Agent skill

Sast Scanning

by sickn33 in sickn33/agentic-awesome-skills

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

MITAuto-check passedSecurity

Install Sast Scanning

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill sast-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills sast-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sast-scanning .claude/skills/sast-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sast-scanning
GitHub stars
47k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
272 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

  • Tasks that involve Static analysis and SAST
  • SKILL.md covers When to Use This Skill, Prerequisites, Tool Comparison and Semgrep, plus 8 more sections
  • Calls semgrep, pip and jq; needs SONAR_TOKEN and SEMGREP_APP_TOKEN

What it does

Sast Scanning is an agent skill from sickn33/agentic-awesome-skills. Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not…

It sits in Security, covering Static analysis and SAST. It works with Semgrep and Python. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “/sast-scanning”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in SEMGREP_APP_TOKEN
  • A credential in SONAR_TOKEN
  • Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep
    • pip
    • jq
    • brew
    • npm
    • gem

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SONAR_TOKEN
    • SEMGREP_APP_TOKEN
    • SONAR_JDBC_PASSWORD
    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Sast Scanning loads about 2.4k tokens when it runs. Until then it costs about 26 tokens; SKILL.md has 272 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~26
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 272 words, ~2,415 tokens.

Download SKILL.mdSave it as .claude/skills/sast-scanning/SKILL.md (or your agent's skills folder).
name
sast-scanning
description
Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.
compatibility
Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.
category
security
risk
safe
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

SAST Scanning

Identify security vulnerabilities in source code through static analysis.

When to Use This Skill

Use this skill when:

  • Implementing secure SDLC practices
  • Adding security gates to CI/CD
  • Automating code security reviews
  • Finding vulnerabilities before deployment
  • Meeting compliance requirements

Prerequisites

  • Source code access
  • CI/CD pipeline
  • SAST tool installation

Tool Comparison

ToolLicenseLanguagesBest For
SemgrepOSS/Commercial30+Custom rules, speed
CodeQLFree (GitHub)10+Deep analysis
SonarQubeOSS/Commercial25+Quality + Security
BanditOSSPythonPython projects
BrakemanOSSRubyRails apps

Semgrep

Installation
bash
# Install via pip
pip install semgrep

# Or via Homebrew
brew install semgrep
Basic Usage
bash
# Run with default rules
semgrep --config auto .

# Run specific rulesets
semgrep --config p/security-audit .
semgrep --config p/owasp-top-ten .
semgrep --config p/ci .

# Scan specific languages
semgrep --config p/python .
semgrep --config p/javascript .

# Output formats
semgrep --config auto --json -o results.json .
semgrep --config auto --sarif -o results.sarif .
Custom Rules
yaml
# .semgrep/custom-rules.yaml
rules:
  - id: hardcoded-password
    patterns:
      - pattern-either:
          - pattern: password = "..."
          - pattern: PASSWORD = "..."
          - pattern: passwd = "..."
    message: Hardcoded password detected
    severity: ERROR
    languages: [python, javascript, java]
    metadata:
      cwe: "CWE-798"
      owasp: "A3:2017"

  - id: sql-injection
    patterns:
      - pattern: |
          $QUERY = "..." + $USER_INPUT + "..."
          $DB.execute($QUERY)
    message: Potential SQL injection
    severity: ERROR
    languages: [python]
    metadata:
      cwe: "CWE-89"

  - id: insecure-random
    pattern: random.random()
    message: Use secrets module for security-sensitive randomness
    severity: WARNING
    languages: [python]
    fix: secrets.token_hex()
CI Configuration
yaml
# .github/workflows/semgrep.yml
name: Semgrep

on:
  push:
    branches: [main]
  pull_request:

jobs:
  semgrep:
    runs-on: ubuntu-latest
    container:
      image: returntocorp/semgrep
    steps:
      - uses: actions/checkout@v4

      - name: Run Semgrep
        run: semgrep ci
        env:
          SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}

CodeQL

Setup
yaml
# .github/workflows/codeql.yml
name: CodeQL Analysis

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]
  schedule:
    - cron: '0 0 * * 0'

jobs:
  analyze:
    runs-on: ubuntu-latest
    permissions:
      security-events: write
      actions: read
      contents: read

    strategy:
      matrix:
        language: ['javascript', 'python']

    steps:
      - uses: actions/checkout@v4

      - name: Initialize CodeQL
        uses: github/codeql-action/init@v3
        with:
          languages: ${{ matrix.language }}
          queries: +security-and-quality

      - name: Autobuild
        uses: github/codeql-action/autobuild@v3

      - name: Perform CodeQL Analysis
        uses: github/codeql-action/analyze@v3
        with:
          category: "/language:${{ matrix.language }}"
Custom Queries
ql
// queries/sql-injection.ql
/**
 * @name SQL Injection
 * @description User input in SQL query
 * @kind path-problem
 * @problem.severity error
 * @security-severity 9.0
 * @precision high
 * @id py/sql-injection
 * @tags security
 */

import python
import semmle.python.dataflow.new.DataFlow
import semmle.python.dataflow.new.TaintTracking
import semmle.python.security.dataflow.SqlInjectionQuery

from SqlInjectionConfiguration config, DataFlow::PathNode source, DataFlow::PathNode sink
where config.hasFlowPath(source, sink)
select sink.getNode(), source, sink, "SQL injection from $@.", source.getNode(), "user input"

SonarQube

Docker Setup
yaml
# docker-compose.yml
version: '3.8'

services:
  sonarqube:
    image: sonarqube:lts-community
    ports:
      - "9000:9000"
    environment:
      - SONAR_JDBC_URL=jdbc:postgresql://db:5432/sonar
      - SONAR_JDBC_USERNAME=sonar
      - SONAR_JDBC_PASSWORD=sonar
    volumes:
      - sonarqube_data:/opt/sonarqube/data
      - sonarqube_logs:/opt/sonarqube/logs
    depends_on:
      - db

  db:
    image: postgres:15
    environment:
      - POSTGRES_USER=sonar
      - POSTGRES_PASSWORD=sonar
      - POSTGRES_DB=sonar
    volumes:
      - postgresql_data:/var/lib/postgresql/data

volumes:
  sonarqube_data:
  sonarqube_logs:
  postgresql_data:
Scanner Configuration
properties
# sonar-project.properties
sonar.projectKey=myproject
sonar.projectName=My Project
sonar.projectVersion=1.0

sonar.sources=src
sonar.tests=tests
sonar.exclusions=**/node_modules/**,**/vendor/**

sonar.language=py
sonar.python.coverage.reportPaths=coverage.xml

sonar.qualitygate.wait=true
CI Integration
yaml
# GitHub Actions
- name: SonarQube Scan
  uses: sonarsource/sonarqube-scan-action@master
  env:
    SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
    SONAR_HOST_URL: ${{ secrets.SONAR_HOST_URL }}

- name: Quality Gate
  uses: sonarsource/sonarqube-quality-gate-action@master
  timeout-minutes: 5
  env:
    SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}

Language-Specific Tools

Python (Bandit)
bash
# Install
pip install bandit

# Run scan
bandit -r src/ -f json -o bandit-report.json

# With configuration
bandit -r src/ -c bandit.yaml
yaml
# bandit.yaml
skips: ['B101', 'B601']
exclude_dirs: ['tests', 'venv']

assert_used:
  skips: ['*_test.py', '*_tests.py']
JavaScript (ESLint Security)
bash
# Install
npm install eslint eslint-plugin-security --save-dev
javascript
// .eslintrc.js
module.exports = {
  plugins: ['security'],
  extends: ['plugin:security/recommended'],
  rules: {
    'security/detect-object-injection': 'error',
    'security/detect-non-literal-regexp': 'warn',
    'security/detect-unsafe-regex': 'error',
    'security/detect-buffer-noassert': 'error',
    'security/detect-eval-with-expression': 'error',
    'security/detect-no-csrf-before-method-override': 'error',
    'security/detect-possible-timing-attacks': 'warn'
  }
};
Ruby (Brakeman)
bash
# Install
gem install brakeman

# Run scan
brakeman -o brakeman-report.json -f json

# CI configuration
brakeman --no-exit-on-warn --no-exit-on-error -o report.html

Quality Gates

SonarQube Quality Gate
json
{
  "name": "Security Gate",
  "conditions": [
    {
      "metric": "new_security_rating",
      "op": "GT",
      "error": "1"
    },
    {
      "metric": "new_vulnerabilities",
      "op": "GT",
      "error": "0"
    },
    {
      "metric": "new_security_hotspots_reviewed",
      "op": "LT",
      "error": "100"
    }
  ]
}
Custom Gate Script
bash
#!/bin/bash
# security-gate.sh

CRITICAL=$(cat results.json | jq '[.results[] | select(.severity == "critical")] | length')
HIGH=$(cat results.json | jq '[.results[] | select(.severity == "high")] | length')

echo "Critical: $CRITICAL, High: $HIGH"

if [ "$CRITICAL" -gt 0 ]; then
  echo "FAILED: Critical vulnerabilities found"
  exit 1
fi

if [ "$HIGH" -gt 5 ]; then
  echo "FAILED: Too many high severity vulnerabilities"
  exit 1
fi

echo "PASSED: Security gate"
exit 0

Common Issues

Issue: Too Many False Positives

Problem: Alerts on safe code patterns Solution: Tune rules, add suppressions, use baseline

Issue: Slow Scans

Problem: SAST taking too long in CI Solution: Incremental scanning, parallel execution, exclude test files

Issue: Missing Coverage

Problem: Vulnerabilities not detected Solution: Add custom rules, combine multiple tools

Best Practices

  • Run on every PR/commit
  • Establish baseline for existing code
  • Prioritize by severity and exploitability
  • Maintain custom rules for your codebase
  • Integrate with IDE for early feedback
  • Track trends over time
  • Document false positive suppressions
  • Combine with DAST for comprehensive coverage
  • dast-scanning (dast-scanning) - Dynamic testing
  • dependency-scanning (dependency-scanning) - Dependency vulnerabilities
  • github-actions (github-actions) - CI integration

Limitations

  • Apply guidance only within authorized scope; test destructive steps in non-production first.
  • Docs-only import: upstream scripts and templates not bundled.
Example
bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sast-scanning of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sast Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sast Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sast Scanning this skillsickn33/agentic-awesome-skills47k1 repos~2.4kAutomated safety check: PassMIT
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Sarif Parsingtrailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0
Detection Breadthdeonmenezes/mantishack504—~510Automated safety check: PassApache-2.0
Sast ScanningBagelHole/DevOps-Security-Agent-Skills1.1k—~2.2kAutomated safety check: PassMIT
Clawsec ScannerLeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT

Similar skills

  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Sarif Parsing

    trailofbits/skills

    Official

    Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

    7.4k GitHub starsUsed in 3 repos~4.4k tokens
    SecurityAuto-check: notes
  • Detection Breadth

    deonmenezes/mantishack

    When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

    504 GitHub stars~510 tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Sast Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

    1.1k GitHub stars~2.2k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Clawsec Scanner

    LeoYeAI/openclaw-master-skills

    Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

    2.2k GitHub stars~4.1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Static Application Security Testing

    seb1n/awesome-ai-agent-skills

    Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

    206 GitHub stars~2.6k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Categories

Questions about Sast Scanning

What does Sast Scanning do?

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. Sast Scanning is an agent skill from sickn33/agentic-awesome-skills. Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

When should I use Sast Scanning?

Sast Scanning fits situations like: tasks that involve Static analysis and SAST.

How do I install Sast Scanning in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill sast-scanning -a claude-code`. Or copy the skill folder (skills/sast-scanning in sickn33/agentic-awesome-skills) into .claude/skills/sast-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Sast Scanning in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill sast-scanning -a codex`. Or copy the skill folder (skills/sast-scanning in sickn33/agentic-awesome-skills) into .agents/skills/sast-scanning in your project. Codex loads it when a task matches its description.

Can I use Sast Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill sast-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sast-scanning, .gemini/skills/sast-scanning, .github/skills/sast-scanning and .opencode/skills/sast-scanning in your project.

What does Sast Scanning need to run?

Going by SKILL.md and its folder, Sast Scanning needs the command-line tools its instructions call (semgrep, pip, jq, brew, npm and gem) and credentials named SONAR_TOKEN, SEMGREP_APP_TOKEN, SONAR_JDBC_PASSWORD and POSTGRES_PASSWORD. Our summary lists: Python 3; Node.js; Docker; A credential in SEMGREP_APP_TOKEN; A credential in SONAR_TOKEN. Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled..

Does Sast Scanning access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Sast Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sast Scanning use?

Sast Scanning is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sast Scanning use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sast Scanning?

Skills that share tags, products or a category with Sast Scanning: Kedro Security Review (kedro-org/kedro, 11k stars), Sarif Parsing (trailofbits/skills, 7.4k stars), Detection Breadth (deonmenezes/mantishack, 504 stars) and Sast Scanning (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sast Scanning?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.