Agent skill

Static Application Security Testing

by seb1n in seb1n/awesome-ai-agent-skills

Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

MITAuto-check passedSecurity

Install Static Application Security Testing

skills CLI
$ npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install seb1n/awesome-ai-agent-skills static-application-security-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/static-application-security-testing .claude/skills/static-application-security-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
static-application-security-testing
GitHub stars
206
Token cost
~2.6k tokens
SKILL.md length
882 words
Files
1
Skills in repo
92
Repo updated
First seen
Licence
MIT

At a glance

Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

  • Works in 6 steps: Detect Languages and Frameworks —… → Select and Configure SAST Tools — Choose… → Execute Static Analysis — Run the… → …
  • The user requests static application security testing
  • SKILL.md covers Workflow, Supported Technologies, Usage and Examples, plus 3 more sections
  • Calls semgrep; needs DB_PASSWORD and JWT_SECRET

What it does

Static Application Security Testing is an agent skill from seb1n/awesome-ai-agent-skills. Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. Use when the user requests static application security testing or provides relevant inputs for this workflow.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST. It works with Semgrep and Python. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.

When your agent uses it

  • The user requests static application security testing
  • Provides relevant inputs for this workflow

Example prompts

  • “/static-application-security-testing”

Requirements

  • Python 3
  • A credential in JWT_SECRET

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Detect Languages and Frameworks — Analyze the repository to determine primary languages (Python, JavaScript, Java, Go, C#, etc.) and…
  2. Select and Configure SAST Tools — Choose the appropriate tools for the detected stack. Use Semgrep for multi-language pattern matching…
  3. Execute Static Analysis — Run the selected tools against the codebase. Capture all findings including the vulnerability type, affected…
  4. Triage and Deduplicate Findings — Merge results from multiple tools, remove duplicate detections of the same issue, and classify findings…
  5. Generate Report with Fix Suggestions — Produce a structured findings report grouped by severity and category. Include the vulnerable code…
  6. Integrate into CI Pipeline — Configure the scan to run on every pull request or push to protected branches. Set quality gates that block…

What it can do on your machine

Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DB_PASSWORD
    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Static Application Security Testing loads about 2.6k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 882 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 882 words, ~2,620 tokens.

Download SKILL.mdSave it as .claude/skills/static-application-security-testing/SKILL.md (or your agent's skills folder).
name
static-application-security-testing
description
Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. Use when the user requests static application security testing or provides relevant inputs for this workflow.
license
MIT
metadata.author
awesome-ai-agent-skills
metadata.version
1.0.0

Static Application Security Testing

This skill enables the agent to perform Static Application Security Testing (SAST) on source code repositories to detect security vulnerabilities without executing the application. The agent selects appropriate analysis tools based on the project's language, runs scans with relevant rule sets, triages findings to separate true positives from false positives, and integrates results into CI/CD pipelines. SAST catches issues such as SQL injection, cross-site scripting, hardcoded secrets, insecure deserialization, and cryptographic misuse early in the development lifecycle.

Workflow

  1. Detect Languages and Frameworks — Analyze the repository to determine primary languages (Python, JavaScript, Java, Go, C#, etc.) and frameworks in use. This determines which SAST tools and rule sets are applicable. Check for existing tool configurations like .semgrep.yml, codeql query packs, or .bandit config files.

  2. Select and Configure SAST Tools — Choose the appropriate tools for the detected stack. Use Semgrep for multi-language pattern matching, CodeQL for deep semantic analysis, Bandit for Python-specific checks, and ESLint security plugins for JavaScript/TypeScript. Load built-in security rule sets and any project-specific custom rules.

  3. Execute Static Analysis — Run the selected tools against the codebase. Capture all findings including the vulnerability type, affected file and line number, severity level, CWE identifier, and a description of the issue. For large codebases, parallelize scans across multiple tools simultaneously.

  4. Triage and Deduplicate Findings — Merge results from multiple tools, remove duplicate detections of the same issue, and classify findings as true positive, false positive, or needs-review. Use contextual analysis such as checking whether a flagged SQL string actually reaches a database driver to reduce noise.

  5. Generate Report with Fix Suggestions — Produce a structured findings report grouped by severity and category. Include the vulnerable code snippet, an explanation of the risk, a suggested fix with corrected code, and references to relevant CWE entries and OWASP categories.

  6. Integrate into CI Pipeline — Configure the scan to run on every pull request or push to protected branches. Set quality gates that block merges when critical or high-severity findings are introduced. Output results in SARIF format for integration with GitHub Code Scanning, GitLab SAST, or SonarQube.

Supported Technologies

  • Multi-language: Semgrep (Python, JS/TS, Java, Go, Ruby, C#, PHP, Kotlin, Rust)
  • Deep Semantic Analysis: CodeQL (Java, JavaScript, Python, C/C++, C#, Go, Ruby)
  • Python: Bandit, Pylint security checkers
  • JavaScript/TypeScript: ESLint (eslint-plugin-security, eslint-plugin-no-secrets), njsscan
  • Java: SpotBugs with Find Security Bugs plugin, PMD
  • Output Formats: SARIF, JSON, JUnit XML, Markdown
  • CI Platforms: GitHub Actions, GitLab CI, Jenkins, Azure DevOps

Usage

Provide the agent with the path to a source code repository. Optionally specify target languages, custom rule files, or a CI platform for pipeline integration. The agent will run the appropriate SAST tools and deliver a prioritized findings report.

Prompt example:

Run SAST on the Python application in /app using Semgrep and Bandit. Flag any SQL injection, hardcoded secrets, and insecure deserialization. Output results in SARIF format for GitHub Code Scanning.

Examples

Example 1: Semgrep Scan on a Python Flask Application

Command:

bash
semgrep scan --config=p/owasp-top-ten --config=p/python --json --output=semgrep-results.json /app

Findings (excerpt):

┌─────────────────────────────────────────────────────────────────┐
│ python.flask.security.injection.sql-injection-with-format-string │
│ Severity: ERROR  │  CWE-89  │  OWASP A03:2021                  │
├─────────────────────────────────────────────────────────────────┤
│ /app/routes/users.py:42                                         │
│                                                                 │
│   40│   def search_users(name):                                 │
│   41│       query = f"SELECT * FROM users WHERE name = '{name}'"│
│   42│       result = db.execute(query)                          │
│                                                                 │
│ Fix: Use parameterized queries instead of string formatting.    │
├─────────────────────────────────────────────────────────────────┤
│ python.lang.security.audit.hardcoded-password                   │
│ Severity: WARNING  │  CWE-798  │  OWASP A07:2021               │
├─────────────────────────────────────────────────────────────────┤
│ /app/config.py:11                                               │
│                                                                 │
│   10│   class Config:                                           │
│   11│       DB_PASSWORD = "SuperSecret123!"                     │
│   12│       JWT_SECRET = "my-jwt-secret"                        │
│                                                                 │
│ Fix: Load secrets from environment variables or a secrets       │
│      manager, never hardcode them in source files.              │
└─────────────────────────────────────────────────────────────────┘

Fixed code for the SQL injection finding:

python
# BEFORE — vulnerable to SQL injection
def search_users(name):
    query = f"SELECT * FROM users WHERE name = '{name}'"
    result = db.execute(query)
    return result

# AFTER — parameterized query
def search_users(name):
    query = "SELECT * FROM users WHERE name = :name"
    result = db.execute(text(query), {"name": name})
    return result
Example 2: CodeQL Query for Insecure Deserialization in Java

Custom CodeQL query (insecure-deserialization.ql):

ql
/**
 * @name Insecure deserialization of untrusted data
 * @description Deserializing data from an untrusted source without validation
 *              can lead to remote code execution.
 * @kind path-problem
 * @problem.severity error
 * @id java/insecure-deserialization
 * @tags security
 *       cwe-502
 *       owasp-a08
 */

import java
import semmle.code.java.dataflow.TaintTracking
import semmle.code.java.security.UnsafeDeserializationQuery

from UnsafeDeserializationConfig config, DataFlow::PathNode source, DataFlow::PathNode sink
where config.hasFlowPath(source, sink)
select sink.getNode(), source, sink,
  "Untrusted data from $@ is deserialized here without validation.", source.getNode(),
  "user-controlled input"

Running the query:

bash
codeql database create java-db --language=java --source-root=/app
codeql database analyze java-db insecure-deserialization.ql --format=sarif-latest --output=codeql-results.sarif

Sample finding:

/app/src/main/java/com/example/api/ImportController.java:35
  ObjectInputStream ois = new ObjectInputStream(request.getInputStream());
  Object obj = ois.readObject();  // CWE-502: untrusted deserialization

Fix: Replace ObjectInputStream with a safe alternative like JSON deserialization
     with explicit type binding, or use an allowlist-based ObjectInputFilter.
Show full SKILL.md (395 more words)Show less

Best Practices

  • Shift left — scan on every pull request — catching vulnerabilities during code review is 10-100x cheaper than finding them in production. Configure SAST as a required CI check on all protected branches.
  • Tune rules to reduce false positives — start with a curated security rule set (e.g., Semgrep p/owasp-top-ten) rather than enabling all rules. Add suppressions for confirmed false positives with documented justification.
  • Layer multiple tools — no single SAST tool catches everything. Combine pattern-based tools (Semgrep) with semantic analysis tools (CodeQL) for broader coverage. Each tool has different strengths.
  • Create custom rules for your codebase — write project-specific Semgrep or CodeQL rules to enforce internal security patterns, such as ensuring all database queries go through a sanitizing wrapper function.
  • Use SARIF for unified reporting — the Static Analysis Results Interchange Format is supported by GitHub, GitLab, Azure DevOps, and SonarQube, enabling a single dashboard for all SAST findings regardless of the tool that produced them.

Safety Boundaries

  • Work only on systems the user owns or is explicitly authorized to assess, and record the approved scope before testing.
  • Start with passive or read-only inspection. Obtain explicit approval before active scanning, exploitation, load generation, or disruptive remediation.
  • Never expose secrets, extract unrelated data, weaken production controls, or expand beyond the approved targets.
  • Preserve evidence, minimize impact, stop on instability, and provide rollback or containment steps for every material change.

Edge Cases

  • Generated or vendored code — SAST tools will flag issues in auto-generated protobuf stubs, vendored dependencies, or migration files. Exclude these paths from scanning using .semgrepignore or CodeQL path filters to avoid noise.
  • Template languages and DSLs — Jinja2 templates, ERB, JSX, and other templating languages may not be fully parsed by all SAST tools. Use tool-specific plugins or supplementary scanners that understand the template syntax.
  • False positives in test code — test files often contain intentionally insecure patterns (e.g., hardcoded test credentials, raw SQL for test setup). Configure separate rule sets or severity thresholds for test directories.
  • Large monorepos with slow scan times — full CodeQL analysis on a million-line monorepo can take over an hour. Use incremental analysis, scan only changed files on PRs, and run full scans on a nightly schedule.
  • Secrets in historical commits — SAST tools scan the current working tree, not Git history. Pair SAST with secret scanning tools like Gitleaks or TruffleHog to detect credentials committed in past revisions and still present in the Git log.

© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in security/static-application-security-testing of seb1n/awesome-ai-agent-skills.

Open the folder on GitHubat commit 75865a5

Compare with similar skills

Static Application Security Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Static Application Security Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Static Application Security Testing this skillseb1n/awesome-ai-agent-skills206—~2.6kAutomated safety check: PassMIT
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Sarif Parsingtrailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0
Detection Breadthdeonmenezes/mantishack505—~510Automated safety check: PassApache-2.0
Sast Scanningsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Sast ScanningBagelHole/DevOps-Security-Agent-Skills1.1k—~2.2kAutomated safety check: PassMIT

Similar skills

  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Sarif Parsing

    trailofbits/skills

    Official

    Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

    7.4k GitHub starsUsed in 3 repos~4.4k tokens
    SecurityAuto-check: notes
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    505 GitHub stars~510 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Sast Scanning

    sickn33/agentic-awesome-skills

    Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

    47k GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check passed
  • Sast Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

    1.1k GitHub stars~2.2k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Clawsec Scanner

    LeoYeAI/openclaw-master-skills

    Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from seb1n/awesome-ai-agent-skills

All 92 skills in this repo
  • Agent Red Teaming

    seb1n/awesome-ai-agent-skills

    Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.

    206 GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Human In The Loop

    seb1n/awesome-ai-agent-skills

    Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • MCP Server Building

    seb1n/awesome-ai-agent-skills

    Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • PDF Processing

    seb1n/awesome-ai-agent-skills

    Inspect, extract, OCR, create, merge, split, reorder, rotate, annotate, fill, redact, compress, secure, and verify PDF documents while preserving source files and visual fidelity.

    206 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Skill Supply Chain Audit

    seb1n/awesome-ai-agent-skills

    Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.

    206 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Static Application Security Testing

What does Static Application Security Testing do?

Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. Static Application Security Testing is an agent skill from seb1n/awesome-ai-agent-skills. Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

When should I use Static Application Security Testing?

Static Application Security Testing fits situations like: the user requests static application security testing; provides relevant inputs for this workflow.

How do I install Static Application Security Testing in Claude Code?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a claude-code`. Or copy the skill folder (security/static-application-security-testing in seb1n/awesome-ai-agent-skills) into .claude/skills/static-application-security-testing in your project. Claude Code loads it when a task matches its description.

How do I install Static Application Security Testing in Codex?

Run `npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a codex`. Or copy the skill folder (security/static-application-security-testing in seb1n/awesome-ai-agent-skills) into .agents/skills/static-application-security-testing in your project. Codex loads it when a task matches its description.

Can I use Static Application Security Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/static-application-security-testing, .gemini/skills/static-application-security-testing, .github/skills/static-application-security-testing and .opencode/skills/static-application-security-testing in your project.

What does Static Application Security Testing need to run?

Going by SKILL.md and its folder, Static Application Security Testing needs the command-line tools its instructions call (semgrep) and credentials named DB_PASSWORD and JWT_SECRET. Our summary lists: Python 3; A credential in JWT_SECRET.

Does Static Application Security Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Static Application Security Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Static Application Security Testing use?

Static Application Security Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Static Application Security Testing use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Static Application Security Testing?

Skills that share tags, products or a category with Static Application Security Testing: Kedro Security Review (kedro-org/kedro, 11k stars), Sarif Parsing (trailofbits/skills, 7.4k stars), Detection Breadth (deonmenezes/mantishack, 505 stars) and Sast Scanning (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Static Application Security Testing?

seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 92 skills in this directory. The repository was last updated on August 9, 2026.

Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.