Topic · Security

Best Static analysis and SAST skills for Claude Code, Codex and other agents.

Skills that run and write static-analysis rules to find security bugs.
skills
283
official
29

Static analysis and SAST skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Static analysis and SAST skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Turns natural-language code queries into ast-grep rules for structural search, testing each rule against an example file before running it on a codebase.

warp-drive-data/warp-drive3.2k5 repos~2.4kAutomated safety check: PassMITtoday
2

Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script.

code-yeongyu/oh-my-openagent70k—~3.3kAutomated safety check: PassMITtoday
3

A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures.

biomejs/biome26k—~1.4kAutomated safety check: PassApache-2.0today
4
4.CodeqlOfficial

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

elastic/kibana21k—~1.7kAutomated safety check: PassUnknowntoday
5

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

trailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0today
6

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknowntoday
7

Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build.

dotnet/skills5.6k1 repo~3.3kAutomated safety check: PassMITtoday
8

Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

trailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0today
9

Run Semgrep static analysis scan on a codebase using parallel subagents.

vigolium/piolium1401 repo~2.4kAutomated safety check: NotesMIT18 days ago
10

Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

Narwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT6 mo ago
11

Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change.

SonarSource/sonar-java1.2k—~833Automated safety check: PassUnknowntoday
12

Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed…

DougTrajano/pydantic-ai-skills377—~2.2kAutomated safety check: PassMIT4 days ago
13

Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~581Automated safety check: PassApache-2.0today
14

Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

fengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT23 days ago
15

Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

Pa55w0rd/secknowledge-skill423—~2.7kAutomated safety check: PassNo licence3 mo ago
16

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0today
17

Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

ParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0yesterday
18

General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

SunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNo licence1 mo ago
19

A skill your agent uses when writing or reviewing AI agent configs, system prompts, or tool definitions (JSON/YAML/Python) and you need to catch ambiguous tool descriptions, missing stop conditions…

hermes-labs-ai/lintlang1371 repo~719Automated safety check: PassApache-2.0yesterday
20

Audit and enable security-oriented Xcode build settings. An agent skill from superagents-lab/xcode27-skills.

superagents-lab/xcode27-skills338—~4.6kAutomated safety check: PassNo licence4 mo ago
21

Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.

duriantaco/skylos843—~545Automated safety check: PassApache-2.0today
22

Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration.

ozgurcd/gograph227—~4.8kAutomated safety check: NotesMITyesterday
23

Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

AgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassUnknown5 mo ago
24

Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

tradecatlabs/vibe-coding-cn17k1 repo~738Automated safety check: PassApache-2.0today
25

Safely unpack and investigate existing archives through evidence-first static analysis.

AetherKiri/Aether149—~1.6kAutomated safety check: PassGPL-3.0today
26

Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page.

openqa-cn/codexqa152—~1.3kAutomated safety check: PassApache-2.05 days ago
27

Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request.

hermes-labs-ai/lintlang1371 repo~1.8kAutomated safety check: PassApache-2.0yesterday
28

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

netdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0today
29

GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release…

samber/cc-skills-golang3.4k—~3.7kAutomated safety check: PassMIT7 days ago
30

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

openqodex/openqodex303—~1.9kAutomated safety check: PassApache-2.0yesterday
31

Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication.

kucherenko/jscpd6.4k—~4.5kAutomated safety check: PassMITtoday
32

Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks.

seqra/opentaint162—~3.2kAutomated safety check: PassApache-2.0today
33

Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

RaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0today
34

Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks.

telagod/code-abyss243—~552Automated safety check: NotesMIT2 mo ago
35

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0yesterday
36

Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.

block/codecrucible117—~1.2kAutomated safety check: PassApache-2.0yesterday
37

Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to.

arandu-io/arandu281—~1.2kAutomated safety check: PassMIT4 days ago
38

Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

ptn1411/skill219—~917Automated safety check: PassNo licence16 days ago
39

CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines.

context-labs/whip1.1k—~3.5kAutomated safety check: PassMIT3 days ago
40

A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

Automattic/agent-skills2111 repo~1kAutomated safety check: PassNo licence8 mo ago
41

A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.

vigolium/piolium140—~8.7kAutomated safety check: PassMIT18 days ago
42

Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release.

clone45/voxglitch131—~1.2kAutomated safety check: PassGPL-3.023 days ago
43

Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

openqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.05 days ago
44

Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

Hainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT2 mo ago
45

Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

redhat-et/ripwire2.4k—~1.1kAutomated safety check: NotesApache-2.0today
46

Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.

garrytan/gstack136k—~4.5kAutomated safety check: PassMITtoday
47

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0today
48

Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills.

fallow-rs/fallow-skills129—~8.5kAutomated safety check: PassMITtoday

Questions, answered from the data.

What is the best Static analysis and SAST skill?

Structural Code Search with ast-grep from warp-drive-data/warp-drive ranks first of the 283 Static analysis and SAST skills listed here, with the highest score: its repository has 3.2k GitHub stars, 5 other GitHub owners carry a copy, its SKILL.md loads about 2.4k tokens and it passes the automated safety check with no findings. Next come ast-grep Structural Search and Eslint Migrate Options.

Which Static analysis and SAST skills are official?

29 of the 283 Static analysis and SAST skills are official, published by the vendor's own GitHub organization: Eslint Migrate Options, Codeql, CodeQL Security Scan, Find Untested Sources, Trailmark Graph Evolution and 24 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.