Topic · Security

Best Static analysis and SAST skills, page 5

Skills #193–240 of 284, ranked by score.

Static analysis and SAST skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Static analysis and SAST skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
193
193.Clang

Clang/LLVM compiler skill for C/C++ projects. An agent skill from mohitmishra786/low-level-dev-skills.

mohitmishra786/low-level-dev-skills253—~1.4kAutomated safety check: PassMIT3 mo ago
194

A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint…

mtarcure/claude-vibe-squad164—~1.5kAutomated safety check: PassMIT18 days ago
195

Mobile (Android + iOS) application penetration testing methodology.

SnailSploit/Claude-Red7.4k—~3.5kAutomated safety check: PassMIT19 days ago
196

当需要对嵌入式 C/C++ 代码运行 cppcheck、clang-tidy 或 GCC analyzer 静态分析,或进行 MISRA-C 合规检查时使用。

LeoKemp223/embed-ai-tool987—~402Automated safety check: PassNo licence1 mo ago
197
197.Codeql

Use the open-source CodeQL ecosystem for .NET security analysis.

managedcode/dotnet-skills486—~1.1kAutomated safety check: PassMITtoday
198

Scan any agent skill for security risks before you install or use it.

LeoYeAI/openclaw-master-skills2.2k2 repos~3.7kAutomated safety check: PassMIT2 mo ago
199

Verter codebase architecture: high-level module map, TypeScript packages, plugin system, CSS analysis, MCP server, static analysis types

pikax/verter113—~5.6kAutomated safety check: PassMITtoday
200
200.Audit IntegrityOfficial

Enforce output quality, evidence verification, and quality gates across security audits.

github/awesome-copilot40k—~1kAutomated safety check: PassMITtoday
201

Connect the shared untrusted-data source group to new reusable OpenTaint sink groups.

seqra/opentaint163—~814Automated safety check: PassApache-2.0today
202

Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape.

alpha-omega-security/scrutineer239—~439Automated safety check: PassMITtoday
203

Complete workflow for static structural analysis. An agent skill from Cai-aa/CAE-Agent-Hub.

Cai-aa/CAE-Agent-Hub1k—~1.2kAutomated safety check: PassMIT9 days ago
204

Define analysis steps and procedures. An agent skill from Cai-aa/CAE-Agent-Hub.

Cai-aa/CAE-Agent-Hub1k—~1.2kAutomated safety check: PassMIT9 days ago
205

Detect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in parallel…

utkusen/sast-skills1.3k—~8.3kAutomated safety check: PassMIT6 mo ago
206

Validate Snyk SAST / Code findings against repo evidence; emits per-finding verdicts (CONFIRMED / FALSEPOSITIVE / NEEDSREVIEW / DUPLICATE / NOTAPPLICABLE).

epam/ai-dial-chat504—~1.2kAutomated safety check: PassApache-2.0today
207

Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills.

sickn33/agentic-awesome-skills47k2 repos~1.6kAutomated safety check: WarnMITtoday
208

Pull REAL Snyk SAST findings from EPAM Jira (Data Center) via the search-export API using a Personal Access Token, and emit them as a stage-output.json artifact for a downstream triage stage.

epam/ai-dial-chat504—~295Automated safety check: PassApache-2.0today
209

Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.01 mo ago
210

DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

modu-ai/moai-adk1.2k—~2.6kAutomated safety check: PassApache-2.0today
211

A skill your agent uses when conducting a frontend security review — static analysis (risky HTML patterns, env var exposure), authentication/authorization audit (token storage, route guards…

mizchi/skills359—~1.7kAutomated safety check: NotesNo licence7 days ago
212

Deep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing

alinaqi/maggy707—~2kAutomated safety check: PassMIT15 days ago
213

Debug a rule or approximation that behaves unexpectedly by tracing where taint is dropped.

seqra/opentaint163—~1.3kAutomated safety check: PassApache-2.0today
214

Run an OpenTaint scan on project and produces the SARIF report.

seqra/opentaint163—~1.1kAutomated safety check: PassApache-2.0today
215

Mark which of a project's dependency libraries could introduce taint sources.

seqra/opentaint163—~733Automated safety check: PassApache-2.0today
216

Drive static-analysis code quality in pi-agent-dashboard with Biome (analyze → fix → test), in changed-files or whole-repo mode.

BlackBeltTechnology/pi-agent-dashboard315—~1.3kAutomated safety check: PassMITtoday
217

Run an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API.

forcedotcom/sf-skills1.1k—~5.1kAutomated safety check: PassApache-2.02 days ago
218

Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App.

forcedotcom/sf-skills1.1k—~2kAutomated safety check: PassApache-2.02 days ago
219

Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

petrkindlmann/qa-skills168—~4.9kAutomated safety check: PassMIT4 mo ago
220

Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3…

utkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT6 mo ago
221

Use the open-source CodeQL ecosystem for .NET security analysis.

managedcode/Storage138—~977Automated safety check: PassMIT2 days ago
222

Use the open-source free Roslynator analyzer packages and optional CLI for .NET.

managedcode/Storage138—~1.2kAutomated safety check: PassMIT2 days ago
223

Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: WarnApache-2.01 mo ago
224

A skill your agent uses when you need to add or evaluate Maven dependencies that improve code quality or domain modeling — including nullness annotations (JSpecify), static analysis (Error Prone +…

jabrena/plinth447—~1.5kAutomated safety check: PassApache-2.02 days ago
225

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

BagelHole/DevOps-Security-Agent-Skills1.1k—~2.2kAutomated safety check: PassMIT4 mo ago
226

Run a CI-like pipeline locally (format, lint, vet, static-analysis, tests) and summarize per-step results with remediation guidance.

pilinux/gorest506—~388Automated safety check: PassMIT13 days ago
227
227.Glint

Conventions for authoring or editing analyzers in the glint/ Go static-analysis package — Speakeasy's custom golangci-lint plugin built on go/analysis.

speakeasy-api/gram273—~6.4kAutomated safety check: PassAGPL-3.0today
228

Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.

forcedotcom/sf-skills1.1k—~6.3kAutomated safety check: PassApache-2.02 days ago
229

Ghost Security - SAST code scanner. An agent skill from aAAaqwq/AGI-Super-Team.

aAAaqwq/AGI-Super-Team1051 repo~1.4kAutomated safety check: NotesApache-2.0yesterday
230

Write a self-contained OpenTaint engine-issue report from an analysis diagnosis or a full-scan failure.

seqra/opentaint163—~1.1kAutomated safety check: PassApache-2.0today
231

Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel…

utkusen/sast-skills1.3k—~6.7kAutomated safety check: PassMIT6 mo ago
232

Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user…

utkusen/sast-skills1.3k—~7.5kAutomated safety check: PassMIT6 mo ago
233

Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
234

Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to…

utkusen/sast-skills1.3k—~7.2kAutomated safety check: PassMIT6 mo ago
235

Run CI-aligned static analysis (vet, gosec, govulncheck) and convert findings into prioritized remediation steps.

pilinux/gorest506—~266Automated safety check: PassMIT13 days ago
236

Use the open-source free Roslynator analyzer packages and optional CLI for .NET.

managedcode/dotnet-skills486—~1.3kAutomated safety check: PassMITtoday
237

Decide whether a finding's suggested fix is a breaking change for top dependents.

alpha-omega-security/scrutineer239—~1.4kAutomated safety check: PassMITtoday
238

Draft operational mitigations for a finding consumers can apply before a fix ships.

alpha-omega-security/scrutineer239—~1.3kAutomated safety check: PassMITtoday
239

分析 Android 项目源码,用 LLM 从多维度生成 AI 自动化测试所需的先验知识文档,打包上报测试平台。核心价值:让 AI 测试 Agent 在运行前就知道「测什么、怎么断言、有哪些陷阱」。触发词:「分析我的 Android 项目」「生成测试画像」「理解这个 App 的业务」「提取测试先验知识」「帮我分析 Android 源码」

LeoYeAI/openclaw-master-skills2.2k—~2.7kAutomated safety check: PassMIT2 mo ago
240

Comprehensive code security audit with AI-powered vulnerability detection.

LeoYeAI/openclaw-master-skills2.2k—~3.7kAutomated safety check: NotesMIT2 mo ago