Search
Rust · Static analysis and SAST
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | 3 days ago |
| 2 | 2.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 391 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 3 | Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.5k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 5 | Keeps truST's architecture simple and well separated, and runs the automated architecture checks. | johannesPettersson80/ | 222 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 6 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.5k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 7 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.5k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 8 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.5k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 9 | Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. | LeoYeAI/ | 2.2k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 10 | A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source… | mtarcure/ | 165 | — | ~1.4k | Automated safety check: Pass | MIT | 19 days ago |