Topic · Security
Best Static analysis and SAST skills, page 4
Static analysis and SAST skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 145 | Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. | utkusen/ | 1.3k | — | ~6.5k | Automated safety check: Notes | MIT | 6 mo ago |
| 146 | Automatic quality control, linting, and static analysis procedures. | xenitV1/ | 130 | 6 repos | ~432 | Automated safety check: Notes | MIT | 8 mo ago |
| 147 | Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI. | github/ | 40k | 1 repo | ~3.4k | Automated safety check: Pass | MIT | today |
| 148 | 148.Lint Run and fix the repository static analysis suite. An agent skill from ethereum/execution-specs. | ethereum/ | 1.2k | — | ~286 | Automated safety check: Pass | CC0-1.0 | today |
| 149 | 149.Get Caller Tool to get the caller of a function in the codebase. An agent skill from opensage-agent/opensage-adk. | opensage-agent/ | 127 | — | ~208 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 150 | Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. | trailofbits/ | 7.4k | — | ~967 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 151 | 151.Generate Poc Reproduce a true-positive finding against the running application. | seqra/ | 163 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 152 | 152.Aif CI Generate CI/CD pipeline (GitHub Actions / GitLab CI) with linting, static analysis, tests, security. | unxed/ | 241 | — | ~4.7k | Automated safety check: Pass | BSD-3-Clause | today |
| 153 | 153.Sast JWT Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 154 | Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration. | github/ | 5.4k | — | ~2.8k | Automated safety check: Pass | MIT | today |
| 155 | 155.Bug Hunter A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and… | WrongStack/ | 370 | — | ~3.7k | Automated safety check: Pass | MIT | today |
| 156 | 156.Security Audit 全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -… | staruhub/ | 727 | — | ~1.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 157 | 157.Signals Lint Standardized compiler diagnostics, static analysis lints, and automated IDE quick-fixes. | rodydavis/ | 819 | — | ~712 | Automated safety check: Pass | Apache-2.0 | 25 days ago |
| 158 | 158.Reviewdog Automated code review and security linting integration for CI/CD pipelines using reviewdog. | AgentSecOps/ | 220 | 1 repo | ~3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 159 | 159.Sast Bandit Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. | AgentSecOps/ | 220 | 1 repo | ~2.6k | Automated safety check: Pass | Unknown | 5 mo ago |
| 160 | 160.Golang Security Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory… | unxed/ | 241 | 2 repos | ~3.6k | Automated safety check: Pass | MIT | today |
| 161 | Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 162 | Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 163 | Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and… | mukul975/ | 34k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 164 | 164.Audit Prep A skill your agent uses when preparing a codebase for security audit. | ccashwell/ | 131 | — | ~1.4k | Automated safety check: Pass | MIT | 9 days ago |
| 165 | 165.Ida Reverse Reverse engineer binaries with IDA Pro: decompilation, disassembly, data-flow tracking, cross-references, and IDA MCP automation for deep static analysis of PE/ELF/Mach-O targets. | sickn33/ | 47k | 1 repo | ~3.1k | Automated safety check: Pass | MIT | today |
| 166 | Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects. | mukul975/ | 34k | — | ~799 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 167 | Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 168 | Implements API Security Posture Management (API-SPM) to continuously discover, classify, and risk-score APIs -- including internal, external, partner, and shadow endpoints -- while aggregating… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 169 | Implements API security testing on the 42Crunch platform, combining API Audit for static analysis of OpenAPI definitions, API Conformance Scan for dynamic vulnerability testing, and API Protect for… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 170 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 171 | Perform interactive dynamic malware analysis using the ANY.RUN cloud sandbox to detonate samples, observe real-time execution behavior, interact with malware prompts such as dialogs and CAPTCHAs… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 172 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 173 | Performs static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, and resources without executing the binary, identifying packing, anti-analysis… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 174 | 174.Validate Gaql Validates Google Ads Query Language (GAQL) queries via 4-step static analysis and live API dry-runs. | googleads/ | 100 | — | ~225 | Automated safety check: Pass | Apache-2.0 | 22 days ago |
| 175 | 175.Sast Missingauth Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 176 | A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. | alirezarezvani/ | 28k | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 177 | Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines. | ancoleman/ | 526 | — | ~3.8k | Automated safety check: Pass | MIT | 10 mo ago |
| 178 | 178.Sast Patterns Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. | vibeeval/ | 531 | — | ~4.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 179 | Scan C source files for hard-to-test static dependencies — DateTime.Now/UtcNow, File., Directory., Environment., HttpClient, Console., Process., and other untestable statics. | microsoft/ | 1k | — | ~1.9k | Automated safety check: Pass | MIT | today |
| 180 | 180.Vulnhunter Security vulnerability detection and variant analysis skill. | sendaifun/ | 130 | 1 repo | ~2.3k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 181 | 181.Codeql Audit Build a CodeQL database and run dataflow-backed query-suite analysis via the mantiscodeql MCP server | deonmenezes/ | 504 | — | ~325 | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 182 | 182.Code Audit Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification. | sickn33/ | 47k | 1 repo | ~480 | Automated safety check: Pass | MIT | today |
| 183 | 183.Sast Scanning Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | today |
| 184 | 184.Skill Optimizer Diagnose and optimize Agent Skills (SKILL.md) with real session data and research-backed static analysis. | sickn33/ | 47k | 1 repo | ~3k | Automated safety check: Pass | MIT | today |
| 185 | 185.Analyze Findings Triage OpenTaint findings statically. An agent skill from seqra/opentaint. | seqra/ | 163 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 186 | Detect path traversal vulnerabilities in a codebase using a three-phase approach: recon (find file-loading sinks with dynamic paths), batched verify (trace user input and mitigations in parallel… | utkusen/ | 1.3k | — | ~6.8k | Automated safety check: Pass | MIT | 6 mo ago |
| 187 | You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices. | aiskillstore/ | 430 | 7 repos | ~3.9k | Automated safety check: Pass | No licence | today |
| 188 | Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks | aiskillstore/ | 430 | 7 repos | ~3.7k | Automated safety check: Pass | No licence | today |
| 189 | Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination… | mukul975/ | 34k | — | ~620 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 190 | Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 191 | Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 192 | This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory… | mukul975/ | 34k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
Explore related skills
Category
More topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38