Search

Semgrep · Static analysis and SAST

46 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknown2 days ago
2

Run Semgrep static analysis scan on a codebase using parallel subagents.

vigolium/piolium1401 repo~2.4kAutomated safety check: NotesMIT21 days ago
3

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0yesterday
4

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

openqodex/openqodex573—~2.5kAutomated safety check: PassApache-2.0today
5

Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

AgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassUnknown5 mo ago
6

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.03 days ago
7

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.5k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0yesterday
8

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.5k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
9

Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

waybarrios/opencode-power-pack534—~2.4kAutomated safety check: PassMIT5 days ago
10
10.SemgrepOfficial

Run Semgrep static analysis scans and create custom detection rules.

semgrep/skills324—~2.3kAutomated safety check: PassUnknown2 mo ago
11
11.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.5k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
12

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack503—~510Automated safety check: PassApache-2.08 days ago
13

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

skrun-dev/skrun210—~1.3kAutomated safety check: PassMIT18 days ago
14

A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

zhaoxuya520/reverse-skill41k2 repos~374Automated safety check: WarnMIT19 days ago
15

Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

davila7/claude-code-templates33k11 repos~1.6kAutomated safety check: PassMITtoday
16

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by…

hardw00t/ai-security-arsenal105—~2.7kAutomated safety check: PassNo licence5 mo ago
17

Find similar vulnerabilities and bugs across codebases using pattern-based analysis.

waybarrios/opencode-power-pack5345 repos~1.4kAutomated safety check: PassMIT5 days ago
18

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT7 days ago
19

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

Zfinix/aster118—~1.2kAutomated safety check: PassApache-2.02 days ago
20

Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.

KimYx0207/Kim_Service174—~1.2kAutomated safety check: PassMITyesterday
21

Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data.

trailofbits/skills7.5k—~2.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
22

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
23

Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

cyberful/cyberful135—~1.3kAutomated safety check: PassAGPL-3.01 mo ago
24

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

trailofbits/skills7.5k—~2.5kAutomated safety check: PassCC-BY-SA-4.0yesterday
25

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common…

trailofbits/skills7.5k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0yesterday
26
26.Variant AnalysisOfficial

Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.

trailofbits/skills7.5k—~967Automated safety check: PassCC-BY-SA-4.0yesterday
27

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
28

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
29

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

vibeeval/vibecosystem532—~4.6kAutomated safety check: PassMIT2 mo ago
30

Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification.

sickn33/agentic-awesome-skills47k1 repo~480Automated safety check: PassMIT2 days ago
31

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

sickn33/agentic-awesome-skills47k1 repo~2.4kAutomated safety check: PassMIT2 days ago
32

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

aiskillstore/marketplace4337 repos~3.7kAutomated safety check: PassNo licenceyesterday
33

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
34

A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint…

mtarcure/claude-vibe-squad165—~1.5kAutomated safety check: PassMIT20 days ago
35

Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape.

alpha-omega-security/scrutineer242—~439Automated safety check: PassMITyesterday
36

Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

petrkindlmann/qa-skills170—~4.9kAutomated safety check: PassMIT4 mo ago
37

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

BagelHole/DevOps-Security-Agent-Skills1.2k—~2.2kAutomated safety check: PassMIT4 mo ago
38

Draft operational mitigations for a finding consumers can apply before a fix ships.

alpha-omega-security/scrutineer242—~1.3kAutomated safety check: PassMITyesterday
39

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

BankrBot/skills1.2k—~858Automated safety check: PassNo licenceyesterday
40

Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle

deonmenezes/mantishack503—~312Automated safety check: PassApache-2.08 days ago
41

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

ericrisco/rsc-harness180—~2.8kAutomated safety check: NotesMITyesterday
42

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT2 mo ago
43

Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~750Automated safety check: NotesMITyesterday
44

Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…

sundial-org/awesome-openclaw-skills663—~875Automated safety check: PassNo licence7 mo ago
45

A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now…

OneWave-AI/claude-skills336—~836Automated safety check: PassMIT9 days ago
46

Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

seb1n/awesome-ai-agent-skills206—~2.6kAutomated safety check: PassMIT2 mo ago