Kedro Security Review
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.
$ npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills static-application-security-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/static-application-security-testing .claude/skills/static-application-security-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "static-application-security-testing" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/static-application-security-testing into .claude/skills/static-application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "static-application-security-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/static-application-security-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills static-application-security-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/security/static-application-security-testing .agents/skills/static-application-security-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "static-application-security-testing" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/static-application-security-testing into .agents/skills/static-application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "static-application-security-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills static-application-security-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/security/static-application-security-testing .cursor/skills/static-application-security-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "static-application-security-testing" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/static-application-security-testing into .cursor/skills/static-application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "static-application-security-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/seb1n/awesome-ai-agent-skills.git --path security/static-application-security-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills static-application-security-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/security/static-application-security-testing .gemini/skills/static-application-security-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "static-application-security-testing" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/static-application-security-testing into .gemini/skills/static-application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "static-application-security-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install seb1n/awesome-ai-agent-skills static-application-security-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/security/static-application-security-testing .github/skills/static-application-security-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "static-application-security-testing" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/static-application-security-testing into .github/skills/static-application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "static-application-security-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install seb1n/awesome-ai-agent-skills static-application-security-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/seb1n/awesome-ai-agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/security/static-application-security-testing .opencode/skills/static-application-security-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "static-application-security-testing" agent skill from https://github.com/seb1n/awesome-ai-agent-skills/tree/main/security/static-application-security-testing into .opencode/skills/static-application-security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "static-application-security-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
static-application-security-testingAnalyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.
Static Application Security Testing is an agent skill from seb1n/awesome-ai-agent-skills. Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. Use when the user requests static application security testing or provides relevant inputs for this workflow.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Static analysis and SAST. It works with Semgrep and Python. The repository describes itself as: 103 ready-to-use AI agent skills for Claude Code, OpenAI Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, and other Agent Skills-compatible tools. Complete SKILL.md… The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 75865a5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
semgrepFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DB_PASSWORDJWT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Static Application Security Testing loads about 2.6k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 882 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from seb1n/awesome-ai-agent-skills at commit 75865a5, republished under its MIT licence (© seb1n). 882 words, ~2,620 tokens.
.claude/skills/static-application-security-testing/SKILL.md (or your agent's skills folder).This skill enables the agent to perform Static Application Security Testing (SAST) on source code repositories to detect security vulnerabilities without executing the application. The agent selects appropriate analysis tools based on the project's language, runs scans with relevant rule sets, triages findings to separate true positives from false positives, and integrates results into CI/CD pipelines. SAST catches issues such as SQL injection, cross-site scripting, hardcoded secrets, insecure deserialization, and cryptographic misuse early in the development lifecycle.
Detect Languages and Frameworks — Analyze the repository to determine primary languages (Python, JavaScript, Java, Go, C#, etc.) and frameworks in use. This determines which SAST tools and rule sets are applicable. Check for existing tool configurations like .semgrep.yml, codeql query packs, or .bandit config files.
Select and Configure SAST Tools — Choose the appropriate tools for the detected stack. Use Semgrep for multi-language pattern matching, CodeQL for deep semantic analysis, Bandit for Python-specific checks, and ESLint security plugins for JavaScript/TypeScript. Load built-in security rule sets and any project-specific custom rules.
Execute Static Analysis — Run the selected tools against the codebase. Capture all findings including the vulnerability type, affected file and line number, severity level, CWE identifier, and a description of the issue. For large codebases, parallelize scans across multiple tools simultaneously.
Triage and Deduplicate Findings — Merge results from multiple tools, remove duplicate detections of the same issue, and classify findings as true positive, false positive, or needs-review. Use contextual analysis such as checking whether a flagged SQL string actually reaches a database driver to reduce noise.
Generate Report with Fix Suggestions — Produce a structured findings report grouped by severity and category. Include the vulnerable code snippet, an explanation of the risk, a suggested fix with corrected code, and references to relevant CWE entries and OWASP categories.
Integrate into CI Pipeline — Configure the scan to run on every pull request or push to protected branches. Set quality gates that block merges when critical or high-severity findings are introduced. Output results in SARIF format for integration with GitHub Code Scanning, GitLab SAST, or SonarQube.
Provide the agent with the path to a source code repository. Optionally specify target languages, custom rule files, or a CI platform for pipeline integration. The agent will run the appropriate SAST tools and deliver a prioritized findings report.
Prompt example:
Run SAST on the Python application in /app using Semgrep and Bandit. Flag any SQL injection, hardcoded secrets, and insecure deserialization. Output results in SARIF format for GitHub Code Scanning.Command:
semgrep scan --config=p/owasp-top-ten --config=p/python --json --output=semgrep-results.json /appFindings (excerpt):
┌─────────────────────────────────────────────────────────────────┐
│ python.flask.security.injection.sql-injection-with-format-string │
│ Severity: ERROR │ CWE-89 │ OWASP A03:2021 │
├─────────────────────────────────────────────────────────────────┤
│ /app/routes/users.py:42 │
│ │
│ 40│ def search_users(name): │
│ 41│ query = f"SELECT * FROM users WHERE name = '{name}'"│
│ 42│ result = db.execute(query) │
│ │
│ Fix: Use parameterized queries instead of string formatting. │
├─────────────────────────────────────────────────────────────────┤
│ python.lang.security.audit.hardcoded-password │
│ Severity: WARNING │ CWE-798 │ OWASP A07:2021 │
├─────────────────────────────────────────────────────────────────┤
│ /app/config.py:11 │
│ │
│ 10│ class Config: │
│ 11│ DB_PASSWORD = "SuperSecret123!" │
│ 12│ JWT_SECRET = "my-jwt-secret" │
│ │
│ Fix: Load secrets from environment variables or a secrets │
│ manager, never hardcode them in source files. │
└─────────────────────────────────────────────────────────────────┘Fixed code for the SQL injection finding:
# BEFORE — vulnerable to SQL injection
def search_users(name):
query = f"SELECT * FROM users WHERE name = '{name}'"
result = db.execute(query)
return result
# AFTER — parameterized query
def search_users(name):
query = "SELECT * FROM users WHERE name = :name"
result = db.execute(text(query), {"name": name})
return resultCustom CodeQL query (insecure-deserialization.ql):
/**
* @name Insecure deserialization of untrusted data
* @description Deserializing data from an untrusted source without validation
* can lead to remote code execution.
* @kind path-problem
* @problem.severity error
* @id java/insecure-deserialization
* @tags security
* cwe-502
* owasp-a08
*/
import java
import semmle.code.java.dataflow.TaintTracking
import semmle.code.java.security.UnsafeDeserializationQuery
from UnsafeDeserializationConfig config, DataFlow::PathNode source, DataFlow::PathNode sink
where config.hasFlowPath(source, sink)
select sink.getNode(), source, sink,
"Untrusted data from $@ is deserialized here without validation.", source.getNode(),
"user-controlled input"Running the query:
codeql database create java-db --language=java --source-root=/app
codeql database analyze java-db insecure-deserialization.ql --format=sarif-latest --output=codeql-results.sarifSample finding:
/app/src/main/java/com/example/api/ImportController.java:35
ObjectInputStream ois = new ObjectInputStream(request.getInputStream());
Object obj = ois.readObject(); // CWE-502: untrusted deserialization
Fix: Replace ObjectInputStream with a safe alternative like JSON deserialization
with explicit type binding, or use an allowlist-based ObjectInputFilter.p/owasp-top-ten) rather than enabling all rules. Add suppressions for confirmed false positives with documented justification..semgrepignore or CodeQL path filters to avoid noise.© seb1n, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in security/static-application-security-testing of seb1n/awesome-ai-agent-skills.
Open the folder on GitHubat commit 75865a5
Static Application Security Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Static Application Security Testing this skillseb1n/awesome-ai-agent-skills | 206 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Sarif Parsingtrailofbits/skills | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Detection Breadthdeonmenezes/mantishack | 505 | — | ~510 | Automated safety check: Pass | Apache-2.0 | |
| Sast Scanningsickn33/agentic-awesome-skills | 47k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Sast ScanningBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~2.2k | Automated safety check: Pass | MIT |
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
trailofbits/skills
Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.
deonmenezes/mantishack
When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain
sickn33/agentic-awesome-skills
Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.
BagelHole/DevOps-Security-Agent-Skills
Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.
LeoYeAI/openclaw-master-skills
Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.
seb1n/awesome-ai-agent-skills
Plan, execute, document, and retest authorized security assessments of AI agents and multi-agent workflows using safe adversarial cases, synthetic identities, canaries, and evidence-based findings.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
seb1n/awesome-ai-agent-skills
Design and verify auditable human oversight, approval gates, escalation paths, and safe state transitions for AI agent workflows.
seb1n/awesome-ai-agent-skills
Design, implement, harden, and verify Model Context Protocol (MCP) servers with precise tool contracts, least-privilege authorization, safe transports, structured errors, and interoperability tests.
seb1n/awesome-ai-agent-skills
Inspect, extract, OCR, create, merge, split, reorder, rotate, annotate, fill, redact, compress, secure, and verify PDF documents while preserving source files and visual fidelity.
seb1n/awesome-ai-agent-skills
Audit agent skills, plugins, prompts, manifests, scripts, dependencies, and bundled assets for provenance, prompt-injection, permission, execution, exfiltration, persistence, and update risk.
Categories
Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. Static Application Security Testing is an agent skill from seb1n/awesome-ai-agent-skills. Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.
Static Application Security Testing fits situations like: the user requests static application security testing; provides relevant inputs for this workflow.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a claude-code`. Or copy the skill folder (security/static-application-security-testing in seb1n/awesome-ai-agent-skills) into .claude/skills/static-application-security-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a codex`. Or copy the skill folder (security/static-application-security-testing in seb1n/awesome-ai-agent-skills) into .agents/skills/static-application-security-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add seb1n/awesome-ai-agent-skills --skill static-application-security-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/static-application-security-testing, .gemini/skills/static-application-security-testing, .github/skills/static-application-security-testing and .opencode/skills/static-application-security-testing in your project.
Going by SKILL.md and its folder, Static Application Security Testing needs the command-line tools its instructions call (semgrep) and credentials named DB_PASSWORD and JWT_SECRET. Our summary lists: Python 3; A credential in JWT_SECRET.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Static Application Security Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Static Application Security Testing: Kedro Security Review (kedro-org/kedro, 11k stars), Sarif Parsing (trailofbits/skills, 7.4k stars), Detection Breadth (deonmenezes/mantishack, 505 stars) and Sast Scanning (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
seb1n (a GitHub user) maintains it in seb1n/awesome-ai-agent-skills, which has 206 GitHub stars. The repository holds 92 skills in this directory. The repository was last updated on August 9, 2026.
Source: seb1n/awesome-ai-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.