Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

MITAuto-check passedSecurity

Install Sast Scanning

skills CLI
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sast-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BagelHole/DevOps-Security-Agent-Skills sast-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/scanning/sast-scanning .claude/skills/sast-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sast-scanning
GitHub stars
1.2k
Token cost
~2.2k tokens
SKILL.md length
224 words
Files
2 (incl. references)
Skills in repo
44
Repo updated
First seen
Licence
MIT

At a glance

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

  • Implementing secure SDLC
  • SKILL.md covers When to Use This Skill, Prerequisites, Tool Comparison and Semgrep, plus 7 more sections
  • Calls semgrep, pip and jq; needs SONAR_TOKEN and SEMGREP_APP_TOKEN
  • Code review automation

What it does

Sast Scanning is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. Identify security vulnerabilities in source code before deployment. Use when implementing secure SDLC, code review automation, or security gates in CI/CD pipelines.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/sast-tools.md`).

It sits in Security, covering Static analysis and SAST. It works with Semgrep and Python. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.

When your agent uses it

  • Implementing secure SDLC
  • Code review automation
  • Security gates in CI/CD pipelines

Example prompts

  • “/sast-scanning”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in SEMGREP_APP_TOKEN
  • A credential in SONAR_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep
    • pip
    • jq
    • brew
    • npm
    • gem

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN
    • SEMGREP_APP_TOKEN
    • SONAR_JDBC_PASSWORD
    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sast Scanning loads about 2.2k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 68 tokens; SKILL.md has 224 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~68
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 224 words, ~2,202 tokens.

Download SKILL.mdSave it as .claude/skills/sast-scanning/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
sast-scanning
description
Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. Identify security vulnerabilities in source code before deployment. Use when implementing secure SDLC, code review automation, or security gates in CI/CD pipelines.
license
MIT
metadata.author
devops-skills
metadata.version
1.0

SAST Scanning

Identify security vulnerabilities in source code through static analysis.

When to Use This Skill

Use this skill when:

  • Implementing secure SDLC practices
  • Adding security gates to CI/CD
  • Automating code security reviews
  • Finding vulnerabilities before deployment
  • Meeting compliance requirements

Prerequisites

  • Source code access
  • CI/CD pipeline
  • SAST tool installation

Tool Comparison

ToolLicenseLanguagesBest For
SemgrepOSS/Commercial30+Custom rules, speed
CodeQLFree (GitHub)10+Deep analysis
SonarQubeOSS/Commercial25+Quality + Security
BanditOSSPythonPython projects
BrakemanOSSRubyRails apps

Semgrep

Installation
bash
# Install via pip
pip install semgrep

# Or via Homebrew
brew install semgrep
Basic Usage
bash
# Run with default rules
semgrep --config auto .

# Run specific rulesets
semgrep --config p/security-audit .
semgrep --config p/owasp-top-ten .
semgrep --config p/ci .

# Scan specific languages
semgrep --config p/python .
semgrep --config p/javascript .

# Output formats
semgrep --config auto --json -o results.json .
semgrep --config auto --sarif -o results.sarif .
Custom Rules
yaml
# .semgrep/custom-rules.yaml
rules:
  - id: hardcoded-password
    patterns:
      - pattern-either:
          - pattern: password = "..."
          - pattern: PASSWORD = "..."
          - pattern: passwd = "..."
    message: Hardcoded password detected
    severity: ERROR
    languages: [python, javascript, java]
    metadata:
      cwe: "CWE-798"
      owasp: "A3:2017"

  - id: sql-injection
    patterns:
      - pattern: |
          $QUERY = "..." + $USER_INPUT + "..."
          $DB.execute($QUERY)
    message: Potential SQL injection
    severity: ERROR
    languages: [python]
    metadata:
      cwe: "CWE-89"

  - id: insecure-random
    pattern: random.random()
    message: Use secrets module for security-sensitive randomness
    severity: WARNING
    languages: [python]
    fix: secrets.token_hex()
CI Configuration
yaml
# .github/workflows/semgrep.yml
name: Semgrep

on:
  push:
    branches: [main]
  pull_request:

jobs:
  semgrep:
    runs-on: ubuntu-latest
    container:
      image: returntocorp/semgrep
    steps:
      - uses: actions/checkout@v4

      - name: Run Semgrep
        run: semgrep ci
        env:
          SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}

CodeQL

Setup
yaml
# .github/workflows/codeql.yml
name: CodeQL Analysis

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]
  schedule:
    - cron: '0 0 * * 0'

jobs:
  analyze:
    runs-on: ubuntu-latest
    permissions:
      security-events: write
      actions: read
      contents: read

    strategy:
      matrix:
        language: ['javascript', 'python']

    steps:
      - uses: actions/checkout@v4

      - name: Initialize CodeQL
        uses: github/codeql-action/init@v3
        with:
          languages: ${{ matrix.language }}
          queries: +security-and-quality

      - name: Autobuild
        uses: github/codeql-action/autobuild@v3

      - name: Perform CodeQL Analysis
        uses: github/codeql-action/analyze@v3
        with:
          category: "/language:${{ matrix.language }}"
Custom Queries
ql
// queries/sql-injection.ql
/**
 * @name SQL Injection
 * @description User input in SQL query
 * @kind path-problem
 * @problem.severity error
 * @security-severity 9.0
 * @precision high
 * @id py/sql-injection
 * @tags security
 */

import python
import semmle.python.dataflow.new.DataFlow
import semmle.python.dataflow.new.TaintTracking
import semmle.python.security.dataflow.SqlInjectionQuery

from SqlInjectionConfiguration config, DataFlow::PathNode source, DataFlow::PathNode sink
where config.hasFlowPath(source, sink)
select sink.getNode(), source, sink, "SQL injection from $@.", source.getNode(), "user input"

SonarQube

Docker Setup
yaml
# docker-compose.yml
version: '3.8'

services:
  sonarqube:
    image: sonarqube:lts-community
    ports:
      - "9000:9000"
    environment:
      - SONAR_JDBC_URL=jdbc:postgresql://db:5432/sonar
      - SONAR_JDBC_USERNAME=sonar
      - SONAR_JDBC_PASSWORD=sonar
    volumes:
      - sonarqube_data:/opt/sonarqube/data
      - sonarqube_logs:/opt/sonarqube/logs
    depends_on:
      - db

  db:
    image: postgres:15
    environment:
      - POSTGRES_USER=sonar
      - POSTGRES_PASSWORD=sonar
      - POSTGRES_DB=sonar
    volumes:
      - postgresql_data:/var/lib/postgresql/data

volumes:
  sonarqube_data:
  sonarqube_logs:
  postgresql_data:
Scanner Configuration
properties
# sonar-project.properties
sonar.projectKey=myproject
sonar.projectName=My Project
sonar.projectVersion=1.0

sonar.sources=src
sonar.tests=tests
sonar.exclusions=**/node_modules/**,**/vendor/**

sonar.language=py
sonar.python.coverage.reportPaths=coverage.xml

sonar.qualitygate.wait=true
CI Integration
yaml
# GitHub Actions
- name: SonarQube Scan
  uses: sonarsource/sonarqube-scan-action@master
  env:
    SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
    SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}

- name: Quality Gate
  uses: sonarsource/sonarqube-quality-gate-action@master
  timeout-minutes: 5
  env:
    SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}

Language-Specific Tools

Python (Bandit)
bash
# Install
pip install bandit

# Run scan
bandit -r src/ -f json -o bandit-report.json

# With configuration
bandit -r src/ -c bandit.yaml
yaml
# bandit.yaml
skips: ['B101', 'B601']
exclude_dirs: ['tests', 'venv']

assert_used:
  skips: ['*_test.py', '*_tests.py']
JavaScript (ESLint Security)
bash
# Install
npm install eslint eslint-plugin-security --save-dev
javascript
// .eslintrc.js
module.exports = {
  plugins: ['security'],
  extends: ['plugin:security/recommended'],
  rules: {
    'security/detect-object-injection': 'error',
    'security/detect-non-literal-regexp': 'warn',
    'security/detect-unsafe-regex': 'error',
    'security/detect-buffer-noassert': 'error',
    'security/detect-eval-with-expression': 'error',
    'security/detect-no-csrf-before-method-override': 'error',
    'security/detect-possible-timing-attacks': 'warn'
  }
};
Ruby (Brakeman)
bash
# Install
gem install brakeman

# Run scan
brakeman -o brakeman-report.json -f json

# CI configuration
brakeman --no-exit-on-warn --no-exit-on-error -o report.html

Quality Gates

SonarQube Quality Gate
json
{
  "name": "Security Gate",
  "conditions": [
    {
      "metric": "new_security_rating",
      "op": "GT",
      "error": "1"
    },
    {
      "metric": "new_vulnerabilities",
      "op": "GT",
      "error": "0"
    },
    {
      "metric": "new_security_hotspots_reviewed",
      "op": "LT",
      "error": "100"
    }
  ]
}
Custom Gate Script
bash
#!/bin/bash
# security-gate.sh

CRITICAL=$(cat results.json | jq '[.results[] | select(.severity == "critical")] | length')
HIGH=$(cat results.json | jq '[.results[] | select(.severity == "high")] | length')

echo "Critical: $CRITICAL, High: $HIGH"

if [ "$CRITICAL" -gt 0 ]; then
  echo "FAILED: Critical vulnerabilities found"
  exit 1
fi

if [ "$HIGH" -gt 5 ]; then
  echo "FAILED: Too many high severity vulnerabilities"
  exit 1
fi

echo "PASSED: Security gate"
exit 0

Common Issues

Issue: Too Many False Positives

Problem: Alerts on safe code patterns Solution: Tune rules, add suppressions, use baseline

Issue: Slow Scans

Problem: SAST taking too long in CI Solution: Incremental scanning, parallel execution, exclude test files

Issue: Missing Coverage

Problem: Vulnerabilities not detected Solution: Add custom rules, combine multiple tools

Best Practices

  • Run on every PR/commit
  • Establish baseline for existing code
  • Prioritize by severity and exploitability
  • Maintain custom rules for your codebase
  • Integrate with IDE for early feedback
  • Track trends over time
  • Document false positive suppressions
  • Combine with DAST for comprehensive coverage

© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in security/scanning/sast-scanning of BagelHole/DevOps-Security-Agent-Skills.

  • SKILL.md
  • references/sast-tools.md

Open the folder on GitHubat commit 0365f57

Compare with similar skills

Sast Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sast Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sast Scanning this skillBagelHole/DevOps-Security-Agent-Skills1.2k—~2.2kAutomated safety check: PassMIT
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Sarif Parsingtrailofbits/skills7.5k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0
Detection Breadthdeonmenezes/mantishack503—~510Automated safety check: PassApache-2.0
Sast Scanningsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Clawsec ScannerLeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT

Similar skills

  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Sarif Parsing

    trailofbits/skills

    Official

    Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

    7.5k GitHub starsUsed in 3 repos~4.4k tokens
    SecurityAuto-check: notes
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    503 GitHub stars~510 tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Sast Scanning

    sickn33/agentic-awesome-skills

    Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

    47k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Clawsec Scanner

    LeoYeAI/openclaw-master-skills

    Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Static Application Security Testing

    seb1n/awesome-ai-agent-skills

    Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

    206 GitHub stars~2.6k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from BagelHole/DevOps-Security-Agent-Skills

All 44 skills in this repo
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Kubernetes Ops

    BagelHole/DevOps-Security-Agent-Skills

    Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~662 tokensUpdated 4 mo ago
    Auto-check: notes
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.2k GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Vulnerability Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    1.2k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Sast Scanning

What does Sast Scanning do?

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. Sast Scanning is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

When should I use Sast Scanning?

Sast Scanning fits situations like: implementing secure SDLC; code review automation; security gates in CI/CD pipelines.

How do I install Sast Scanning in Claude Code?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sast-scanning -a claude-code`. Or copy the skill folder (security/scanning/sast-scanning in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/sast-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Sast Scanning in Codex?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sast-scanning -a codex`. Or copy the skill folder (security/scanning/sast-scanning in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/sast-scanning in your project. Codex loads it when a task matches its description.

Can I use Sast Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sast-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sast-scanning, .gemini/skills/sast-scanning, .github/skills/sast-scanning and .opencode/skills/sast-scanning in your project.

What does Sast Scanning need to run?

Going by SKILL.md and its folder, Sast Scanning needs the command-line tools its instructions call (semgrep, pip, jq, brew, npm and gem) and credentials named SONAR_TOKEN, SEMGREP_APP_TOKEN, SONAR_JDBC_PASSWORD and POSTGRES_PASSWORD. Our summary lists: Python 3; Node.js; Docker; A credential in SEMGREP_APP_TOKEN; A credential in SONAR_TOKEN.

Does Sast Scanning access the network?

SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sast Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sast Scanning use?

Sast Scanning is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sast Scanning use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 497 tokens, read only when the agent opens those files.

What are the alternatives to Sast Scanning?

Skills that share tags, products or a category with Sast Scanning: Kedro Security Review (kedro-org/kedro, 11k stars), Sarif Parsing (trailofbits/skills, 7.5k stars), Detection Breadth (deonmenezes/mantishack, 503 stars) and Sast Scanning (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sast Scanning?

BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,152 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on May 22, 2026.

Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.