Topic · Security

Best Static analysis and SAST skills, page 3

Skills #97–144 of 284, ranked by score.

Static analysis and SAST skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Static analysis and SAST skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
97

Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact.

utkusen/sast-skills1.3k—~1.7kAutomated safety check: PassMIT6 mo ago
98

Lints Dockerfiles with Hadolint for security misconfigurations and best-practice violations, locally and in CI, with strict, balanced and permissive rule templates.

AgentSecOps/SecOpsAgentKit2201 repo~4.4kAutomated safety check: PassUnknown5 mo ago
99

Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

davila7/claude-code-templates32k11 repos~1.6kAutomated safety check: PassMITtoday
100

Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

axelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0today
101

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by…

hardw00t/ai-security-arsenal104—~2.7kAutomated safety check: PassNo licence5 mo ago
102

Methodology for root-causing hard concurrency / memory-ordering bugs (intermittent races, use-after-free, RCU/lock-free publish-order defects, "impossible" stale reads) with LTTng flight-recorder…

isc-projects/bind9780—~2.5kAutomated safety check: PassMPL-2.0today
103

Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

luongnv89/skills131—~4.5kAutomated safety check: PassMITtoday
104

Model a method's taint propagation as a passThrough approximation.

seqra/opentaint163—~1.7kAutomated safety check: PassApache-2.0today
105
105.Lint

Health-check the Obsidian wiki — the "static analysis" pass for a knowledge base.

HurricaHjz/second-yourself120—~6.3kAutomated safety check: PassMIT7 days ago
106

Find similar vulnerabilities and bugs across codebases using pattern-based analysis.

waybarrios/opencode-power-pack5335 repos~1.4kAutomated safety check: PassMIT3 days ago
107

Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch.

cloudposse/atmos1.4k—~1.3kAutomated safety check: PassApache-2.0today
108

Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

transilienceai/communitytools562—~1.2kAutomated safety check: NotesMIT2 mo ago
109

Review code for refactorability — surface concrete, prioritized refactoring opportunities grounded in Martin Fowler's smell catalog and SOLID, augmented with static analysis tools (gocyclo…

meain/dotfiles285—~2kAutomated safety check: PassMITyesterday
110

Writes strictly typed modern PHP 8.3+ for Laravel, Symfony and plain projects, with PHPStan level 9, PHPUnit or Pest tests, typed DTOs and secure defaults.

Jeffallan/claude-skills12k—~1.6kAutomated safety check: NotesMIT5 days ago
111

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT5 days ago
112

Author and verify an OpenTaint rule. An agent skill from seqra/opentaint.

seqra/opentaint163—~2.6kAutomated safety check: PassApache-2.0today
113

Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel…

utkusen/sast-skills1.3k—~5.3kAutomated safety check: PassMIT6 mo ago
114

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

Zfinix/aster113—~1.2kAutomated safety check: PassApache-2.0today
115

Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.

KimYx0207/Kim_Service174—~1.2kAutomated safety check: PassMIT2 days ago
116

Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data.

trailofbits/skills7.4k—~2.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
117

Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

trailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0yesterday
118

Builds a code graph of functions, classes and calls across languages, then queries it for call paths, taint, blast radius, entry points and complexity hotspots.

trailofbits/skills7.4k—~4.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
119

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
120

Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

cyberful/cyberful135—~1.3kAutomated safety check: PassAGPL-3.01 mo ago
121

Get a path in the call graph from a source function to a specified destination function in the codebase.

opensage-agent/opensage-adk127—~272Automated safety check: PassApache-2.02 mo ago
122

Elite code review expert specializing in modern AI-powered code analysis, security vulnerabilities, performance optimization, and production reliability.

AratKruglik/claude-laravel1558 repos~2.3kAutomated safety check: PassNo licence5 mo ago
123

How to monitor and fix security issues in Massing — CodeQL alerts, dependency audits, secret scanning, and ReDoS/XXE fixes.

ibuilder/massing122—~1.7kAutomated safety check: PassMITtoday
124

GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL).

secondsky/claude-skills227—~4kAutomated safety check: NotesMIT11 days ago
125

Create an OpenTaint test project with positive/negative samples for verifying a rule or approximation.

seqra/opentaint163—~2.3kAutomated safety check: PassApache-2.0today
126

Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel…

utkusen/sast-skills1.3k—~7.3kAutomated safety check: PassMIT6 mo ago
127

Scans Algorand TEAL and PyTeal contracts for 11 known vulnerability patterns, such as unchecked rekeying and fees, and reports each with severity and a fix.

trailofbits/skills7.4k—~3.1kAutomated safety check: PassCC-BY-SA-4.0yesterday
128

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

trailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.0yesterday
129

Scans Cairo and StarkNet contracts for 6 vulnerability patterns, including felt252 overflow, L1 to L2 messaging faults, address conversion and signature replay.

trailofbits/skills7.4k—~3.3kAutomated safety check: PassCC-BY-SA-4.0yesterday
130

Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark…

trailofbits/skills7.4k—~1.5kAutomated safety check: NotesCC-BY-SA-4.0yesterday
131

Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation…

affaan-m/ECC276k1 repo~2.7kAutomated safety check: PassMIT4 days ago
132

Guides static analysis of an Android APK with jadx and apktool: reading the manifest, Java code, resources and permissions, and recognizing hardening or obfuscation.

dslsdzc/rev-skills130—~2kAutomated safety check: PassApache-2.04 days ago
133

安全专家入口。用于 Codex CLI 的 $expert-security 调用. An agent skill from ReJeCtAll/ExpertTeam-Codex.

ReJeCtAll/ExpertTeam-Codex113—~780Automated safety check: PassMIT3 mo ago
134

WordPress PHPStan review and setup guidance. An agent skill from jorgerosal/wordpress-skills.

jorgerosal/wordpress-skills102—~1.2kAutomated safety check: PassMIT4 mo ago
135

Graph-evidence AI code review (codexqa-code-reviewer) for ANY language repo using ONLY the CodexQA CLI symbol graph (call chains, classes, methods, configs, blast radius, test edges), then an…

openqa-cn/codexqa152—~7.2kAutomated safety check: WarnApache-2.06 days ago
136

Tool to get the callee of a function in the codebase by function name and file path.

opensage-agent/opensage-adk127—~223Automated safety check: PassApache-2.02 mo ago
137

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common…

trailofbits/skills7.4k—~1.1kAutomated safety check: NotesCC-BY-SA-4.0yesterday
138

Queries a local CodexQA symbol graph for change review, regression scope, test gaps, error location, and entry risk.

openqa-cn/codexqa152—~1.2kAutomated safety check: PassApache-2.06 days ago
139

Configure code scanning in Harness pipelines using STO security scanners.

harness/harness-skills115—~2.2kAutomated safety check: PassApache-2.02 days ago
140

Expertise in LLVM-based static analysis including dataflow analysis, pointer analysis, taint tracking, and program verification.

aftermathlabs/llvm-msvc438—~1.8kAutomated safety check: PassAGPL-3.05 days ago
141

Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

ArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.01 mo ago
142

Run a Snyk security scan of the repo (frontend npm deps, backend pip deps, Dockerfile/base image, and Snyk Code SAST), triage findings, and remediate the real ones with verified fixes.

bagofwords1/bagofwords459—~1.7kAutomated safety check: PassUnknowntoday
143

Run static analysis on Common Lisp projects with the Mallet command-line linter.

ultralisp/ultralisp258—~771Automated safety check: PassNo licence26 days ago
144

Classify project-used dependency members and record taint sources as rule-authoring units.

seqra/opentaint163—~1.7kAutomated safety check: PassApache-2.0today