8 mo ago
22

Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

AgentSecOps/SecOpsAgentKit2201 repo~2.6kAutomated safety check: PassUnknown5 mo ago
23

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

sickn33/agentic-awesome-skills47k1 repo~2.4kAutomated safety check: PassMITyesterday
24

Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3…

utkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT6 mo ago
25

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

BagelHole/DevOps-Security-Agent-Skills1.1k—~2.2kAutomated safety check: PassMIT4 mo ago
26

Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
27

This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.

aiskillstore/marketplace4301 repo~2.6kAutomated safety check: PassNo licenceyesterday
28

Validate API consistency between two versions of Python libraries.

ArabelaTso/Skills-4-SE253—~609Automated safety check: PassApache-2.01 mo ago
29

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT2 mo ago
30

Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

LeoYeAI/openclaw-master-skills2.2k—~5.1kAutomated safety check: PassApache-2.02 mo ago
31

Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

seb1n/awesome-ai-agent-skills206—~2.6kAutomated safety check: PassMIT2 mo ago