Topic · Security
Best Static analysis and SAST skills, page 2
Static analysis and SAST skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | 49.Codeql Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF. | waybarrios/ | 533 | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 3 days ago |
| 50 | Model a method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes. | seqra/ | 163 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 51 | 51.Lintlang A skill your agent uses when writing or reviewing AI agent configs, system prompts, or tool definitions (JSON/YAML/Python) and you need to catch ambiguous tool descriptions, missing stop conditions… | hermes-labs-ai/ | 138 | — | ~719 | Automated safety check: Pass | Apache-2.0 | today |
| 52 | Evidence-based security report generation for firmware assessments. | OrbitCurve/ | 215 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 53 | 53.Fix Diagnose and fix Session Sniffer bugs, errors, tracebacks, logs, lint failures, static-analysis findings, test failures, and IDE-reported problems. | BUZZARDGTA/ | 104 | — | ~2.7k | Automated safety check: Pass | GPL-3.0 | today |
| 54 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 55 | 55.Semgrep Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis. | waybarrios/ | 533 | — | ~2.4k | Automated safety check: Pass | MIT | 3 days ago |
| 56 | Interactive smart contract security audit using Map-Hunt-Attack methodology with static analysis, parallel hunt lanes, skeptic-judge verification, and structured reporting. | Archethect/ | 127 | — | ~5.9k | Automated safety check: Notes | No licence | 6 mo ago |
| 57 | Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings. | trailofbits/ | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 58 | Run multi-dimensional quality assurance for InstructorPHP. An agent skill from cognesy/instructor-php. | cognesy/ | 328 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 59 | 59.Bom Evidence Enriches an existing CycloneDX BOM with occurrence, callstack, reachability, data-flow, and crypto-flow evidence using cdxgen evinse, including Go analysis via Golem and Rust analysis via Rusi, and… | cdxgen/ | 1.1k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 60 | Run one stage of the OpenTaint pipeline by coordinating leaf subagents and deterministic joins. | seqra/ | 163 | — | ~806 | Automated safety check: Pass | Apache-2.0 | today |
| 61 | 61.Lintlang Lint AI agent instruction files (SKILL.md, CLAUDE.md, AGENTS.md, GEMINI.md), tool definitions, system prompts, and agent configs with the deterministic LintLang CLI. | hermes-labs-ai/ | 138 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 62 | 62.Fix Issues A skill your agent uses when fixing compiler warnings, static analyzer findings (clang-tidy, etc.), or runtime errors/crashes in the libYSE codebase. | yvanvds/ | 238 | — | ~3k | Automated safety check: Pass | MIT | 9 days ago |
| 63 | Run Semgrep static analysis scans and create custom detection rules. | semgrep/ | 322 | — | ~2.3k | Automated safety check: Pass | Unknown | 2 mo ago |
| 64 | Pre-release readiness check for the voxglitch plugin, run before submitting a version to the VCV Rack library. | clone45/ | 131 | — | ~781 | Automated safety check: Pass | GPL-3.0 | 24 days ago |
| 65 | Perform codebase analysis and architecture mapping as the first phase of a security assessment. | utkusen/ | 1.3k | — | ~1k | Automated safety check: Pass | MIT | 6 mo ago |
| 66 | Android APK static analysis — OWASP Mobile Top 10, Retrofit API audit, transport security, smali reading, component export, auth flow analysis. | s0ld13rr/ | 828 | — | ~2.9k | Automated safety check: Pass | MIT | 6 days ago |
| 67 | Systematic static analysis of ELF firmware binaries using command-line tools (file, strings, readelf, objdump, xxd). | OrbitCurve/ | 215 | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 68 | Finds sensitive data that C, C++ or Rust code never wipes from memory, including wipes the compiler optimizes away, using source, assembly and control-flow analysis. | trailofbits/ | 7.4k | 4 repos | ~5.9k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 69 | Manage OpenClaw GitHub Actions and Blacksmith CI capacity, runner-registration budgets, fanout caps, main-push single-flight, shard sizing, hosted-runner offload, queue health, and safe… | openclaw/ | 392k | — | ~14k | Automated safety check: Pass | MIT | today |
| 70 | Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle. | apache/ | 2.9k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | today |
| 71 | Audit a named AI agent config, system prompt, tool-definition or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI, on request. | hermes-labs-ai/ | 138 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | today |
| 72 | Research notes drawn from Trail of Bits, SlowMist, ConsenSys, Immunefi and Cyfrin on smart contract audit methodology, with Slither, Echidna and Medusa setup. | tradecatlabs/ | 17k | 2 repos | ~9.9k | Automated safety check: Pass | MIT | today |
| 73 | 73.Cpp Style C++ naming, formatting, static analysis, and RTTI rules for LuisaCompute. | LuisaGroup/ | 1.1k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 74 | Master ShellCheck static analysis configuration and usage for shell script quality. Use when setting up linting infrastructure, fixing code issues… | wshobson/ | 40k | 11 repos | ~403 | Automated safety check: Pass | MIT | 4 days ago |
| 75 | 75.Sast Graphql Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input… | utkusen/ | 1.3k | — | ~4.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 76 | Static safety audit of a SKILL.md that scores five dimensions and acts as a gate: skills below the pass line do not ship, whatever else they score. | openJiuwen-ai/ | 446 | — | ~3.5k | Automated safety check: Warn | Apache-2.0 | today |
| 77 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 78 | 78.Ship Release The Massing release discipline — how to ship a verified, CI-green version-numbered release direct to main. | ibuilder/ | 122 | — | ~2.3k | Automated safety check: Pass | MIT | today |
| 79 | 分析 Code Scanning (CodeQL) 告警,评估安全风险并创建修复任务。当用户要求分析 Code Scanning 告警、CodeQL 告警时触发。参数为告警编号。 | ModelEngine-Group/ | 2.1k | — | ~187 | Automated safety check: Pass | MIT | 7 mo ago |
| 80 | Scans a Power Pages site project for security issues in source code and dependencies. | microsoft/ | 979 | — | ~3.4k | Automated safety check: Notes | MIT | today |
| 81 | 81.Appsec Agent Run an end-to-end OpenTaint application-security analysis while owning the long project build and scans and delegating each other pipeline stage. | seqra/ | 163 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | today |
| 82 | Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories. | waynesutton/ | 628 | — | ~1.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 83 | 83.Codex Review Run a Codex-CLI static-analysis parity review of the current diff against the local RPython/PyPy sources, then act on it — fix the regressions and new mismatches in-session, and file the rest as… | youknowone/ | 116 | — | ~2.3k | Automated safety check: Pass | Unknown | today |
| 84 | Audit a named AI agent config, system prompt, tool definition, or instruction file (YAML, JSON, Markdown, text, or Python) with the released LintLang CLI in GitHub Copilot CLI. | hermes-labs-ai/ | 138 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | today |
| 85 | 85.Code Quality Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector. | bonny/ | 317 | — | ~519 | Automated safety check: Notes | No licence | yesterday |
| 86 | A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. | AratKruglik/ | 155 | 1 repo | ~1.1k | Automated safety check: Notes | No licence | 5 mo ago |
| 87 | 87.Audit Prep Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project… | PlamenTSV/ | 303 | — | ~3.7k | Automated safety check: Pass | MIT | 12 days ago |
| 88 | 88.Sast Idor Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3… | utkusen/ | 1.3k | — | ~4.9k | Automated safety check: Pass | MIT | 6 mo ago |
| 89 | Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency… | affaan-m/ | 276k | 5 repos | ~1.5k | Automated safety check: Pass | MIT | 4 days ago |
| 90 | 关闭 Code Scanning (CodeQL) 告警,需提供合理理由。当用户要求关闭 Code Scanning 告警、dismiss CodeQL 告警时触发。参数为告警编号。 | ModelEngine-Group/ | 2.1k | — | ~185 | Automated safety check: Pass | MIT | 7 mo ago |
| 91 | Reduce technical debt and improve code quality by systematically resolving static analysis warnings. | flutter/ | 2k | — | ~429 | Automated safety check: Pass | BSD-3-Clause | today |
| 92 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 504 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 93 | Build a target project into an opentaint project model. An agent skill from seqra/opentaint. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 94 | Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. | skrun-dev/ | 210 | — | ~1.3k | Automated safety check: Pass | MIT | 16 days ago |
| 95 | Verification loop for Laravel projects: env checks, linting, static analysis, tests with coverage, security scans, and deployment readiness. | affaan-m/ | 276k | 4 repos | ~1.1k | Automated safety check: Notes | MIT | 4 days ago |
| 96 | 96.Code Audit A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification. | zhaoxuya520/ | 40k | 2 repos | ~374 | Automated safety check: Warn | MIT | 17 days ago |
Explore related skills
Category
More topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38