Agent skill

Security Scanning Security Sast

by aiskillstore in aiskillstore/marketplace

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

No licenceAuto-check passedSecurity

Install Security Scanning Security Sast

skills CLI
$ npx skills add aiskillstore/marketplace --skill security-scanning-security-sast -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace security-scanning-security-sast --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sickn33/security-scanning-security-sast .claude/skills/security-scanning-security-sast && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scanning-security-sast
GitHub stars
430
Used in
7 other repos
Token cost
~3.7k tokens
SKILL.md length
500 words
Files
2
Skills in repo
1,044
Repo updated
First seen
Licence
None found

At a glance

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

  • Works in 4 steps: Identify the languages, frameworks, and… → Select SAST tools and configure rules… → Run scans in CI or locally with… → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Capabilities, Use this skill when, Do not use this skill when and Instructions, plus 9 more sections
  • Calls semgrep, pip and npm; needs SECRET_KEY and API_KEY

What it does

Security Scanning Security Sast is an agent skill from aiskillstore/marketplace. Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill-report.json`).

It sits in Security, covering Static analysis and SAST and Web application vulnerabilities. It works with Semgrep. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/security-scanning-security-sast”

Requirements

  • Python 3
  • Node.js
  • A credential in API_KEY
  • A credential in SECRET_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the languages, frameworks, and scope to scan.
  2. Select SAST tools and configure rules for the codebase.
  3. Run scans in CI or locally with reproducible settings.
  4. Triage findings, prioritize by severity, and propose fixes.

What it can do on your machine

Read from SKILL.md and the folder at commit 755bc35. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep
    • pip
    • npm
    • eslint
    • mvn
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY
    • API_KEY
    • AWS_ACCESS_KEY_ID
    • DB_PASSWORD
    • DJANGO_SECRET_KEY
    • FLASK_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Scanning Security Sast loads about 3.7k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 500 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 500 words (~3,679 tokens).

“Static Application Security Testing (SAST) for comprehensive code vulnerability detection across multiple languages, frameworks, and security patterns.”

— opening of SKILL.md by aiskillstore
name
security-scanning-security-sast
risk
critical
source
community
date_added
2026-02-27

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in skills/sickn33/security-scanning-security-sast of aiskillstore/marketplace.

  • SKILL.md
  • skill-report.json

Open the folder on GitHubat commit 755bc35

Used in 7 other repositories

We found 16 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in aiskillstore/marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Scanning Security Sast next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Scanning Security Sast compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Scanning Security Sast this skillaiskillstore/marketplace4307 repos~3.7kAutomated safety check: PassNone
Semgrep Rule Creatorskrun-dev/skrun210—~1.3kAutomated safety check: PassMIT
Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Sast Patternsvibeeval/vibecosystem531—~4.6kAutomated safety check: PassMIT
Security Testingpetrkindlmann/qa-skills168—~4.9kAutomated safety check: PassMIT
Security Scanericrisco/rsc-harness174—~2.8kAutomated safety check: NotesMIT

Similar skills

  • Semgrep Rule Creator

    skrun-dev/skrun

    Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

    210 GitHub stars~1.3k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Implementing Devsecops Security Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Patterns

    vibeeval/vibecosystem

    Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

    531 GitHub stars~4.6k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Testing

    petrkindlmann/qa-skills

    Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

    168 GitHub stars~4.9k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    174 GitHub stars~2.8k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from aiskillstore/marketplace

All 1,044 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 1 repo~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Project Planner

    aiskillstore/marketplace

    Detects stale project plans and suggests session commands. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~504 tokens
    Auto-check passed

Works with

Categories

Questions about Security Scanning Security Sast

What does Security Scanning Security Sast do?

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks. Security Scanning Security Sast is an agent skill from aiskillstore/marketplace.

When should I use Security Scanning Security Sast?

Security Scanning Security Sast fits situations like: tasks that involve Static analysis and SAST; tasks that involve Web application vulnerabilities.

How do I install Security Scanning Security Sast in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill security-scanning-security-sast -a claude-code`. Or copy the skill folder (skills/sickn33/security-scanning-security-sast in aiskillstore/marketplace) into .claude/skills/security-scanning-security-sast in your project. Claude Code loads it when a task matches its description.

How do I install Security Scanning Security Sast in Codex?

Run `npx skills add aiskillstore/marketplace --skill security-scanning-security-sast -a codex`. Or copy the skill folder (skills/sickn33/security-scanning-security-sast in aiskillstore/marketplace) into .agents/skills/security-scanning-security-sast in your project. Codex loads it when a task matches its description.

Can I use Security Scanning Security Sast in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill security-scanning-security-sast -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scanning-security-sast, .gemini/skills/security-scanning-security-sast, .github/skills/security-scanning-security-sast and .opencode/skills/security-scanning-security-sast in your project.

What does Security Scanning Security Sast need to run?

Going by SKILL.md and its folder, Security Scanning Security Sast needs the command-line tools its instructions call (semgrep, pip, npm, eslint, mvn and cargo) and credentials named SECRET_KEY, API_KEY, AWS_ACCESS_KEY_ID and DB_PASSWORD. Our summary lists: Python 3; Node.js; A credential in API_KEY; A credential in SECRET_KEY.

Does Security Scanning Security Sast access the network?

SKILL.md contains no URLs. Its commands use pip and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Security Scanning Security Sast safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Scanning Security Sast use?

No licence was found for Security Scanning Security Sast or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Scanning Security Sast use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Scanning Security Sast?

Skills that share tags, products or a category with Security Scanning Security Sast: Semgrep Rule Creator (skrun-dev/skrun, 210 stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Sast Patterns (vibeeval/vibecosystem, 531 stars) and Security Testing (petrkindlmann/qa-skills, 168 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Scanning Security Sast?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,044 skills in this directory. The repository was last updated on October 9, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.