Topic · Security
Best Static analysis and SAST skills for Claude Code, Codex and other agents.
- skills
- 283
- official
- 29
Static analysis and SAST skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Turns natural-language code queries into ast-grep rules for structural search, testing each rule against an example file before running it on a codebase. | warp-drive-data/ | 3.2k | 5 repos | ~2.4k | Automated safety check: Pass | MIT | today |
| 2 | Searches and rewrites code by syntax-tree shape across 25 languages with ast-grep, for codemods, structural queries and YAML lint rules, using a Python wrapper script. | code-yeongyu/ | 70k | — | ~3.3k | Automated safety check: Pass | MIT | today |
| 3 | A skill your agent uses when biome migrate eslint must preserve configurable ESLint rule options through source-option models, Biome conversions, typed rule variants, and migration fixtures. | biomejs/ | 26k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. | elastic/ | 21k | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 5 | Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. | trailofbits/ | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 6 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | today |
| 7 | Statically pairs source files with test files to list code that no test references, using Roslyn for C# or tree-sitter for many languages, with no build. | dotnet/ | 5.6k | 1 repo | ~3.3k | Automated safety check: Pass | MIT | today |
| 8 | Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss. | trailofbits/ | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | today |
| 9 | 9.Semgrep Run Semgrep static analysis scan on a codebase using parallel subagents. | vigolium/ | 140 | 1 repo | ~2.4k | Automated safety check: Notes | MIT | 18 days ago |
| 10 | 10.C To Ast Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills. | Narwhal-Lab/ | 316 | — | ~1.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 11 | Sets the sonar-java conventions for adding an analyzer rule: metadata from rule-api, test locations, MethodMatchers and what not to commit or change. | SonarSource/ | 1.2k | — | ~833 | Automated safety check: Pass | Unknown | today |
| 12 | 12.Sonarqube Operate SonarQube-enabled repositories through the SonarQube CLI (sonar): verify authentication, discover project keys, inspect project metadata, issues, measures, and quality gates, analyze changed… | DougTrajano/ | 377 | — | ~2.2k | Automated safety check: Pass | MIT | 4 days ago |
| 13 | 13.Skylos Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | today |
| 14 | Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented. | fengshao1227/ | 5.9k | — | ~621 | Automated safety check: Notes | MIT | 23 days ago |
| 15 | Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 | Pa55w0rd/ | 423 | — | ~2.7k | Automated safety check: Pass | No licence | 3 mo ago |
| 16 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 17 | Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner. | ParzivalHack/ | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 18 | General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis. | SunWeb3Sec/ | 286 | — | ~6.2k | Automated safety check: Pass | No licence | 1 mo ago |
| 19 | 19.Lintlang A skill your agent uses when writing or reviewing AI agent configs, system prompts, or tool definitions (JSON/YAML/Python) and you need to catch ambiguous tool descriptions, missing stop conditions… | hermes-labs-ai/ | 137 | 1 repo | ~719 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 20 | Audit and enable security-oriented Xcode build settings. An agent skill from superagents-lab/xcode27-skills. | superagents-lab/ | 338 | — | ~4.6k | Automated safety check: Pass | No licence | 4 mo ago |
| 21 | Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos. | duriantaco/ | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 | today |
| 22 | Gives an agent working in a Go codebase a structural view through a local MCP server: call graphs, blast-radius and impact analysis, and bounded first-call exploration. | ozgurcd/ | 227 | — | ~4.8k | Automated safety check: Notes | MIT | yesterday |
| 23 | 23.Sast Semgrep Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. | AgentSecOps/ | 220 | 2 repos | ~2.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 24 | Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings. | tradecatlabs/ | 17k | 1 repo | ~738 | Automated safety check: Pass | Apache-2.0 | today |
| 25 | Safely unpack and investigate existing archives through evidence-first static analysis. | AetherKiri/ | 149 | — | ~1.6k | Automated safety check: Pass | GPL-3.0 | today |
| 26 | Builds a local architecture wiki for a repository from the CodexQA symbol graph (no model needed): modules, who calls whom and how often, reading paths, and one self-contained HTML page. | openqa-cn/ | 152 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 27 | Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request. | hermes-labs-ai/ | 137 | 1 repo | ~1.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 28 | Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. | netdata/ | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | today |
| 29 | GitHub Actions CI/CD pipeline configuration for Golang projects — workflow files for test, lint, SAST, coverage and vulnerability-scan jobs, Dependabot and Renovate config files, GoReleaser release… | samber/ | 3.4k | — | ~3.7k | Automated safety check: Pass | MIT | 7 days ago |
| 30 | 30.Openqodex Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex. | openqodex/ | 303 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 31 | Finds duplicated code in 220+ languages with jscpd, reports exact, renamed and near-miss clones in a compact agent-friendly format and measures duplication. | kucherenko/ | 6.4k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 32 | Analyze an OpenTaint scan's dropped external methods and decide which of them are propagators and optionally sinks. | seqra/ | 162 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | today |
| 33 | 33.Skeptic Run the security-focused Skeptic persona on the local working tree's diff against a base branch. | RaoFoundation/ | 389 | — | ~660 | Automated safety check: Pass | Apache-2.0 | today |
| 34 | Scans code with a bundled Node scanner for injection, secret leaks and other dangerous patterns, and requires documented decisions for accepted risks. | telagod/ | 243 | — | ~552 | Automated safety check: Notes | MIT | 2 mo ago |
| 35 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 36 | Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results. | block/ | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 37 | Explains what each aru doctor architecture-check finding means in the Arandu Go framework, why it is never suppressed, and how to fix the line it points to. | arandu-io/ | 281 | — | ~1.2k | Automated safety check: Pass | MIT | 4 days ago |
| 38 | Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation. | ptn1411/ | 219 | — | ~917 | Automated safety check: Pass | No licence | 16 days ago |
| 39 | CI/CD with GitHub Actions for Golang — testing, linting, SAST, security scanning, coverage, Dependabot, Renovate, GoReleaser, release pipelines. | context-labs/ | 1.1k | — | ~3.5k | Automated safety check: Pass | MIT | 3 days ago |
| 40 | 40.Wp Phpstan A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and… | Automattic/ | 211 | 1 repo | ~1k | Automated safety check: Pass | No licence | 8 mo ago |
| 41 | 41.Audit A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. | vigolium/ | 140 | — | ~8.7k | Automated safety check: Pass | MIT | 18 days ago |
| 42 | Run the VCV Rack library's static-analysis check on voxglitch locally, before submitting a release. | clone45/ | 131 | — | ~1.2k | Automated safety check: Pass | GPL-3.0 | 23 days ago |
| 43 | Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis. | openqa-cn/ | 152 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 44 | 44.Cyber Neo Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo. | Hainrixz/ | 281 | — | ~5.9k | Automated safety check: Warn | MIT | 2 mo ago |
| 45 | Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode. | redhat-et/ | 2.4k | — | ~1.1k | Automated safety check: Notes | Apache-2.0 | today |
| 46 | Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled. | garrytan/ | 136k | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 47 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | today |
| 48 | 48.Fallow Codebase intelligence for TypeScript and JavaScript. An agent skill from fallow-rs/fallow-skills. | fallow-rs/ | 129 | — | ~8.5k | Automated safety check: Pass | MIT | today |
Questions, answered from the data.
What is the best Static analysis and SAST skill?
Structural Code Search with ast-grep from warp-drive-data/warp-drive ranks first of the 283 Static analysis and SAST skills listed here, with the highest score: its repository has 3.2k GitHub stars, 5 other GitHub owners carry a copy, its SKILL.md loads about 2.4k tokens and it passes the automated safety check with no findings. Next come ast-grep Structural Search and Eslint Migrate Options.
Which Static analysis and SAST skills are official?
29 of the 283 Static analysis and SAST skills are official, published by the vendor's own GitHub organization: Eslint Migrate Options, Codeql, CodeQL Security Scan, Find Untested Sources, Trailmark Graph Evolution and 24 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38