Topic · Security
Best Static analysis and SAST skills, page 5
Static analysis and SAST skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 193 | 193.Clang Clang/LLVM compiler skill for C/C++ projects. An agent skill from mohitmishra786/low-level-dev-skills. | mohitmishra786/ | 253 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 194 | 194.Evm Audit Flow A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint… | mtarcure/ | 164 | — | ~1.5k | Automated safety check: Pass | MIT | 18 days ago |
| 195 | 195.Offensive Mobile Mobile (Android + iOS) application penetration testing methodology. | SnailSploit/ | 7.4k | — | ~3.5k | Automated safety check: Pass | MIT | 19 days ago |
| 196 | 196.Static Analysis 当需要对嵌入式 C/C++ 代码运行 cppcheck、clang-tidy 或 GCC analyzer 静态分析,或进行 MISRA-C 合规检查时使用。 | LeoKemp223/ | 987 | — | ~402 | Automated safety check: Pass | No licence | 1 mo ago |
| 197 | 197.Codeql Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 486 | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 198 | 198.Skill Scanner Scan any agent skill for security risks before you install or use it. | LeoYeAI/ | 2.2k | 2 repos | ~3.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 199 | 199.Architecture Verter codebase architecture: high-level module map, TypeScript packages, plugin system, CSS analysis, MCP server, static analysis types | pikax/ | 113 | — | ~5.6k | Automated safety check: Pass | MIT | today |
| 200 | Enforce output quality, evidence verification, and quality gates across security audits. | github/ | 40k | — | ~1k | Automated safety check: Pass | MIT | today |
| 201 | Connect the shared untrusted-data source group to new reusable OpenTaint sink groups. | seqra/ | 163 | — | ~814 | Automated safety check: Pass | Apache-2.0 | today |
| 202 | 202.Semgrep Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape. | alpha-omega-security/ | 239 | — | ~439 | Automated safety check: Pass | MIT | today |
| 203 | Complete workflow for static structural analysis. An agent skill from Cai-aa/CAE-Agent-Hub. | Cai-aa/ | 1k | — | ~1.2k | Automated safety check: Pass | MIT | 9 days ago |
| 204 | 204.Abaqus Step Define analysis steps and procedures. An agent skill from Cai-aa/CAE-Agent-Hub. | Cai-aa/ | 1k | — | ~1.2k | Automated safety check: Pass | MIT | 9 days ago |
| 205 | 205.Sast Rce Detect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in parallel… | utkusen/ | 1.3k | — | ~8.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 206 | 206.Snyk Triage Validate Snyk SAST / Code findings against repo evidence; emits per-finding verdicts (CONFIRMED / FALSEPOSITIVE / NEEDSREVIEW / DUPLICATE / NOTAPPLICABLE). | epam/ | 504 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | today |
| 207 | 207.Audit Skills Expert security auditor for AI Skills and Bundles. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~1.6k | Automated safety check: Warn | MIT | today |
| 208 | 208.Snyk Jira Ingest Pull REAL Snyk SAST findings from EPAM Jira (Data Center) via the search-export API using a Personal Access Token, and emit them as a stage-output.json artifact for a downstream triage stage. | epam/ | 504 | — | ~295 | Automated safety check: Pass | Apache-2.0 | today |
| 209 | Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 210 | 210.Moai Ref Secops DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | today |
| 211 | A skill your agent uses when conducting a frontend security review — static analysis (risky HTML patterns, env var exposure), authentication/authorization audit (token storage, route guards… | mizchi/ | 359 | — | ~1.7k | Automated safety check: Notes | No licence | 7 days ago |
| 212 | 212.Cpg Analysis Deep code property graph analysis with Joern CPG (AST+CFG+PDG) and CodeQL for control flow, data flow, taint analysis, and security auditing | alinaqi/ | 707 | — | ~2k | Automated safety check: Pass | MIT | 15 days ago |
| 213 | 213.Debug Rule Debug a rule or approximation that behaves unexpectedly by tracing where taint is dropped. | seqra/ | 163 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | today |
| 214 | 214.Run Scan Run an OpenTaint scan on project and produces the SARIF report. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 215 | Mark which of a project's dependency libraries could introduce taint sources. | seqra/ | 163 | — | ~733 | Automated safety check: Pass | Apache-2.0 | today |
| 216 | 216.Code Quality Drive static-analysis code quality in pi-agent-dashboard with Biome (analyze → fix → test), in changed-files or whole-repo mode. | BlackBeltTechnology/ | 315 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 217 | 217.Dx Apexguru Scan Run an ApexGuru performance scan on a Salesforce Apex project via the ApexGuru SFAP Scan API. | forcedotcom/ | 1.1k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 218 | Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App. | forcedotcom/ | 1.1k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 219 | 219.Security Testing Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests… | petrkindlmann/ | 168 | — | ~4.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 220 | 220.Sast Sqli Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3… | utkusen/ | 1.3k | — | ~6k | Automated safety check: Pass | MIT | 6 mo ago |
| 221 | Use the open-source CodeQL ecosystem for .NET security analysis. | managedcode/ | 138 | — | ~977 | Automated safety check: Pass | MIT | 2 days ago |
| 222 | Use the open-source free Roslynator analyzer packages and optional CLI for .NET. | managedcode/ | 138 | — | ~1.2k | Automated safety check: Pass | MIT | 2 days ago |
| 223 | Analyze malicious Linux ELF binaries — botnets, cryptominers, ransomware, and rootkits targeting Linux servers, containers, and cloud infrastructure — through static analysis, dynamic tracing, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 224 | A skill your agent uses when you need to add or evaluate Maven dependencies that improve code quality or domain modeling — including nullness annotations (JSpecify), static analysis (Error Prone +… | jabrena/ | 447 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 225 | 225.Sast Scanning Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | BagelHole/ | 1.1k | — | ~2.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 226 | 226.CI Orchestrator Run a CI-like pipeline locally (format, lint, vet, static-analysis, tests) and summarize per-step results with remediation guidance. | pilinux/ | 506 | — | ~388 | Automated safety check: Pass | MIT | 13 days ago |
| 227 | 227.Glint Conventions for authoring or editing analyzers in the glint/ Go static-analysis package — Speakeasy's custom golangci-lint plugin built on go/analysis. | speakeasy-api/ | 273 | — | ~6.4k | Automated safety check: Pass | AGPL-3.0 | today |
| 228 | Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations. | forcedotcom/ | 1.1k | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 229 | 229.Ghost Scan Code Ghost Security - SAST code scanner. An agent skill from aAAaqwq/AGI-Super-Team. | aAAaqwq/ | 105 | 1 repo | ~1.4k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 230 | Write a self-contained OpenTaint engine-issue report from an analysis diagnosis or a full-scan failure. | seqra/ | 163 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 231 | 231.Sast Ssrf Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel… | utkusen/ | 1.3k | — | ~6.7k | Automated safety check: Pass | MIT | 6 mo ago |
| 232 | 232.Sast Ssti Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user… | utkusen/ | 1.3k | — | ~7.5k | Automated safety check: Pass | MIT | 6 mo ago |
| 233 | 233.Sast Xss Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 234 | 234.Sast Xxe Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to… | utkusen/ | 1.3k | — | ~7.2k | Automated safety check: Pass | MIT | 6 mo ago |
| 235 | 235.Static Analysis Run CI-aligned static analysis (vet, gosec, govulncheck) and convert findings into prioritized remediation steps. | pilinux/ | 506 | — | ~266 | Automated safety check: Pass | MIT | 13 days ago |
| 236 | 236.Roslynator Use the open-source free Roslynator analyzer packages and optional CLI for .NET. | managedcode/ | 486 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 237 | 237.Breaking Change Decide whether a finding's suggested fix is a breaking change for top dependents. | alpha-omega-security/ | 239 | — | ~1.4k | Automated safety check: Pass | MIT | today |
| 238 | 238.Mitigate Draft operational mitigations for a finding consumers can apply before a fix ships. | alpha-omega-security/ | 239 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 239 | 分析 Android 项目源码,用 LLM 从多维度生成 AI 自动化测试所需的先验知识文档,打包上报测试平台。核心价值:让 AI 测试 Agent 在运行前就知道「测什么、怎么断言、有哪些陷阱」。触发词:「分析我的 Android 项目」「生成测试画像」「理解这个 App 的业务」「提取测试先验知识」「帮我分析 Android 源码」 | LeoYeAI/ | 2.2k | — | ~2.7k | Automated safety check: Pass | MIT | 2 mo ago |
| 240 | Comprehensive code security audit with AI-powered vulnerability detection. | LeoYeAI/ | 2.2k | — | ~3.7k | Automated safety check: Notes | MIT | 2 mo ago |
Explore related skills
More topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38