Semgrep Rule Creator
skrun-dev/skrun
Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.
Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.
$ npx skills add vibeeval/vibecosystem --skill sast-patterns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vibeeval/vibecosystem sast-patterns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sast-patterns .claude/skills/sast-patterns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sast-patterns" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/sast-patterns into .claude/skills/sast-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-patterns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vibeeval/vibecosystem/tree/main/skills/sast-patternsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vibeeval/vibecosystem --skill sast-patterns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vibeeval/vibecosystem sast-patterns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/sast-patterns .agents/skills/sast-patterns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sast-patterns" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/sast-patterns into .agents/skills/sast-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-patterns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vibeeval/vibecosystem --skill sast-patterns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vibeeval/vibecosystem sast-patterns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/sast-patterns .cursor/skills/sast-patterns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sast-patterns" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/sast-patterns into .cursor/skills/sast-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-patterns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vibeeval/vibecosystem.git --path skills/sast-patterns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vibeeval/vibecosystem --skill sast-patterns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vibeeval/vibecosystem sast-patterns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/sast-patterns .gemini/skills/sast-patterns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sast-patterns" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/sast-patterns into .gemini/skills/sast-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-patterns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vibeeval/vibecosystem sast-patternsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vibeeval/vibecosystem --skill sast-patterns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/sast-patterns .github/skills/sast-patterns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sast-patterns" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/sast-patterns into .github/skills/sast-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-patterns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vibeeval/vibecosystem --skill sast-patterns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vibeeval/vibecosystem sast-patterns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/sast-patterns .opencode/skills/sast-patterns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sast-patterns" agent skill from https://github.com/vibeeval/vibecosystem/tree/main/skills/sast-patterns into .opencode/skills/sast-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-patterns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sast-patternsStatic Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.
Sast Patterns is an agent skill from vibeeval/vibecosystem. Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. Use when scanning code for security vulnerabilities or writing custom SAST rules.
Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Static analysis and SAST and Web application vulnerabilities. It works with Semgrep. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.
Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
semgrepnpmpipgomvngradlebundleFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
semgrep.devowasp.orgcwe.mitre.orgnvd.nist.govsecurity.snyk.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYSEMGREP_APP_TOKENDJANGO_SECRET_KEYSESSION_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sast Patterns loads about 4.6k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 492 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 492 words, ~4,634 tokens.
.claude/skills/sast-patterns/SKILL.md (or your agent's skills folder).Comprehensive vulnerability pattern library for static application security testing. Covers OWASP Top 10, language-specific patterns, Semgrep custom rules, and CI/CD pipeline integration.
What to Look For:
Detection Patterns:
// VULNERABLE: No authorization check
app.get('/api/users/:id', async (req, res) => {
const user = await db.users.findById(req.params.id)
res.json(user) // Anyone can access any user
})
// SECURE: Authorization verified
app.get('/api/users/:id', authenticate, async (req, res) => {
if (req.user.id !== req.params.id && !req.user.isAdmin) {
return res.status(403).json({ error: 'Forbidden' })
}
const user = await db.users.findById(req.params.id)
res.json(user)
})# VULNERABLE: No permission check
@app.route('/admin/delete/<user_id>', methods=['DELETE'])
def delete_user(user_id):
db.session.delete(User.query.get(user_id))
db.session.commit()
# SECURE: Permission verified
@app.route('/admin/delete/<user_id>', methods=['DELETE'])
@login_required
@admin_required
def delete_user(user_id):
db.session.delete(User.query.get(user_id))
db.session.commit()Semgrep Rules:
rules:
- id: missing-auth-check
patterns:
- pattern: |
app.$METHOD($PATH, async (req, res) => {
...
$DB.$QUERY(...)
...
})
- pattern-not: |
app.$METHOD($PATH, authenticate, ...)
message: "Endpoint missing authentication middleware"
severity: ERRORWhat to Look For:
Detection Patterns:
// VULNERABLE: Weak password hashing
const hash = crypto.createHash('md5').update(password).digest('hex')
// SECURE: Strong password hashing
const hash = await bcrypt.hash(password, 12)# VULNERABLE: Hardcoded secret
SECRET_KEY = "my-super-secret-key-123"
# SECURE: Environment variable
SECRET_KEY = os.environ.get('SECRET_KEY')
if not SECRET_KEY:
raise ValueError("SECRET_KEY environment variable required")Regex Patterns for Detection:
# API Keys
(?:api[_-]?key|apikey)\s*[:=]\s*['"][A-Za-z0-9_\-]{20,}['"]
# AWS Keys
(?:AKIA|ASIA)[A-Z0-9]{16}
# Generic Secrets
(?:password|passwd|pwd|secret|token)\s*[:=]\s*['"][^'"]{8,}['"]
# Private Keys
-----BEGIN (?:RSA |EC |DSA )?PRIVATE KEY-----
# JWT Tokens
eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+What to Look For:
Detection Patterns:
// SQL Injection
const query = `SELECT * FROM users WHERE id = ${userId}` // VULNERABLE
const query = 'SELECT * FROM users WHERE id = $1' // SECURE
// Command Injection
exec(`ping ${hostname}`) // VULNERABLE
execFile('ping', [hostname]) // SECURE
// NoSQL Injection (MongoDB)
db.users.find({ email: req.body.email }) // VULNERABLE if email = {"$gt": ""}
db.users.find({ email: String(req.body.email) }) // SECURE: type coercion# SQL Injection
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}") # VULNERABLE
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,)) # SECURE
# Command Injection
os.system(f"convert {filename} output.png") # VULNERABLE
subprocess.run(['convert', filename, 'output.png'], check=True) # SECURE// SQL Injection
db.Query("SELECT * FROM users WHERE id = " + userID) // VULNERABLE
db.Query("SELECT * FROM users WHERE id = $1", userID) // SECURE
// Command Injection
exec.Command("sh", "-c", userInput) // VULNERABLE
exec.Command("ping", "-c", "1", hostname) // SECURE// SQL Injection
stmt.executeQuery("SELECT * FROM users WHERE id = " + id); // VULNERABLE
PreparedStatement ps = conn.prepareStatement("SELECT * FROM users WHERE id = ?");
ps.setString(1, id); // SECUREWhat to Look For:
Detection Patterns:
// VULNERABLE: No rate limiting on login
app.post('/login', async (req, res) => {
const user = await authenticate(req.body)
res.json({ token: generateToken(user) })
})
// SECURE: Rate limited login
const loginLimiter = rateLimit({
windowMs: 15 * 60 * 1000,
max: 5,
message: 'Too many login attempts'
})
app.post('/login', loginLimiter, async (req, res) => {
const user = await authenticate(req.body)
res.json({ token: generateToken(user) })
})# VULNERABLE: Race condition in balance check
balance = get_balance(user_id)
if balance >= amount:
withdraw(user_id, amount) # Another request could drain first
# SECURE: Atomic transaction
with db.transaction():
balance = db.query("SELECT balance FROM accounts WHERE id = %s FOR UPDATE", user_id)
if balance >= amount:
db.execute("UPDATE accounts SET balance = balance - %s WHERE id = %s", amount, user_id)What to Look For:
Detection Patterns:
// VULNERABLE: Debug mode
app.set('env', 'development') // In production config
// VULNERABLE: Missing security headers
// No helmet or manual headers
// SECURE: Security headers
import helmet from 'helmet'
app.use(helmet())
app.use(helmet.contentSecurityPolicy({
directives: {
defaultSrc: ["'self'"],
scriptSrc: ["'self'"],
styleSrc: ["'self'", "'unsafe-inline'"],
imgSrc: ["'self'", 'data:', 'https:'],
}
}))# VULNERABLE: Debug in production
DEBUG = True # In production settings
# VULNERABLE: Default secret key
SECRET_KEY = 'django-insecure-change-me'
# SECURE
DEBUG = os.environ.get('DEBUG', 'False') == 'True'
SECRET_KEY = os.environ['DJANGO_SECRET_KEY']Security Headers Checklist:
Content-Security-Policy: default-src 'self'
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 0
Strict-Transport-Security: max-age=31536000; includeSubDomains
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()Detection Commands:
# Node.js
npm audit
npm audit --json
npm outdated
# Python
pip-audit
safety check
pip list --outdated
# Go
go list -m -u all
govulncheck ./...
# Java
mvn dependency-check:check
gradle dependencyCheckAnalyze
# Ruby
bundle audit checkWhat to Look For:
Detection Patterns:
// VULNERABLE: Plaintext password comparison
if (password === user.password) { /* login */ }
// SECURE: Hashed comparison
const isValid = await bcrypt.compare(password, user.passwordHash)
// VULNERABLE: Weak session management
app.use(session({ secret: 'secret' }))
// SECURE: Strong session
app.use(session({
secret: process.env.SESSION_SECRET,
resave: false,
saveUninitialized: false,
cookie: {
secure: true,
httpOnly: true,
sameSite: 'strict',
maxAge: 3600000
}
}))What to Look For:
Detection Patterns:
<!-- VULNERABLE: No SRI -->
<script src="https://cdn.example.com/lib.js"></script>
<!-- SECURE: With SRI -->
<script src="https://cdn.example.com/lib.js"
integrity="sha384-abc123..."
crossorigin="anonymous"></script># VULNERABLE: Insecure deserialization
import pickle
data = pickle.loads(user_input)
# SECURE: Use JSON
import json
data = json.loads(user_input)What to Look For:
Detection Patterns:
// VULNERABLE: No logging
app.post('/login', async (req, res) => {
const user = await authenticate(req.body)
if (!user) return res.status(401).json({ error: 'Invalid' })
res.json({ token: generateToken(user) })
})
// SECURE: Audit logging
app.post('/login', async (req, res) => {
const user = await authenticate(req.body)
if (!user) {
logger.warn('Failed login attempt', {
email: req.body.email,
ip: req.ip,
timestamp: new Date().toISOString()
})
return res.status(401).json({ error: 'Invalid credentials' })
}
logger.info('Successful login', { userId: user.id, ip: req.ip })
res.json({ token: generateToken(user) })
})
// VULNERABLE: Sensitive data in logs
console.log('Login:', { email, password, token })
// SECURE: Redacted logs
console.log('Login:', { email, passwordProvided: !!password })What to Look For:
Detection Patterns:
// VULNERABLE: SSRF
const response = await fetch(req.query.url)
// SECURE: URL whitelist
const ALLOWED_DOMAINS = ['api.example.com', 'cdn.example.com']
const url = new URL(req.query.url)
if (!ALLOWED_DOMAINS.includes(url.hostname)) {
throw new Error('Domain not allowed')
}
// Also block internal IPs
const ip = await dns.resolve(url.hostname)
if (isPrivateIP(ip)) {
throw new Error('Internal addresses not allowed')
}
const response = await fetch(url.toString())# VULNERABLE: SSRF
response = requests.get(user_url)
# SECURE: URL validation
from urllib.parse import urlparse
parsed = urlparse(user_url)
if parsed.hostname not in ALLOWED_HOSTS:
raise ValueError("Domain not allowed")
if is_private_ip(socket.gethostbyname(parsed.hostname)):
raise ValueError("Internal addresses blocked")
response = requests.get(user_url, allow_redirects=False)rules:
- id: rule-unique-id
pattern: |
eval($USER_INPUT)
message: "eval() with dynamic input detected - potential RCE"
languages: [javascript, typescript]
severity: ERROR
metadata:
cwe:
- CWE-94
owasp:
- A03:2021
category: security
confidence: HIGH# pattern: match exactly
- pattern: eval($X)
# pattern-not: exclude matches
- pattern-not: eval("static-string")
# patterns: AND (all must match)
- patterns:
- pattern: $DB.query($SQL)
- pattern-not: $DB.query($SQL, $PARAMS)
# pattern-either: OR (any can match)
- pattern-either:
- pattern: eval($X)
- pattern: new Function($X)
# pattern-inside: match within a context
- pattern-inside: |
app.$METHOD($PATH, (req, res) => {
...
})
# pattern-not-inside: exclude context
- pattern-not-inside: |
app.$METHOD($PATH, authenticate, ...)
# pattern-regex: regex in code
- pattern-regex: "password\s*=\s*['\"][^'\"]{3,}['\"]"rules:
- id: weak-hash-for-passwords
patterns:
- pattern: crypto.createHash($ALG).update($INPUT)
- metavariable-regex:
metavariable: $ALG
regex: "('md5'|'sha1')"
- metavariable-regex:
metavariable: $INPUT
regex: ".*password.*"
message: "Weak hash algorithm used for password: $ALG"
languages: [javascript, typescript]
severity: ERRORrules:
- id: sql-injection-taint
mode: taint
pattern-sources:
- pattern: req.body.$PARAM
- pattern: req.query.$PARAM
- pattern: req.params.$PARAM
pattern-sinks:
- pattern: $DB.query($SQL)
pattern-sanitizers:
- pattern: $DB.escape($X)
- pattern: sanitize($X)
message: "User input flows to SQL query without sanitization"
languages: [javascript]
severity: ERRORrules:
- id: no-hardcoded-secrets
pattern-regex: |
(?:api[_-]?key|secret|password|token)\s*[:=]\s*['"][A-Za-z0-9+/=_\-]{16,}['"]
paths:
exclude:
- "*.test.*"
- "*.spec.*"
- "__tests__/*"
- "*.example"
message: "Potential hardcoded secret detected"
languages: [generic]
severity: ERROR
- id: no-console-log-sensitive
patterns:
- pattern: console.log(..., $DATA, ...)
- metavariable-regex:
metavariable: $DATA
regex: ".*(?:password|secret|token|key|credential).*"
message: "Sensitive data in console.log"
languages: [javascript, typescript]
severity: WARNING
- id: require-input-validation
patterns:
- pattern: |
app.post($PATH, async (req, res) => {
...
$DB.$METHOD(req.body)
...
})
- pattern-not: |
app.post($PATH, async (req, res) => {
...
$SCHEMA.parse(...)
...
})
message: "POST endpoint without input validation"
languages: [javascript, typescript]
severity: WARNINGname: SAST Security Scan
on:
pull_request:
branches: [main, develop]
push:
branches: [main]
jobs:
sast:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Semgrep Scan
uses: semgrep/semgrep-action@v1
with:
config: >-
p/owasp-top-ten
p/secrets
p/typescript
generateSarif: "1"
env:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
- name: Upload SARIF
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: semgrep.sarif
if: always()
- name: Dependency Audit
run: npm audit --audit-level=high
- name: Check for Secrets
uses: trufflesecurity/trufflehog@main
with:
extra_args: --only-verified# .pre-commit-config.yaml
repos:
- repo: https://github.com/semgrep/semgrep
rev: 'v1.60.0'
hooks:
- id: semgrep
args: ['--config', 'auto', '--error', '--severity', 'ERROR']sast:
stage: test
image: semgrep/semgrep
script:
- semgrep --config auto --config "p/secrets" --json --output gl-sast-report.json .
artifacts:
reports:
sast: gl-sast-report.json
rules:
- if: $CI_MERGE_REQUEST_ID# Full scan with auto rules
semgrep --config auto .
# OWASP + Secrets
semgrep --config "p/owasp-top-ten" --config "p/secrets" .
# Only errors (for CI gates)
semgrep --config auto --error --severity ERROR .
# JSON output for processing
semgrep --config auto --json --output report.json .
# Scan specific files
semgrep --config auto src/api/ src/auth/
# Diff-aware (only changed code)
semgrep --config auto --baseline-commit origin/main
# Custom rules
semgrep --config .semgrep.yml .
# Exclude test files
semgrep --config auto --exclude="*test*" --exclude="*spec*" .
# With metrics disabled (privacy)
semgrep --config auto --metrics=off .| Severity | Criteria | Action | SLA |
|---|---|---|---|
| CRITICAL | Exploitable RCE, SQLi, auth bypass, data breach | Fix IMMEDIATELY, block deploy | < 1 hour |
| HIGH | XSS, SSRF, IDOR, missing auth, weak crypto | Fix before production | < 24 hours |
| MEDIUM | Missing validation, verbose errors, weak headers | Fix in current sprint | < 1 week |
| LOW | Debug mode, outdated lib (no known CVE), info leak | Fix in backlog | < 1 month |
Is user input involved?
YES -> Does it reach a dangerous sink (DB, exec, DOM)?
YES -> Is it sanitized/validated?
NO -> CRITICAL (injection)
YES -> Check sanitizer adequacy -> MEDIUM if weak
NO -> MEDIUM (missing validation)
NO -> Is it a configuration issue?
YES -> Affects security posture?
YES -> HIGH (misconfiguration)
NO -> LOW (best practice)
NO -> Is it a dependency issue?
YES -> Known CVE?
YES -> Match CVE severity
NO -> LOW (outdated)
NO -> InformationalRemember: SAST catches patterns, not intent. Always verify findings with manual review. A finding is only a vulnerability if it can be exploited in the application's specific context.
© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/sast-patterns of vibeeval/vibecosystem.
Open the folder on GitHubat commit 3b763b1
Sast Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sast Patterns this skillvibeeval/vibecosystem | 531 | — | ~4.6k | Automated safety check: Pass | MIT | |
| Semgrep Rule Creatorskrun-dev/skrun | 210 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Security Scanning Security Sastaiskillstore/marketplace | 430 | 7 repos | ~3.7k | Automated safety check: Pass | None | |
| Security Testingpetrkindlmann/qa-skills | 165 | — | ~4.9k | Automated safety check: Pass | MIT | |
| Security Scanericrisco/rsc-harness | 167 | — | ~2.8k | Automated safety check: Notes | MIT |
skrun-dev/skrun
Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.
mukul975/Anthropic-Cybersecurity-Skills
Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.
aiskillstore/marketplace
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
petrkindlmann/qa-skills
Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…
ericrisco/rsc-harness
A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
vibeeval/vibecosystem
Framework for measuring and tracking agent response quality over time.
vibeeval/vibecosystem
Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.
vibeeval/vibecosystem
A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.
vibeeval/vibecosystem
Systematic false positive verification for security findings.
vibeeval/vibecosystem
n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.
vibeeval/vibecosystem
A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.
Works with
Categories
Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. Sast Patterns is an agent skill from vibeeval/vibecosystem. Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.
Sast Patterns fits situations like: scanning code for security vulnerabilities; writing custom SAST rules.
Run `npx skills add vibeeval/vibecosystem --skill sast-patterns -a claude-code`. Or copy the skill folder (skills/sast-patterns in vibeeval/vibecosystem) into .claude/skills/sast-patterns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vibeeval/vibecosystem --skill sast-patterns -a codex`. Or copy the skill folder (skills/sast-patterns in vibeeval/vibecosystem) into .agents/skills/sast-patterns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill sast-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sast-patterns, .gemini/skills/sast-patterns, .github/skills/sast-patterns and .opencode/skills/sast-patterns in your project.
Going by SKILL.md and its folder, Sast Patterns needs the command-line tools its instructions call (semgrep, npm, pip, go, mvn and gradle) and credentials named SECRET_KEY, SEMGREP_APP_TOKEN, DJANGO_SECRET_KEY and SESSION_SECRET. Our summary lists: Python 3; Node.js; A credential in SECRET_KEY; A credential in DJANGO_SECRET_KEY.
SKILL.md names 6 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: semgrep.dev, owasp.org, cwe.mitre.org, nvd.nist.gov and security.snyk.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sast Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sast Patterns: Semgrep Rule Creator (skrun-dev/skrun, 210 stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Security Scanning Security Sast (aiskillstore/marketplace, 430 stars) and Security Testing (petrkindlmann/qa-skills, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 8, 2026.
Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.