Search
Python · Static analysis and SAST
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 2 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | yesterday |
| 3 | Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build. | dotnet/ | 5.6k | 1 repo | ~3.3k | Automated safety check: Pass | MIT | today |
| 4 | 4.C To Ast Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills. | Narwhal-Lab/ | 316 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 5 | Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed… | DougTrajano/ | 377 | — | ~2.2k | Automated safety check: Pass | MIT | 4 days ago |
| 6 | 6.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 23 days ago |
| 8 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 9 | 9.Lintlang A skill your agent uses when writing or reviewing AI agent configs, system prompts, or tool definitions (JSON/YAML/Python) and you need to catch ambiguous tool descriptions, missing stop conditions… | hermes-labs-ai/ | 137 | 1 repo | ~719 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 10 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 11 | Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. | tradecatlabs/ | 17k | 1 repo | ~738 | Automated safety check: Pass | Apache-2.0 | today |
| 12 | Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request. | hermes-labs-ai/ | 137 | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 13 | 13.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 14 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 4 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 15 | 15.Lintlang Lint AI agent instruction files (SKILL.md, CLAUDE.md, AGENTS.md, GEMINI.md), tool definitions, system prompts, and agent configs with the deterministic LintLang CLI. | hermes-labs-ai/ | 137 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 16 | Audit a named AI agent config, system prompt, tool definition, or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI in GitHub Copilot CLI. | hermes-labs-ai/ | 137 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 17 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 505 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 18 | Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 19 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 20 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Automatic quality control, linting, and static analysis procedures. | xenitV1/ | 130 | 6 repos | ~432 | Automated safety check: Notes | MIT | 8 mo ago |
| 22 | 22.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 23 | Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 24 | 24.Sast Sqli Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 25 | Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | BagelHole/ | 1.1k | — | ~2.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 26 | 26.Sast Xss Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 27 | 27.Binary Re This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work. | aiskillstore/ | 430 | 1 repo | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 28 | Validate API consistency between two versions of Python libraries. | ArabelaTso/ | 253 | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 30 | Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. | LeoYeAI/ | 2.2k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 31 | Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. | seb1n/ | 206 | — | ~2.6k | Automated safety check: Pass | MIT | 2 mo ago |