Agent skill

Sast Patterns

by vibeeval in vibeeval/vibecosystem

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

MITAuto-check passedSecurity

Install Sast Patterns

skills CLI
$ npx skills add vibeeval/vibecosystem --skill sast-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vibeeval/vibecosystem sast-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vibeeval/vibecosystem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sast-patterns .claude/skills/sast-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sast-patterns
GitHub stars
531
Token cost
~4.6k tokens
SKILL.md length
492 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
MIT

At a glance

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

  • Scanning code for security vulnerabilities
  • SKILL.md covers When to Activate, OWASP Top 10 (2021) Checklist, Semgrep Custom Rule Writing… and CI/CD Integration, plus 3 more sections
  • Calls semgrep, npm and pip; reaches github.com; needs SECRET_KEY and SEMGREP_APP_TOKEN
  • Writing custom SAST rules

What it does

Sast Patterns is an agent skill from vibeeval/vibecosystem. Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. Use when scanning code for security vulnerabilities or writing custom SAST rules.

Its SKILL.md is about 4.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Static analysis and SAST and Web application vulnerabilities. It works with Semgrep. The repository describes itself as: AI software team for Claude Code - 138 agents, 295 skills, 73 hooks. Self-learning, multi-agent swarm, autonomous skill evolution. The licence is MIT.

When your agent uses it

  • Scanning code for security vulnerabilities
  • Writing custom SAST rules

Example prompts

  • “/sast-patterns”

Requirements

  • Python 3
  • Node.js
  • A credential in SECRET_KEY
  • A credential in DJANGO_SECRET_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 3b763b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • semgrep
    • npm
    • pip
    • go
    • mvn
    • gradle
    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • semgrep.dev
    • owasp.org
    • cwe.mitre.org
    • nvd.nist.gov
    • security.snyk.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY
    • SEMGREP_APP_TOKEN
    • DJANGO_SECRET_KEY
    • SESSION_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sast Patterns loads about 4.6k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 492 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vibeeval/vibecosystem at commit 3b763b1, republished under its MIT licence (© vibeeval). 492 words, ~4,634 tokens.

Download SKILL.mdSave it as .claude/skills/sast-patterns/SKILL.md (or your agent's skills folder).
name
sast-patterns
description
Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. Use when scanning code for security vulnerabilities or writing custom SAST rules.

SAST Patterns Skill

Comprehensive vulnerability pattern library for static application security testing. Covers OWASP Top 10, language-specific patterns, Semgrep custom rules, and CI/CD pipeline integration.

When to Activate

  • Running security scans on code
  • Writing custom Semgrep rules
  • Setting up CI/CD security gates
  • Reviewing code for security vulnerabilities
  • After sast-on-edit hook triggers
  • Before production deployment

OWASP Top 10 (2021) Checklist

A01: Broken Access Control

What to Look For:

  • Missing authorization checks on endpoints
  • Direct object reference without ownership validation
  • CORS misconfiguration allowing wildcard origins
  • Missing function-level access control
  • Metadata manipulation (JWT, cookies, hidden fields)

Detection Patterns:

javascript
// VULNERABLE: No authorization check
app.get('/api/users/:id', async (req, res) => {
  const user = await db.users.findById(req.params.id)
  res.json(user)  // Anyone can access any user
})

// SECURE: Authorization verified
app.get('/api/users/:id', authenticate, async (req, res) => {
  if (req.user.id !== req.params.id && !req.user.isAdmin) {
    return res.status(403).json({ error: 'Forbidden' })
  }
  const user = await db.users.findById(req.params.id)
  res.json(user)
})
python
# VULNERABLE: No permission check
@app.route('/admin/delete/<user_id>', methods=['DELETE'])
def delete_user(user_id):
    db.session.delete(User.query.get(user_id))
    db.session.commit()

# SECURE: Permission verified
@app.route('/admin/delete/<user_id>', methods=['DELETE'])
@login_required
@admin_required
def delete_user(user_id):
    db.session.delete(User.query.get(user_id))
    db.session.commit()

Semgrep Rules:

yaml
rules:
  - id: missing-auth-check
    patterns:
      - pattern: |
          app.$METHOD($PATH, async (req, res) => {
            ...
            $DB.$QUERY(...)
            ...
          })
      - pattern-not: |
          app.$METHOD($PATH, authenticate, ...)
    message: "Endpoint missing authentication middleware"
    severity: ERROR

A02: Cryptographic Failures

What to Look For:

  • Hardcoded secrets in source code
  • Weak hashing (MD5, SHA1) for passwords
  • Missing encryption for sensitive data at rest
  • HTTP instead of HTTPS
  • Weak TLS configuration

Detection Patterns:

javascript
// VULNERABLE: Weak password hashing
const hash = crypto.createHash('md5').update(password).digest('hex')

// SECURE: Strong password hashing
const hash = await bcrypt.hash(password, 12)
python
# VULNERABLE: Hardcoded secret
SECRET_KEY = "my-super-secret-key-123"

# SECURE: Environment variable
SECRET_KEY = os.environ.get('SECRET_KEY')
if not SECRET_KEY:
    raise ValueError("SECRET_KEY environment variable required")

Regex Patterns for Detection:

# API Keys
(?:api[_-]?key|apikey)\s*[:=]\s*['"][A-Za-z0-9_\-]{20,}['"]

# AWS Keys
(?:AKIA|ASIA)[A-Z0-9]{16}

# Generic Secrets
(?:password|passwd|pwd|secret|token)\s*[:=]\s*['"][^'"]{8,}['"]

# Private Keys
-----BEGIN (?:RSA |EC |DSA )?PRIVATE KEY-----

# JWT Tokens
eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+

A03: Injection

What to Look For:

  • SQL injection (string concatenation in queries)
  • Command injection (unsanitized shell execution)
  • NoSQL injection (MongoDB query operators in user input)
  • LDAP injection
  • Expression Language injection

Detection Patterns:

javascript
// SQL Injection
const query = `SELECT * FROM users WHERE id = ${userId}`  // VULNERABLE
const query = 'SELECT * FROM users WHERE id = $1'         // SECURE

// Command Injection
exec(`ping ${hostname}`)           // VULNERABLE
execFile('ping', [hostname])        // SECURE

// NoSQL Injection (MongoDB)
db.users.find({ email: req.body.email })        // VULNERABLE if email = {"$gt": ""}
db.users.find({ email: String(req.body.email) }) // SECURE: type coercion
python
# SQL Injection
cursor.execute(f"SELECT * FROM users WHERE id = {user_id}")  # VULNERABLE
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))  # SECURE

# Command Injection
os.system(f"convert {filename} output.png")                # VULNERABLE
subprocess.run(['convert', filename, 'output.png'], check=True)  # SECURE
go
// SQL Injection
db.Query("SELECT * FROM users WHERE id = " + userID)     // VULNERABLE
db.Query("SELECT * FROM users WHERE id = $1", userID)     // SECURE

// Command Injection
exec.Command("sh", "-c", userInput)                       // VULNERABLE
exec.Command("ping", "-c", "1", hostname)                 // SECURE
java
// SQL Injection
stmt.executeQuery("SELECT * FROM users WHERE id = " + id);          // VULNERABLE
PreparedStatement ps = conn.prepareStatement("SELECT * FROM users WHERE id = ?");
ps.setString(1, id);                                                // SECURE

A04: Insecure Design

What to Look For:

  • Missing rate limiting on critical operations
  • No account lockout after failed attempts
  • Missing CAPTCHA on public forms
  • Business logic flaws
  • Missing transaction atomicity

Detection Patterns:

javascript
// VULNERABLE: No rate limiting on login
app.post('/login', async (req, res) => {
  const user = await authenticate(req.body)
  res.json({ token: generateToken(user) })
})

// SECURE: Rate limited login
const loginLimiter = rateLimit({
  windowMs: 15 * 60 * 1000,
  max: 5,
  message: 'Too many login attempts'
})
app.post('/login', loginLimiter, async (req, res) => {
  const user = await authenticate(req.body)
  res.json({ token: generateToken(user) })
})
python
# VULNERABLE: Race condition in balance check
balance = get_balance(user_id)
if balance >= amount:
    withdraw(user_id, amount)  # Another request could drain first

# SECURE: Atomic transaction
with db.transaction():
    balance = db.query("SELECT balance FROM accounts WHERE id = %s FOR UPDATE", user_id)
    if balance >= amount:
        db.execute("UPDATE accounts SET balance = balance - %s WHERE id = %s", amount, user_id)

A05: Security Misconfiguration

What to Look For:

  • Debug mode in production
  • Default credentials
  • Unnecessary features enabled
  • Missing security headers
  • Verbose error messages
  • Directory listing enabled

Detection Patterns:

javascript
// VULNERABLE: Debug mode
app.set('env', 'development')  // In production config

// VULNERABLE: Missing security headers
// No helmet or manual headers

// SECURE: Security headers
import helmet from 'helmet'
app.use(helmet())
app.use(helmet.contentSecurityPolicy({
  directives: {
    defaultSrc: ["'self'"],
    scriptSrc: ["'self'"],
    styleSrc: ["'self'", "'unsafe-inline'"],
    imgSrc: ["'self'", 'data:', 'https:'],
  }
}))
python
# VULNERABLE: Debug in production
DEBUG = True  # In production settings

# VULNERABLE: Default secret key
SECRET_KEY = 'django-insecure-change-me'

# SECURE
DEBUG = os.environ.get('DEBUG', 'False') == 'True'
SECRET_KEY = os.environ['DJANGO_SECRET_KEY']

Security Headers Checklist:

Content-Security-Policy: default-src 'self'
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 0
Strict-Transport-Security: max-age=31536000; includeSubDomains
Referrer-Policy: strict-origin-when-cross-origin
Permissions-Policy: camera=(), microphone=(), geolocation=()

A06: Vulnerable and Outdated Components

Detection Commands:

bash
# Node.js
npm audit
npm audit --json
npm outdated

# Python
pip-audit
safety check
pip list --outdated

# Go
go list -m -u all
govulncheck ./...

# Java
mvn dependency-check:check
gradle dependencyCheckAnalyze

# Ruby
bundle audit check

A07: Identification and Authentication Failures

What to Look For:

  • Weak password policies
  • Missing MFA
  • Session fixation
  • Credential stuffing vulnerability
  • Plaintext password storage/comparison

Detection Patterns:

javascript
// VULNERABLE: Plaintext password comparison
if (password === user.password) { /* login */ }

// SECURE: Hashed comparison
const isValid = await bcrypt.compare(password, user.passwordHash)

// VULNERABLE: Weak session management
app.use(session({ secret: 'secret' }))

// SECURE: Strong session
app.use(session({
  secret: process.env.SESSION_SECRET,
  resave: false,
  saveUninitialized: false,
  cookie: {
    secure: true,
    httpOnly: true,
    sameSite: 'strict',
    maxAge: 3600000
  }
}))

A08: Software and Data Integrity Failures

What to Look For:

  • Missing Subresource Integrity (SRI) on CDN scripts
  • Insecure deserialization
  • Missing code signing
  • Auto-update without integrity verification
  • CI/CD pipeline without integrity checks

Detection Patterns:

html
<!-- VULNERABLE: No SRI -->
<script src="https://cdn.example.com/lib.js"></script>

<!-- SECURE: With SRI -->
<script src="https://cdn.example.com/lib.js"
  integrity="sha384-abc123..."
  crossorigin="anonymous"></script>
python
# VULNERABLE: Insecure deserialization
import pickle
data = pickle.loads(user_input)

# SECURE: Use JSON
import json
data = json.loads(user_input)

Show full SKILL.md (199 more words)Show less
A09: Security Logging and Monitoring Failures

What to Look For:

  • Missing audit logs for auth events
  • Sensitive data in logs
  • No log integrity protection
  • Missing alerting for suspicious activity

Detection Patterns:

javascript
// VULNERABLE: No logging
app.post('/login', async (req, res) => {
  const user = await authenticate(req.body)
  if (!user) return res.status(401).json({ error: 'Invalid' })
  res.json({ token: generateToken(user) })
})

// SECURE: Audit logging
app.post('/login', async (req, res) => {
  const user = await authenticate(req.body)
  if (!user) {
    logger.warn('Failed login attempt', {
      email: req.body.email,
      ip: req.ip,
      timestamp: new Date().toISOString()
    })
    return res.status(401).json({ error: 'Invalid credentials' })
  }
  logger.info('Successful login', { userId: user.id, ip: req.ip })
  res.json({ token: generateToken(user) })
})

// VULNERABLE: Sensitive data in logs
console.log('Login:', { email, password, token })

// SECURE: Redacted logs
console.log('Login:', { email, passwordProvided: !!password })

A10: Server-Side Request Forgery (SSRF)

What to Look For:

  • User-controlled URLs in server-side requests
  • Missing URL validation/whitelist
  • Internal service access via SSRF
  • Cloud metadata endpoint access

Detection Patterns:

javascript
// VULNERABLE: SSRF
const response = await fetch(req.query.url)

// SECURE: URL whitelist
const ALLOWED_DOMAINS = ['api.example.com', 'cdn.example.com']
const url = new URL(req.query.url)
if (!ALLOWED_DOMAINS.includes(url.hostname)) {
  throw new Error('Domain not allowed')
}
// Also block internal IPs
const ip = await dns.resolve(url.hostname)
if (isPrivateIP(ip)) {
  throw new Error('Internal addresses not allowed')
}
const response = await fetch(url.toString())
python
# VULNERABLE: SSRF
response = requests.get(user_url)

# SECURE: URL validation
from urllib.parse import urlparse
parsed = urlparse(user_url)
if parsed.hostname not in ALLOWED_HOSTS:
    raise ValueError("Domain not allowed")
if is_private_ip(socket.gethostbyname(parsed.hostname)):
    raise ValueError("Internal addresses blocked")
response = requests.get(user_url, allow_redirects=False)

Semgrep Custom Rule Writing Guide

Basic Rule Structure
yaml
rules:
  - id: rule-unique-id
    pattern: |
      eval($USER_INPUT)
    message: "eval() with dynamic input detected - potential RCE"
    languages: [javascript, typescript]
    severity: ERROR
    metadata:
      cwe:
        - CWE-94
      owasp:
        - A03:2021
      category: security
      confidence: HIGH
Pattern Operators
yaml
# pattern: match exactly
- pattern: eval($X)

# pattern-not: exclude matches
- pattern-not: eval("static-string")

# patterns: AND (all must match)
- patterns:
    - pattern: $DB.query($SQL)
    - pattern-not: $DB.query($SQL, $PARAMS)

# pattern-either: OR (any can match)
- pattern-either:
    - pattern: eval($X)
    - pattern: new Function($X)

# pattern-inside: match within a context
- pattern-inside: |
    app.$METHOD($PATH, (req, res) => {
      ...
    })

# pattern-not-inside: exclude context
- pattern-not-inside: |
    app.$METHOD($PATH, authenticate, ...)

# pattern-regex: regex in code
- pattern-regex: "password\s*=\s*['\"][^'\"]{3,}['\"]"
Metavariable Constraints
yaml
rules:
  - id: weak-hash-for-passwords
    patterns:
      - pattern: crypto.createHash($ALG).update($INPUT)
      - metavariable-regex:
          metavariable: $ALG
          regex: "('md5'|'sha1')"
      - metavariable-regex:
          metavariable: $INPUT
          regex: ".*password.*"
    message: "Weak hash algorithm used for password: $ALG"
    languages: [javascript, typescript]
    severity: ERROR
Taint Analysis (Pro)
yaml
rules:
  - id: sql-injection-taint
    mode: taint
    pattern-sources:
      - pattern: req.body.$PARAM
      - pattern: req.query.$PARAM
      - pattern: req.params.$PARAM
    pattern-sinks:
      - pattern: $DB.query($SQL)
    pattern-sanitizers:
      - pattern: $DB.escape($X)
      - pattern: sanitize($X)
    message: "User input flows to SQL query without sanitization"
    languages: [javascript]
    severity: ERROR
Project .semgrep.yml Example
yaml
rules:
  - id: no-hardcoded-secrets
    pattern-regex: |
      (?:api[_-]?key|secret|password|token)\s*[:=]\s*['"][A-Za-z0-9+/=_\-]{16,}['"]
    paths:
      exclude:
        - "*.test.*"
        - "*.spec.*"
        - "__tests__/*"
        - "*.example"
    message: "Potential hardcoded secret detected"
    languages: [generic]
    severity: ERROR

  - id: no-console-log-sensitive
    patterns:
      - pattern: console.log(..., $DATA, ...)
      - metavariable-regex:
          metavariable: $DATA
          regex: ".*(?:password|secret|token|key|credential).*"
    message: "Sensitive data in console.log"
    languages: [javascript, typescript]
    severity: WARNING

  - id: require-input-validation
    patterns:
      - pattern: |
          app.post($PATH, async (req, res) => {
            ...
            $DB.$METHOD(req.body)
            ...
          })
      - pattern-not: |
          app.post($PATH, async (req, res) => {
            ...
            $SCHEMA.parse(...)
            ...
          })
    message: "POST endpoint without input validation"
    languages: [javascript, typescript]
    severity: WARNING

CI/CD Integration

GitHub Actions
yaml
name: SAST Security Scan

on:
  pull_request:
    branches: [main, develop]
  push:
    branches: [main]

jobs:
  sast:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Semgrep Scan
        uses: semgrep/semgrep-action@v1
        with:
          config: >-
            p/owasp-top-ten
            p/secrets
            p/typescript
          generateSarif: "1"
        env:
          SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}

      - name: Upload SARIF
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: semgrep.sarif
        if: always()

      - name: Dependency Audit
        run: npm audit --audit-level=high

      - name: Check for Secrets
        uses: trufflesecurity/trufflehog@main
        with:
          extra_args: --only-verified
Pre-commit Hook
yaml
# .pre-commit-config.yaml
repos:
  - repo: https://github.com/semgrep/semgrep
    rev: 'v1.60.0'
    hooks:
      - id: semgrep
        args: ['--config', 'auto', '--error', '--severity', 'ERROR']
GitLab CI
yaml
sast:
  stage: test
  image: semgrep/semgrep
  script:
    - semgrep --config auto --config "p/secrets" --json --output gl-sast-report.json .
  artifacts:
    reports:
      sast: gl-sast-report.json
  rules:
    - if: $CI_MERGE_REQUEST_ID
CLI Commands Quick Reference
bash
# Full scan with auto rules
semgrep --config auto .

# OWASP + Secrets
semgrep --config "p/owasp-top-ten" --config "p/secrets" .

# Only errors (for CI gates)
semgrep --config auto --error --severity ERROR .

# JSON output for processing
semgrep --config auto --json --output report.json .

# Scan specific files
semgrep --config auto src/api/ src/auth/

# Diff-aware (only changed code)
semgrep --config auto --baseline-commit origin/main

# Custom rules
semgrep --config .semgrep.yml .

# Exclude test files
semgrep --config auto --exclude="*test*" --exclude="*spec*" .

# With metrics disabled (privacy)
semgrep --config auto --metrics=off .

Severity Classification Guide

SeverityCriteriaActionSLA
CRITICALExploitable RCE, SQLi, auth bypass, data breachFix IMMEDIATELY, block deploy< 1 hour
HIGHXSS, SSRF, IDOR, missing auth, weak cryptoFix before production< 24 hours
MEDIUMMissing validation, verbose errors, weak headersFix in current sprint< 1 week
LOWDebug mode, outdated lib (no known CVE), info leakFix in backlog< 1 month

Quick Decision Tree

Is user input involved?
  YES -> Does it reach a dangerous sink (DB, exec, DOM)?
    YES -> Is it sanitized/validated?
      NO  -> CRITICAL (injection)
      YES -> Check sanitizer adequacy -> MEDIUM if weak
    NO  -> MEDIUM (missing validation)
  NO  -> Is it a configuration issue?
    YES -> Affects security posture?
      YES -> HIGH (misconfiguration)
      NO  -> LOW (best practice)
    NO  -> Is it a dependency issue?
      YES -> Known CVE?
        YES -> Match CVE severity
        NO  -> LOW (outdated)
      NO  -> Informational

Resources


Remember: SAST catches patterns, not intent. Always verify findings with manual review. A finding is only a vulnerability if it can be exploited in the application's specific context.

© vibeeval, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sast-patterns of vibeeval/vibecosystem.

Open the folder on GitHubat commit 3b763b1

Compare with similar skills

Sast Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sast Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sast Patterns this skillvibeeval/vibecosystem531—~4.6kAutomated safety check: PassMIT
Semgrep Rule Creatorskrun-dev/skrun210—~1.3kAutomated safety check: PassMIT
Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Security Scanning Security Sastaiskillstore/marketplace4307 repos~3.7kAutomated safety check: PassNone
Security Testingpetrkindlmann/qa-skills165—~4.9kAutomated safety check: PassMIT
Security Scanericrisco/rsc-harness167—~2.8kAutomated safety check: NotesMIT

Similar skills

  • Semgrep Rule Creator

    skrun-dev/skrun

    Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

    210 GitHub stars~1.3k tokensUpdated 16 days ago
    SecurityAuto-check passed
  • Implementing Devsecops Security Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Scanning Security Sast

    aiskillstore/marketplace

    Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

    430 GitHub starsUsed in 7 repos~3.7k tokens
    SecurityAuto-check passed
  • Security Testing

    petrkindlmann/qa-skills

    Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

    165 GitHub stars~4.9k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    167 GitHub stars~2.8k tokensUpdated today
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed

More from vibeeval/vibecosystem

All 12 skills in this repo
  • Agent Benchmark

    vibeeval/vibecosystem

    Framework for measuring and tracking agent response quality over time.

    531 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Differential Review

    vibeeval/vibecosystem

    Security-focused differential code review with blast radius analysis, risk-adaptive depth (DEEP/FOCUSED/SURGICAL), git history correlation, and structured finding format.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • Factcheck Guard

    vibeeval/vibecosystem

    A skill your agent uses when making any factual claim about the codebase — existence, absence, or behavior.

    531 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Fp Check

    vibeeval/vibecosystem

    Systematic false positive verification for security findings.

    531 GitHub stars~1.6k tokensUpdated 2 mo ago
    Auto-check passed
  • N8n Workflows

    vibeeval/vibecosystem

    n8n otomasyon workflow'lari. An agent skill from vibeeval/vibecosystem.

    531 GitHub stars~3.3k tokensUpdated 2 mo ago
    Auto-check passed
  • Notepad System

    vibeeval/vibecosystem

    A skill your agent uses when context compression is imminent, when resuming a session, or when preserving critical decisions across long tasks.

    531 GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Sast Patterns

What does Sast Patterns do?

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. Sast Patterns is an agent skill from vibeeval/vibecosystem. Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

When should I use Sast Patterns?

Sast Patterns fits situations like: scanning code for security vulnerabilities; writing custom SAST rules.

How do I install Sast Patterns in Claude Code?

Run `npx skills add vibeeval/vibecosystem --skill sast-patterns -a claude-code`. Or copy the skill folder (skills/sast-patterns in vibeeval/vibecosystem) into .claude/skills/sast-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Sast Patterns in Codex?

Run `npx skills add vibeeval/vibecosystem --skill sast-patterns -a codex`. Or copy the skill folder (skills/sast-patterns in vibeeval/vibecosystem) into .agents/skills/sast-patterns in your project. Codex loads it when a task matches its description.

Can I use Sast Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vibeeval/vibecosystem --skill sast-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sast-patterns, .gemini/skills/sast-patterns, .github/skills/sast-patterns and .opencode/skills/sast-patterns in your project.

What does Sast Patterns need to run?

Going by SKILL.md and its folder, Sast Patterns needs the command-line tools its instructions call (semgrep, npm, pip, go, mvn and gradle) and credentials named SECRET_KEY, SEMGREP_APP_TOKEN, DJANGO_SECRET_KEY and SESSION_SECRET. Our summary lists: Python 3; Node.js; A credential in SECRET_KEY; A credential in DJANGO_SECRET_KEY.

Does Sast Patterns access the network?

SKILL.md names 6 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: semgrep.dev, owasp.org, cwe.mitre.org, nvd.nist.gov and security.snyk.io. This is read from the text; nothing was executed.

Is Sast Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sast Patterns use?

Sast Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sast Patterns use?

About 4.6k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sast Patterns?

Skills that share tags, products or a category with Sast Patterns: Semgrep Rule Creator (skrun-dev/skrun, 210 stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Security Scanning Security Sast (aiskillstore/marketplace, 430 stars) and Security Testing (petrkindlmann/qa-skills, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sast Patterns?

vibeeval (a GitHub user) maintains it in vibeeval/vibecosystem, which has 531 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on August 8, 2026.

Source: vibeeval/vibecosystem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.