Search
Static analysis and SAST
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Turns natural-language code queries into ast-grep rules for structural search, testing each rule against an example file before running it on a codebase. | warp-drive-data/ | 3.2k | 5 repos | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 2 | Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script. | code-yeongyu/ | 70k | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 3 | A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures. | biomejs/ | 26k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. | elastic/ | 21k | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 5 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 6 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | yesterday |
| 7 | Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build. | dotnet/ | 5.6k | 1 repo | ~3.3k | Automated safety check: Pass | MIT | today |
| 8 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 9 | 9.Semgrep Run Semgrep static analysis scan on a codebase using parallel subagents. | vigolium/ | 140 | 1 repo | ~2.4k | Automated safety check: Notes | MIT | 18 days ago |
| 10 | 10.C To Ast Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills. | Narwhal-Lab/ | 316 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 11 | Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. | SonarSource/ | 1.2k | — | ~833 | Automated safety check: Pass | Unknown | today |
| 12 | 12.Sonarqube Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed… | DougTrajano/ | 377 | — | ~2.2k | Automated safety check: Pass | MIT | 4 days ago |
| 13 | 13.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 23 days ago |
| 15 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 423 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 16 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 17 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 18 | General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. | SunWeb3Sec/ | 286 | — | ~6.2k | Automated safety check: Pass | No licence | 1 mo ago |
| 19 | 19.Lintlang A skill your agent uses when writing or reviewing AI agent configs, system prompts, or tool definitions (JSON/YAML/Python) and you need to catch ambiguous tool descriptions, missing stop conditions… | hermes-labs-ai/ | 137 | 1 repo | ~719 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 20 | Audit and enable security-oriented Xcode build settings. An agent skill from superagents-lab/xcode27-skills. | superagents-lab/ | 338 | — | ~4.6k | Automated safety check: Pass | No licence | 4 mo ago |
| 21 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 22 | Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration. | ozgurcd/ | 227 | — | ~4.8k | Automated safety check: Notes | MIT | yesterday |
| 23 | 23.Sast Semgrep Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. | AgentSecOps/ | 220 | 2 repos | ~2.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 24 | Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. | tradecatlabs/ | 17k | 1 repo | ~738 | Automated safety check: Pass | Apache-2.0 | today |
| 25 | Safely unpack and investigate existing archives through evidence-first static analysis. | AetherKiri/ | 149 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | today |
| 26 | Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page. | openqa-cn/ | 152 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 27 | Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request. | hermes-labs-ai/ | 137 | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 28 | Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. | netdata/ | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | today |
| 29 | GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release… | samber/ | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | 7 days ago |
| 30 | 30.Openqodex Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex. | openqodex/ | 303 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 31 | Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication. | kucherenko/ | 6.4k | — | ~4.5k | Automated safety check: Pass | MIT | yesterday |
| 32 | Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks. | seqra/ | 162 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 33 | 33.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 34 | Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. | telagod/ | 243 | — | ~552 | Automated safety check: Notes | MIT | 2 mo ago |
| 35 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 36 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 37 | Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to. | arandu-io/ | 281 | — | ~1.2k | Automated safety check: Pass | MIT | 4 days ago |
| 38 | Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation. | ptn1411/ | 219 | — | ~917 | Automated safety check: Pass | No licence | 16 days ago |
| 39 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 3 days ago |
| 40 | 40.Wp Phpstan A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and… | Automattic/ | 211 | 1 repo | ~1k | Automated safety check: Pass | No licence | 8 mo ago |
| 41 | 41.Audit A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. | vigolium/ | 140 | — | ~8.7k | Automated safety check: Pass | MIT | 18 days ago |
| 42 | Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. | clone45/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 23 days ago |
| 43 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 44 | 44.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 45 | Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode. | redhat-et/ | 2.4k | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 46 | Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled. | garrytan/ | 136k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 47 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 48 | 48.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 129 | — | ~8.5k | Automated safety check: Pass | MIT | yesterday |