Topic · Security
Best Static analysis and SAST skills, page 3
Static analysis and SAST skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | 97.Sast Report Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. | utkusen/ | 1.3k | — | ~1.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 98 | Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates. | AgentSecOps/ | 220 | 1 repo | ~4.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 99 | Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages. | davila7/ | 32k | 11 repos | ~1.6k | Automated safety check: Pass | MIT | today |
| 100 | Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle… | axelixlabs/ | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | today |
| 101 | Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by… | hardw00t/ | 104 | — | ~2.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 102 | Methodology for root-causing hard concurrency / memory-ordering bugs (intermittent races, use-after-free, RCU/lock-free publish-order defects, "impossible" stale reads) with LTTng flight-recorder… | isc-projects/ | 780 | — | ~2.5k | Automated safety check: Pass | MPL-2.0 | today |
| 103 | 103.Security Setup Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 104 | Model a method's taint propagation as a passThrough approximation. | seqra/ | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 105 | 105.Lint Health-check the Obsidian wiki — the "static analysis" pass for a knowledge base. | HurricaHjz/ | 120 | — | ~6.3k | Automated safety check: Pass | MIT | 7 days ago |
| 106 | 106.Variant Analysis Find similar vulnerabilities and bugs across codebases using pattern-based analysis. | waybarrios/ | 533 | 5 repos | ~1.4k | Automated safety check: Pass | MIT | 3 days ago |
| 107 | Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch. | cloudposse/ | 1.4k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 108 | Security-focused source code review and SAST. An agent skill from transilienceai/communitytools. | transilienceai/ | 562 | — | ~1.2k | Automated safety check: Notes | MIT | 2 mo ago |
| 109 | 109.Refactorability Review code for refactorability — surface concrete, prioritized refactoring opportunities grounded in Martin Fowler's smell catalog and SOLID, augmented with static analysis tools (gocyclo… | meain/ | 285 | — | ~2k | Automated safety check: Pass | MIT | yesterday |
| 110 | 110.PHP Pro Writes strictly typed modern PHP 8.3+ for Laravel, Symfony and plain projects, with PHPStan level 9, PHPUnit or Pest tests, typed DTOs and secure defaults. | Jeffallan/ | 12k | — | ~1.6k | Automated safety check: Notes | MIT | 5 days ago |
| 111 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 5 days ago |
| 112 | 112.Create Rule Author and verify an OpenTaint rule. An agent skill from seqra/opentaint. | seqra/ | 163 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 113 | Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel… | utkusen/ | 1.3k | — | ~5.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 114 | 114.Aster Config Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. | Zfinix/ | 113 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 115 | 115.Semgrep Skill Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. | KimYx0207/ | 174 | — | ~1.2k | Automated safety check: Pass | MIT | 2 days ago |
| 116 | Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data. | trailofbits/ | 7.4k | — | ~2.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 117 | Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 118 | Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots. | trailofbits/ | 7.4k | — | ~4.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 119 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 120 | Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits. | cyberful/ | 135 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 121 | 121.Get Call Paths Get a path in the call graph from a source function to a specified destination function in the codebase. | opensage-agent/ | 127 | — | ~272 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 122 | 122.Code Reviewer Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability. | AratKruglik/ | 155 | 8 repos | ~2.3k | Automated safety check: Pass | No licence | 5 mo ago |
| 123 | How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes. | ibuilder/ | 122 | — | ~1.7k | Automated safety check: Pass | MIT | today |
| 124 | GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL). | secondsky/ | 227 | — | ~4k | Automated safety check: Notes | MIT | 11 days ago |
| 125 | Create an OpenTaint test project with positive/negative samples for verifying a rule or approximation. | seqra/ | 163 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 126 | 126.Sast Fileupload Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel… | utkusen/ | 1.3k | — | ~7.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 127 | Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix. | trailofbits/ | 7.4k | — | ~3.1k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 128 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 129 | Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay. | trailofbits/ | 7.4k | — | ~3.3k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 130 | Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark… | trailofbits/ | 7.4k | — | ~1.5k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 131 | Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation… | affaan-m/ | 276k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 4 days ago |
| 132 | Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation. | dslsdzc/ | 130 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 133 | 133.Expert Security 安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex. | ReJeCtAll/ | 113 | — | ~780 | Automated safety check: Pass | MIT | 3 mo ago |
| 134 | WordPress PHPStan review and setup guidance. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 102 | — | ~1.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 135 | Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an… | openqa-cn/ | 152 | — | ~7.2k | Automated safety check: Warn | Apache-2.0 | 6 days ago |
| 136 | 136.Get Callee Tool to get the callee of a function in the codebase by function name and file path. | opensage-agent/ | 127 | — | ~223 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 137 | Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common… | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 138 | Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk. | openqa-cn/ | 152 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 139 | Configure code scanning in Harness pipelines using STO security scanners. | harness/ | 115 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 140 | 140.Static Analysis Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification. | aftermathlabs/ | 438 | — | ~1.8k | Automated safety check: Pass | AGPL-3.0 | 5 days ago |
| 141 | Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations. | ArabelaTso/ | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 142 | 142.Security Scan Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes. | bagofwords1/ | 459 | — | ~1.7k | Automated safety check: Pass | Unknown | today |
| 143 | 143.Lint Common Lisp Run static analysis on Common Lisp projects with the Mallet command-line linter. | ultralisp/ | 258 | — | ~771 | Automated safety check: Pass | No licence | 26 days ago |
| 144 | Classify project-used dependency members and record taint sources as rule-authoring units. | seqra/ | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
Explore related skills
Category
More topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38