Agent skill

Static Vulnerability Detector

by ArabelaTso in ArabelaTso/Skills-4-SE

Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…

Apache-2.0Auto-check passedSecurity

Install Static Vulnerability Detector

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill static-vulnerability-detector -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE static-vulnerability-detector --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/static-vulnerability-detector .claude/skills/static-vulnerability-detector && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
static-vulnerability-detector
GitHub stars
253
Token cost
~2k tokens
SKILL.md length
577 words
Files
3 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…

  • Works in 5 steps: Code Scanning → Pattern Matching → Severity Assessment → …
  • Performing security code review
  • SKILL.md covers Analysis Workflow, Detection Heuristics, CWE Reference and Report Format, plus 2 more sections
  • Needs API_KEY

What it does

Static Vulnerability Detector is an agent skill from ArabelaTso/Skills-4-SE. Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials, and unsafe cryptography. Use when: (1) Performing security code review, (2) Analyzing code for OWASP Top 10 vulnerabilities, (3) Identifying CWE-classified weaknesses, (4) Generating security audit reports, (5) Reviewing code before deployment, or (6) Assessing third-party code security. Findings categorized by CWE ID…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/cwe_patterns.md` and `references/examples.md`).

It sits in Security, covering Web application vulnerabilities, Security review and Cryptography. It works with SQL and C++. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Performing security code review
  • Analyzing code for OWASP Top 10 vulnerabilities
  • Identifying CWE-classified weaknesses
  • Generating security audit reports

Example prompts

  • “/static-vulnerability-detector”

Requirements

  • Python 3
  • A credential in API_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Code Scanning
  2. Pattern Matching
  3. Severity Assessment
  4. Confidence Level
  5. Generate Report

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, markdown, language, c and javascript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Static Vulnerability Detector loads about 2k tokens when it runs, and up to ~7.3k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 577 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 577 words, ~1,955 tokens.

Download SKILL.mdSave it as .claude/skills/static-vulnerability-detector/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
static-vulnerability-detector
description
Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials, and unsafe cryptography. Use when: (1) Performing security code review, (2) Analyzing code for OWASP Top 10 vulnerabilities, (3) Identifying CWE-classified weaknesses, (4) Generating security audit reports, (5) Reviewing code before deployment, or (6) Assessing third-party code security. Findings categorized by CWE ID and severity (Critical/High/Medium/Low).

Static Vulnerability Detector

Analyze code for security vulnerabilities with CWE classification and severity assessment.

Analysis Workflow

1. Code Scanning

Systematically examine code for vulnerability patterns:

Memory Safety (C/C++):

  • Buffer overflows (CWE-119)
  • Out-of-bounds access (CWE-125)
  • Use-after-free (CWE-416)
  • Double free (CWE-415)
  • Null pointer dereference (CWE-476)

Injection Vulnerabilities:

  • SQL injection (CWE-89)
  • Command injection (CWE-78)
  • Cross-site scripting (CWE-79)
  • XML injection (CWE-91)
  • LDAP injection (CWE-90)

Authentication & Authorization:

  • Missing authentication (CWE-306)
  • Improper authentication (CWE-287)
  • Missing authorization (CWE-862)
  • Hard-coded credentials (CWE-798)

Cryptographic Issues:

  • Weak algorithms (CWE-327)
  • Inadequate encryption (CWE-326)
  • Weak random values (CWE-330)
  • Missing encryption (CWE-311)

Deserialization:

  • Untrusted deserialization (CWE-502)
  • Mass assignment (CWE-915)

Input Validation:

  • Improper validation (CWE-20)
  • Path traversal (CWE-22)
  • SSRF (CWE-918)
2. Pattern Matching

For each vulnerability category, identify:

Dangerous Functions:

  • C/C++: strcpy, sprintf, gets, scanf
  • Python: pickle.loads, eval, exec
  • SQL: String concatenation in queries
  • Shell: os.system, subprocess with shell=True

Unsafe Patterns:

  • Unvalidated user input
  • Missing bounds checking
  • Weak cryptographic algorithms
  • Hard-coded secrets
  • Missing authentication decorators

Context Analysis:

  • Data flow from user input to sink
  • Sanitization and validation presence
  • Authentication/authorization checks
  • Error handling adequacy
3. Severity Assessment

Assign severity based on:

CRITICAL:

  • Remote code execution possible
  • Authentication bypass
  • SQL injection with admin access
  • Arbitrary file read/write

HIGH:

  • Privilege escalation
  • Sensitive data exposure
  • Hard-coded credentials
  • Weak cryptography for sensitive data

MEDIUM:

  • Information disclosure
  • Denial of service
  • Missing input validation
  • Insecure configuration

LOW:

  • Minor information leaks
  • Verbose error messages
  • Missing security headers
4. Confidence Level

Assess confidence in finding:

HIGH: Clear vulnerability pattern, no mitigating factors MEDIUM: Vulnerability likely but context unclear LOW: Potential issue requiring manual verification

5. Generate Report

Structure findings as:

markdown
## Vulnerability: [Title]

**ID**: VULN-[number]
**CWE**: CWE-[ID]
**Severity**: [CRITICAL/HIGH/MEDIUM/LOW]
**Confidence**: [HIGH/MEDIUM/LOW]
**Location**: [File:Line]

### Description
[What the vulnerability is]

### Code Snippet
```[language]
[vulnerable code]
Impact
  • [Potential consequences]
Remediation
language
[fixed code]
References
  • [CWE link]
  • [OWASP reference]

## Vulnerability Categories

### Memory Safety (C/C++)

**Buffer Overflow (CWE-119)**:
```c
// VULNERABLE
char buf[10];
strcpy(buf, user_input);  // No bounds check

Use-After-Free (CWE-416):

c
// VULNERABLE
free(ptr);
ptr->field = value;  // Use after free
Injection Attacks

SQL Injection (CWE-89):

python
# VULNERABLE
query = f"SELECT * FROM users WHERE id = {user_id}"
cursor.execute(query)

Command Injection (CWE-78):

python
# VULNERABLE
os.system("ping " + user_host)

XSS (CWE-79):

javascript
// VULNERABLE
element.innerHTML = user_input;
Authentication Issues

Missing Authentication (CWE-306):

python
# VULNERABLE
@app.route('/admin')
def admin_panel():
    return render_template('admin.html')  # No auth check

Hard-coded Credentials (CWE-798):

python
# VULNERABLE
PASSWORD = "admin123"
API_KEY = "sk-1234567890"
Cryptographic Weaknesses

Weak Algorithm (CWE-327):

python
# VULNERABLE
hash = hashlib.md5(password.encode()).hexdigest()

Weak Random (CWE-330):

python
# VULNERABLE
token = random.randint(1000, 9999)  # For security token
Deserialization

Untrusted Data (CWE-502):

python
# VULNERABLE
obj = pickle.loads(user_data)  # RCE possible
Input Validation

Path Traversal (CWE-22):

python
# VULNERABLE
with open(f'/uploads/{filename}', 'r') as f:  # ../../../etc/passwd
    content = f.read()

SSRF (CWE-918):

python
# VULNERABLE
response = requests.get(user_url)  # Can access internal services

Detection Heuristics

Data Flow Analysis

Track tainted data from source to sink:

Sources (user input):

  • HTTP parameters, headers, body
  • Command-line arguments
  • File contents
  • Environment variables
  • Database queries

Sinks (dangerous operations):

  • SQL query execution
  • System command execution
  • File operations
  • HTML output
  • Deserialization

Sanitization (check for):

  • Input validation
  • Escaping/encoding
  • Parameterized queries
  • Whitelist filtering
Show full SKILL.md (221 more words)Show less
Pattern Recognition

Dangerous function calls:

  • Without input validation
  • With user-controlled arguments
  • In security-sensitive contexts

Missing security controls:

  • No authentication decorator
  • No authorization check
  • No CSRF protection
  • No rate limiting

Weak configurations:

  • Debug mode enabled
  • Verbose errors
  • Insecure defaults

CWE Reference

For detailed vulnerability patterns and remediation, see cwe_patterns.md.

Key CWE categories:

  • Memory safety (CWE-119, 125, 416, 415)
  • Injection (CWE-89, 78, 79, 91)
  • Authentication (CWE-287, 306, 798, 862)
  • Cryptography (CWE-327, 326, 330, 311)
  • Deserialization (CWE-502, 915)
  • Input validation (CWE-20, 22, 918)

Report Format

Summary Section
markdown
# Security Vulnerability Report

**Scan Date**: [Date]
**Code Base**: [Project]
**Total Findings**: [Count]

## Severity Breakdown
- Critical: [Count]
- High: [Count]
- Medium: [Count]
- Low: [Count]
Detailed Findings

For each vulnerability:

  • Unique ID
  • CWE classification
  • Severity and confidence
  • Location (file, line, function)
  • Description
  • Code snippet
  • Impact assessment
  • Remediation guidance
  • References
Recommendations

Prioritized action items:

  1. Fix critical vulnerabilities immediately
  2. Address high-severity issues
  3. Plan remediation for medium/low issues
  4. Implement security best practices

Examples

For complete vulnerability detection examples including:

  • SQL injection analysis
  • Buffer overflow detection
  • Hard-coded credentials
  • Insecure deserialization
  • Missing authentication
  • Weak cryptography

See examples.md.

Analysis Tips

  • Context matters: Consider surrounding code and mitigations
  • False positives: Mark uncertain findings as low confidence
  • Data flow: Trace user input to dangerous sinks
  • Defense in depth: Note multiple security layers
  • Language-specific: Apply appropriate patterns per language
  • Framework awareness: Consider framework protections
  • Configuration: Check for insecure settings
  • Dependencies: Note vulnerable library versions
  • Completeness: Scan all code paths
  • Prioritize: Focus on critical and high severity first

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/static-vulnerability-detector of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/cwe_patterns.md
  • references/examples.md

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Static Vulnerability Detector next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Static Vulnerability Detector compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Static Vulnerability Detector this skillArabelaTso/Skills-4-SE253—~2kAutomated safety check: PassApache-2.0
Code Security AuditProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Security Reviewliuyanghejerry/Clausura204—~106Automated safety check: PassMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.5kAutomated safety check: NotesMIT
Security Reviewxu-xiang/everything-claude-code-zh2k—~2.4kAutomated safety check: NotesMIT
Go ReviewSpecterOps/skills702—~2.1kAutomated safety check: PassApache-2.0

Similar skills

  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Security Review

    liuyanghejerry/Clausura

    检查 SQL 注入、XSS、硬编码密钥

    204 GitHub stars~106 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Security Review

    xu-xiang/everything-claude-code-zh

    当涉及添加身份验证(Authentication)、处理用户输入、操作机密(Secrets)、创建 API 终端节点或实现支付/敏感功能时,请使用此技能。提供全面的安全检查清单和模式。

    2k GitHub stars~2.5k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Security Review

    xu-xiang/everything-claude-code-zh

    在添加身份验证、处理用户输入、操作机密信息、创建 API 接口或实现支付/敏感功能时使用此技能。提供全面的安全自查清单和模式。

    2k GitHub stars~2.4k tokensUpdated 7 mo ago
    SecurityAuto-check: notes
  • Go Review

    SpecterOps/skills

    Performs security review of arbitrary Go packages, including libraries, frameworks, CLIs, HTTP and gRPC services, and backend applications.

    702 GitHub stars~2.1k tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes

More from ArabelaTso/Skills-4-SE

All 150 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Static Vulnerability Detector

What does Static Vulnerability Detector do?

Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials…. Static Vulnerability Detector is an agent skill from ArabelaTso/Skills-4-SE. Statically analyze code to detect security vulnerabilities including buffer overflows, injection risks (SQL, command, XSS), insecure deserialization, improper authentication, hard-coded credentials, and unsafe cryptography.

When should I use Static Vulnerability Detector?

Static Vulnerability Detector fits situations like: performing security code review; analyzing code for OWASP Top 10 vulnerabilities; identifying CWE-classified weaknesses; generating security audit reports.

How do I install Static Vulnerability Detector in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill static-vulnerability-detector -a claude-code`. Or copy the skill folder (skills/static-vulnerability-detector in ArabelaTso/Skills-4-SE) into .claude/skills/static-vulnerability-detector in your project. Claude Code loads it when a task matches its description.

How do I install Static Vulnerability Detector in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill static-vulnerability-detector -a codex`. Or copy the skill folder (skills/static-vulnerability-detector in ArabelaTso/Skills-4-SE) into .agents/skills/static-vulnerability-detector in your project. Codex loads it when a task matches its description.

Can I use Static Vulnerability Detector in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill static-vulnerability-detector -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/static-vulnerability-detector, .gemini/skills/static-vulnerability-detector, .github/skills/static-vulnerability-detector and .opencode/skills/static-vulnerability-detector in your project.

What does Static Vulnerability Detector need to run?

Going by SKILL.md and its folder, Static Vulnerability Detector needs credentials named API_KEY. Our summary lists: Python 3; A credential in API_KEY.

Does Static Vulnerability Detector access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Static Vulnerability Detector safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Static Vulnerability Detector use?

Static Vulnerability Detector is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Static Vulnerability Detector use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.

What are the alternatives to Static Vulnerability Detector?

Skills that share tags, products or a category with Static Vulnerability Detector: Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Security Review (liuyanghejerry/Clausura, 204 stars), Security Review (xu-xiang/everything-claude-code-zh, 2k stars) and Security Review (xu-xiang/everything-claude-code-zh, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Static Vulnerability Detector?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.