Topic · Security

Best Static analysis and SAST skills, page 4

Skills #145–192 of 284, ranked by score.

Static analysis and SAST skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Static analysis and SAST skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
145

Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates.

utkusen/sast-skills1.3k—~6.5kAutomated safety check: NotesMIT6 mo ago
146

Automatic quality control, linting, and static analysis procedures.

xenitV1/Antigravity-Workflows1306 repos~432Automated safety check: NotesMIT8 mo ago
147
147.CodeqlOfficial

Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

github/awesome-copilot40k1 repo~3.4kAutomated safety check: PassMITtoday
148
148.Lint

Run and fix the repository static analysis suite. An agent skill from ethereum/execution-specs.

ethereum/execution-specs1.2k—~286Automated safety check: PassCC0-1.0today
149

Tool to get the caller of a function in the codebase. An agent skill from opensage-agent/opensage-adk.

opensage-agent/opensage-adk127—~208Automated safety check: PassApache-2.02 mo ago
150
150.Variant AnalysisOfficial

Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.

trailofbits/skills7.4k—~967Automated safety check: PassCC-BY-SA-4.0yesterday
151

Reproduce a true-positive finding against the running application.

seqra/opentaint163—~1.5kAutomated safety check: PassApache-2.0today
152
152.Aif CI

Generate CI/CD pipeline (GitHub Actions / GitLab CI) with linting, static analysis, tests, security.

unxed/f4241—~4.7kAutomated safety check: PassBSD-3-Clausetoday
153

Detect insecure JWT (JSON Web Token) implementations in a codebase using a two-phase approach: first map all JWT issuance and verification sites to understand the token lifecycle and signing…

utkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT6 mo ago
154
154.Developer SecurityOfficial

Security best practices for gh-aw workflows and Go code: template injection prevention, shell script security, supply chain hardening, and static analysis integration.

github/gh-aw5.4k—~2.8kAutomated safety check: PassMITtoday
155

A skill your agent uses when scanning source code for bugs, anti-patterns, code smells, or quality issues in a codebase, or when running a proof-driven bug hunt that must find, prove, fix, and…

WrongStack/WrongStack370—~3.7kAutomated safety check: PassMITtoday
156

全面的代码安全检查和服务器安全审计skill。适用于:(1) 代码漏洞扫描 - 检测SQL注入、XSS、SSRF等OWASP Top 10漏洞,(2) 依赖安全检查 - 识别过时或有漏洞的第三方库,结合实时搜索确认最新CVE,(3) 服务器配置审计 - 检查SSH、防火墙、权限等安全配置,(4) 敏感信息泄露检测 - API密钥、密码、令牌等硬编码检测,(5) 容器安全扫描 -…

staruhub/ClaudeSkills727—~1.3kAutomated safety check: NotesMIT1 mo ago
157

Standardized compiler diagnostics, static analysis lints, and automated IDE quick-fixes.

rodydavis/signals.dart819—~712Automated safety check: PassApache-2.025 days ago
158

Automated code review and security linting integration for CI/CD pipelines using reviewdog.

AgentSecOps/SecOpsAgentKit2201 repo~3kAutomated safety check: PassUnknown5 mo ago
159

Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.

AgentSecOps/SecOpsAgentKit2201 repo~2.6kAutomated safety check: PassUnknown5 mo ago
160

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory…

unxed/f42412 repos~3.6kAutomated safety check: PassMITtoday
161

Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
162

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
163

Performs automated static analysis of Android applications using Mobile Security Framework (MobSF) to identify hardcoded secrets, insecure permissions, vulnerable components, weak cryptography, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
164

A skill your agent uses when preparing a codebase for security audit.

ccashwell/evm-cortex131—~1.4kAutomated safety check: PassMIT9 days ago
165

Reverse engineer binaries with IDA Pro: decompilation, disassembly, data-flow tracking, cross-references, and IDA MCP automation for deep static analysis of PE/ELF/Mach-O targets.

sickn33/agentic-awesome-skills47k1 repo~3.1kAutomated safety check: PassMITtoday
166

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript, shellcode, and suspicious objects.

mukul975/Anthropic-Cybersecurity-Skills34k—~799Automated safety check: PassApache-2.01 mo ago
167

Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
168

Implements API Security Posture Management (API-SPM) to continuously discover, classify, and risk-score APIs -- including internal, external, partner, and shadow endpoints -- while aggregating…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.01 mo ago
169

Implements API security testing on the 42Crunch platform, combining API Audit for static analysis of OpenAPI definitions, API Conformance Scan for dynamic vulnerability testing, and API Protect for…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
170

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
171

Perform interactive dynamic malware analysis using the ANY.RUN cloud sandbox to detonate samples, observe real-time execution behavior, interact with malware prompts such as dialogs and CAPTCHAs…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
172

Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
173

Performs static analysis of Windows PE malware samples using PEStudio to examine file headers, imports, strings, and resources without executing the binary, identifying packing, anti-analysis…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.01 mo ago
174

Validates Google Ads Query Language (GAQL) queries via 4-step static analysis and live API dry-runs.

googleads/google-ads-api-developer-assistant100—~225Automated safety check: PassApache-2.022 days ago
175

Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach: recon (map endpoints and the role/permission system), batched verify…

utkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT6 mo ago
176

A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments.

alirezarezvani/claude-skills28k—~3.5kAutomated safety check: PassMIT1 mo ago
177

Implementing multi-layer security scanning (container, SAST, DAST, SCA, secrets), SBOM generation, and risk-based vulnerability prioritization in CI/CD pipelines.

ancoleman/ai-design-components526—~3.8kAutomated safety check: PassMIT10 mo ago
178

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

vibeeval/vibecosystem531—~4.6kAutomated safety check: PassMIT2 mo ago
179

Scan C source files for hard-to-test static dependencies — DateTime.Now/UtcNow, File., Directory., Environment., HttpClient, Console., Process., and other untestable statics.

microsoft/testfx1k—~1.9kAutomated safety check: PassMITtoday
180

Security vulnerability detection and variant analysis skill.

sendaifun/skills1301 repo~2.3kAutomated safety check: PassApache-2.02 mo ago
181

Build a CodeQL database and run dataflow-backed query-suite analysis via the mantiscodeql MCP server

deonmenezes/mantishack504—~325Automated safety check: PassApache-2.06 days ago
182

Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification.

sickn33/agentic-awesome-skills47k1 repo~480Automated safety check: PassMITtoday
183

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

sickn33/agentic-awesome-skills47k1 repo~2.4kAutomated safety check: PassMITtoday
184

Diagnose and optimize Agent Skills (SKILL.md) with real session data and research-backed static analysis.

sickn33/agentic-awesome-skills47k1 repo~3kAutomated safety check: PassMITtoday
185

Triage OpenTaint findings statically. An agent skill from seqra/opentaint.

seqra/opentaint163—~1.3kAutomated safety check: PassApache-2.0today
186

Detect path traversal vulnerabilities in a codebase using a three-phase approach: recon (find file-loading sinks with dynamic paths), batched verify (trace user input and mitigations in parallel…

utkusen/sast-skills1.3k—~6.8kAutomated safety check: PassMIT6 mo ago
187

You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices.

aiskillstore/marketplace4307 repos~3.9kAutomated safety check: PassNo licencetoday
188

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

aiskillstore/marketplace4307 repos~3.7kAutomated safety check: PassNo licencetoday
189

Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection, dangerous permission-combination…

mukul975/Anthropic-Cybersecurity-Skills34k—~620Automated safety check: PassApache-2.01 mo ago
190

Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
191

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
192

This skill covers analyzing Programmable Logic Controller (PLC) firmware for security vulnerabilities including hardcoded credentials, insecure update mechanisms, backdoor functions, memory…

mukul975/Anthropic-Cybersecurity-Skills34k—~4.9kAutomated safety check: PassApache-2.01 mo ago