Agent skill

LLM Sast Scanner

by SunWeb3Sec in SunWeb3Sec/llm-sast-scanner

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

No licenceAuto-check passedSecurity

Install LLM Sast Scanner

skills CLI
$ npx skills add SunWeb3Sec/llm-sast-scanner --skill llm-sast-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SunWeb3Sec/llm-sast-scanner llm-sast-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SunWeb3Sec/llm-sast-scanner.git skills-src && mkdir -p .claude/skills && cp -r skills-src/llm-sast-scanner .claude/skills/llm-sast-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
llm-sast-scanner
GitHub stars
286
Token cost
~6.2k tokens
SKILL.md length
2,552 words
Files
35 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

  • Works in 6 steps: Understand Scope → Load Relevant References → Analyze Code — Bidirectional Taint… → …
  • The user asks to: analyze code for vulnerabilities
  • SKILL.md covers Purpose, Scope, Workflow and Key Principles
  • Calls bash

What it does

LLM Sast Scanner is an agent skill from SunWeb3Sec/llm-sast-scanner. General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. Trigger when the user asks to: "analyze code for vulnerabilities", "review code security", "find security bugs", "do a SAST scan", "check for [vulnerability type] in code", "audit source code", or requests a security code review of any language or framework. Covers 34 vulnerability classes across web, API, auth, mobile, and logic layers.

Its SKILL.md is about 6.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 35 other files, including reference files (for example `references/arbitrary_file_upload.md`, `references/authentication_jwt.md` and `references/brute_force.md`).

It sits in Security, covering Static analysis and SAST and Code review. The repository describes itself as: A SAST skill that gives AI coding agents structured vulnerability detection across 34 vulnerability classes.

When your agent uses it

  • The user asks to: analyze code for vulnerabilities
  • Review code security
  • Find security bugs
  • Check for [vulnerability type] in code

Example prompts

  • “analyze code for vulnerabilities”
  • “review code security”
  • “find security bugs”
  • “/llm-sast-scanner”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Understand Scope
  2. Load Relevant References
  3. Analyze Code — Bidirectional Taint Tracking
  4. Business Logic & Auth Analysis
  5. Judge — Validity Re-Verification
  6. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit fedaf6a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

LLM Sast Scanner loads about 6.2k tokens when it runs, and up to ~95k if it reads all its reference files. Until then it costs about 114 tokens; SKILL.md has 2,552 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~6.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~95k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 2,552 words (~6,220 tokens).

“Systematically analyze source code for security vulnerabilities using structured Source→Sink taint tracking, pattern matching, and vulnerability-class-specific detection heuristics. Produce actionable findings with severity ratings, affected code locations (file + line number), and remediation guidance.”

— opening of SKILL.md by SunWeb3Sec
name
llm-sast-scanner
metadata.version
1.4.0
metadata.domain
application-security
metadata.references
34 vulnerability knowledge bases

Read the full SKILL.md on GitHub

Files

SKILL.md and 34 other files (references) in llm-sast-scanner of SunWeb3Sec/llm-sast-scanner.

  • SKILL.md
  • references/arbitrary_file_upload.md
  • references/authentication_jwt.md
  • references/brute_force.md
  • references/business_logic.md
  • references/csrf.md
  • references/cve_patterns.md
  • references/default_credentials.md
  • references/denial_of_service.md
  • references/expression_language_injection.md
  • references/graphql_injection.md
  • references/http_method_tamper.md
  • references/idor.md
  • references/information_disclosure.md
  • references/insecure_cookie.md
  • references/insecure_deserialization.md
  • references/jndi_injection.md
  • references/mobile_security.md
  • references/nosql_injection.md
  • references/open_redirect.md
  • … and 15 more

Open the folder on GitHubat commit fedaf6a

Compare with similar skills

LLM Sast Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

LLM Sast Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
LLM Sast Scanner this skillSunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNone
Codexqa Code Analyzeropenqa-cn/codexqa152—~1.2kAutomated safety check: PassApache-2.0
Audit Integritygithub/awesome-copilot40k—~1kAutomated safety check: PassMIT
Trailmark Graph Evolutiontrailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0
Source Code Scanningtransilienceai/communitytools562—~1.2kAutomated safety check: NotesMIT
Secure Code ReviewHack23/cia239—~5.8kAutomated safety check: PassApache-2.0

Similar skills

  • Codexqa Code Analyzer

    openqa-cn/codexqa

    Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.

    152 GitHub stars~1.2k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Audit Integrity

    github/awesome-copilot

    Official

    Enforce output quality, evidence verification, and quality gates across security audits.

    40k GitHub stars~1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    562 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check: notes
  • Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

    239 GitHub stars~5.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Codexqa Code Wiki

    openqa-cn/codexqa

    Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.

    152 GitHub stars~1.3k tokensUpdated 6 days ago
    Knowledge ManagementAuto-check passed

Categories

Questions about LLM Sast Scanner

What does LLM Sast Scanner do?

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. LLM Sast Scanner is an agent skill from SunWeb3Sec/llm-sast-scanner. General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

When should I use LLM Sast Scanner?

LLM Sast Scanner fits situations like: the user asks to: analyze code for vulnerabilities; review code security; find security bugs; check for [vulnerability type] in code.

How do I install LLM Sast Scanner in Claude Code?

Run `npx skills add SunWeb3Sec/llm-sast-scanner --skill llm-sast-scanner -a claude-code`. Or copy the skill folder (llm-sast-scanner in SunWeb3Sec/llm-sast-scanner) into .claude/skills/llm-sast-scanner in your project. Claude Code loads it when a task matches its description.

How do I install LLM Sast Scanner in Codex?

Run `npx skills add SunWeb3Sec/llm-sast-scanner --skill llm-sast-scanner -a codex`. Or copy the skill folder (llm-sast-scanner in SunWeb3Sec/llm-sast-scanner) into .agents/skills/llm-sast-scanner in your project. Codex loads it when a task matches its description.

Can I use LLM Sast Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SunWeb3Sec/llm-sast-scanner --skill llm-sast-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/llm-sast-scanner, .gemini/skills/llm-sast-scanner, .github/skills/llm-sast-scanner and .opencode/skills/llm-sast-scanner in your project.

What does LLM Sast Scanner need to run?

Going by SKILL.md and its folder, LLM Sast Scanner needs the command-line tools its instructions call (bash).

Does LLM Sast Scanner access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is LLM Sast Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does LLM Sast Scanner use?

No licence was found for LLM Sast Scanner or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does LLM Sast Scanner use?

About 6.2k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 89k tokens, read only when the agent opens those files.

What are the alternatives to LLM Sast Scanner?

Skills that share tags, products or a category with LLM Sast Scanner: Codexqa Code Analyzer (openqa-cn/codexqa, 152 stars), Audit Integrity (github/awesome-copilot, 40k stars), Trailmark Graph Evolution (trailofbits/skills, 7.4k stars) and Source Code Scanning (transilienceai/communitytools, 562 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains LLM Sast Scanner?

SunWeb3Sec (a GitHub user) maintains it in SunWeb3Sec/llm-sast-scanner, which has 286 GitHub stars. The repository was last updated on August 22, 2026.

Source: SunWeb3Sec/llm-sast-scanner on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.