Topic · Security

Best Static analysis and SAST skills, page 2

Skills #49–96 of 284, ranked by score.

Static analysis and SAST skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Static analysis and SAST skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.

waybarrios/opencode-power-pack5332 repos~3.7kAutomated safety check: PassMIT3 days ago
50

Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes.

seqra/opentaint163—~1.9kAutomated safety check: PassApache-2.0today
51

A skill your agent uses when writing or reviewing AI agent configs, system prompts, or tool definitions (JSON/YAML/Python) and you need to catch ambiguous tool descriptions, missing stop conditions…

hermes-labs-ai/lintlang138—~719Automated safety check: PassApache-2.0today
52

Evidence-based security report generation for firmware assessments.

OrbitCurve/firmware-reverse-engineering215—~4.1kAutomated safety check: PassApache-2.01 mo ago
53
53.Fix

Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, test failures, and IDE-reported problems.

BUZZARDGTA/Session-Sniffer104—~2.7kAutomated safety check: PassGPL-3.0today
54

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.4k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
55

Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

waybarrios/opencode-power-pack533—~2.4kAutomated safety check: PassMIT3 days ago
56

Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting.

Archethect/sc-auditor127—~5.9kAutomated safety check: NotesNo licence6 mo ago
57

Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

trailofbits/skills7.4k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
58

Run multi-dimensional quality assurance for InstructorPHP. An agent skill from cognesy/instructor-php.

cognesy/instructor-php328—~1.3kAutomated safety check: PassMITyesterday
59

Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and…

cdxgen/cdxgen1.1k—~1.9kAutomated safety check: PassApache-2.0today
60

Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins.

seqra/opentaint163—~806Automated safety check: PassApache-2.0today
61

Lint AI agent instruction files (SKILL.md, CLAUDE.md, AGENTS.md, GEMINI.md), tool definitions, system prompts, and agent configs with the deterministic LintLang CLI.

hermes-labs-ai/lintlang138—~1.7kAutomated safety check: PassApache-2.0today
62

A skill your agent uses when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase.

yvanvds/yse-soundengine238—~3kAutomated safety check: PassMIT9 days ago
63
63.SemgrepOfficial

Run Semgrep static analysis scans and create custom detection rules.

semgrep/skills322—~2.3kAutomated safety check: PassUnknown2 mo ago
64

Pre-release readiness check for the voxglitch plugin, run before submitting a version to the VCV Rack library.

clone45/voxglitch131—~781Automated safety check: PassGPL-3.024 days ago
65

Perform codebase analysis and architecture mapping as the first phase of a security assessment.

utkusen/sast-skills1.3k—~1kAutomated safety check: PassMIT6 mo ago
66

Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis.

s0ld13rr/pentestcode828—~2.9kAutomated safety check: PassMIT6 days ago
67

Systematic static analysis of ELF firmware binaries using command-line tools (file, strings, readelf, objdump, xxd).

OrbitCurve/firmware-reverse-engineering215—~3.2kAutomated safety check: PassApache-2.01 mo ago
68

Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis.

trailofbits/skills7.4k4 repos~5.9kAutomated safety check: NotesCC-BY-SA-4.0yesterday
69

Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe…

openclaw/openclaw392k—~14kAutomated safety check: PassMITtoday
70

Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle.

apache/grails-core2.9k—~3.9kAutomated safety check: PassApache-2.0today
71

Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request.

hermes-labs-ai/lintlang138—~1.8kAutomated safety check: PassApache-2.0today
72

Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup.

tradecatlabs/vibe-coding-cn17k2 repos~9.9kAutomated safety check: PassMITtoday
73

C++ naming, formatting, static analysis, and RTTI rules for LuisaCompute.

LuisaGroup/LuisaCompute1.1k—~1.1kAutomated safety check: PassApache-2.0today
74

Master ShellCheck static analysis configuration and usage for shell script quality. Use when setting up linting infrastructure, fixing code issues…

wshobson/agents40k11 repos~403Automated safety check: PassMIT4 days ago
75

Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input…

utkusen/sast-skills1.3k—~4.7kAutomated safety check: PassMIT6 mo ago
76

Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score.

openJiuwen-ai/agent-core446—~3.5kAutomated safety check: WarnApache-2.0today
77
77.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
78

The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main.

ibuilder/massing122—~2.3kAutomated safety check: PassMITtoday
79

分析 Code Scanning (CodeQL) 告警,评估安全风险并创建修复任务。当用户要求分析 Code Scanning 告警、CodeQL 告警时触发。参数为告警编号。

ModelEngine-Group/fit-framework2.1k—~187Automated safety check: PassMIT7 mo ago
80
80.Scan CodeOfficial

Scans a Power Pages site project for security issues in source code and dependencies.

microsoft/power-platform-skills979—~3.4kAutomated safety check: NotesMITtoday
81

Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage.

seqra/opentaint163—~2.2kAutomated safety check: PassApache-2.0today
82

Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.

waynesutton/markdown-site628—~1.9kAutomated safety check: PassMIT4 mo ago
83

Run a Codex-CLI static-analysis parity review of the current diff against the local RPython/PyPy sources, then act on it — fix the regressions and new mismatches in-session, and file the rest as…

youknowone/pyre116—~2.3kAutomated safety check: PassUnknowntoday
84

Audit a named AI agent config, system prompt, tool definition, or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI in GitHub Copilot CLI.

hermes-labs-ai/lintlang138—~1.9kAutomated safety check: PassApache-2.0today
85

Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector.

bonny/WordPress-Simple-History317—~519Automated safety check: NotesNo licenceyesterday
86

A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

AratKruglik/claude-laravel1551 repo~1.1kAutomated safety check: NotesNo licence5 mo ago
87

Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…

PlamenTSV/plamen303—~3.7kAutomated safety check: PassMIT12 days ago
88

Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3…

utkusen/sast-skills1.3k—~4.9kAutomated safety check: PassMIT6 mo ago
89

Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency…

affaan-m/ECC276k5 repos~1.5kAutomated safety check: PassMIT4 days ago
90

关闭 Code Scanning (CodeQL) 告警,需提供合理理由。当用户要求关闭 Code Scanning 告警、dismiss CodeQL 告警时触发。参数为告警编号。

ModelEngine-Group/fit-framework2.1k—~185Automated safety check: PassMIT7 mo ago
91

Reduce technical debt and improve code quality by systematically resolving static analysis warnings.

flutter/flutter-intellij2k—~429Automated safety check: PassBSD-3-Clausetoday
92

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack504—~510Automated safety check: PassApache-2.05 days ago
93

Build a target project into an opentaint project model. An agent skill from seqra/opentaint.

seqra/opentaint163—~1.1kAutomated safety check: PassApache-2.0today
94

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

skrun-dev/skrun210—~1.3kAutomated safety check: PassMIT16 days ago
95

Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness.

affaan-m/ECC276k4 repos~1.1kAutomated safety check: NotesMIT4 days ago
96

A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

zhaoxuya520/reverse-skill40k2 repos~374Automated safety check: WarnMIT17 days ago