Topic · Security
Best Static analysis and SAST skills, page 6
Static analysis and SAST skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 241 | Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it. | cbrock84/ | 2k | — | ~1.1k | Automated safety check: Pass | MIT | 21 days ago |
| 242 | Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed… | BankrBot/ | 1.2k | — | ~858 | Automated safety check: Pass | No licence | 3 days ago |
| 243 | 243.Slither Analysis A skill your agent uses when running Slither static analysis on Solidity contracts. | ccashwell/ | 131 | — | ~1.5k | Automated safety check: Pass | MIT | 9 days ago |
| 244 | 244.Binary Re This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work. | aiskillstore/ | 430 | 1 repo | ~2.6k | Automated safety check: Pass | No licence | today |
| 245 | 245.Semgrep Triage Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle | deonmenezes/ | 504 | — | ~312 | Automated safety check: Pass | Apache-2.0 | 5 days ago |
| 246 | Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices | Hack23/ | 239 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | today |
| 247 | 247.Security Scan A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 174 | — | ~2.8k | Automated safety check: Notes | MIT | yesterday |
| 248 | 248.Sicurezza GitHub Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot. | ccplugins/ | 970 | — | ~486 | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 249 | Validate API consistency between two versions of Java libraries. | ArabelaTso/ | 253 | — | ~660 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 250 | Validate API consistency between two versions of Python libraries. | ArabelaTso/ | 253 | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 251 | Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters. | cyberful/ | 135 | — | ~1.1k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 252 | MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file… | LeoYeAI/ | 2.2k | — | ~969 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 253 | 253.Clawsec Scanner Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 254 | 254.Phy Regex Audit Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. | LeoYeAI/ | 2.2k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 255 | CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 256 | 256.Warden Scan Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~750 | Automated safety check: Notes | MIT | today |
| 257 | 257.Static Analysis Static analysis skill for C/C++ codebases. An agent skill from mohitmishra786/low-level-dev-skills. | mohitmishra786/ | 253 | — | ~1.4k | Automated safety check: Pass | MIT | 3 mo ago |
| 258 | 258.Nullaway Guide for resolving NullAway static analysis errors. An agent skill from nwjs/chromium.src. | nwjs/ | 160 | — | ~3k | Automated safety check: Pass | BSD-3-Clause | 5 days ago |
| 259 | Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification. | ArabelaTso/ | 253 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 260 | Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource… | ArabelaTso/ | 253 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 261 | Applies abstract interpretation using different abstract domains (intervals, octagons, polyhedra, sign, congruence) to statically analyze program variables and infer invariants, value ranges, and… | ArabelaTso/ | 253 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 262 | Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program. | ArabelaTso/ | 253 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 263 | Explain why counterexamples violate specifications by analyzing formal specifications (temporal logic, invariants, pre/postconditions, code contracts), informal requirements (user stories… | ArabelaTso/ | 253 | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 264 | Subagent for figma-from-code Phase 0b. An agent skill from bitovi/ai-enablement-prompts. | bitovi/ | 121 | — | ~1.4k | Automated safety check: Pass | MIT | 28 days ago |
| 265 | 265.Security Auditor Security vulnerability scanner and OWASP compliance auditor for codebases. | curiositech/ | 243 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 266 | Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff. | InternationalColorConsortium/ | 183 | — | ~1.4k | Automated safety check: Pass | BSD-3-Clause | today |
| 267 | 267.Skillui Reverse-engineer any website's, repo's, or local project's design system into a Claude-ready skill via the SkillUI CLI. | CraftOS-dev/ | 392 | — | ~1.2k | Automated safety check: Pass | MIT | today |
| 268 | Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy | Hack23/ | 239 | — | ~5.8k | Automated safety check: Pass | Apache-2.0 | today |
| 269 | Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis. | EmeaAppGbb/ | 100 | — | ~2.2k | Automated safety check: Pass | MIT | 5 mo ago |
| 270 | 270.Php Tooling Configure PHP ecosystem tooling, dependency management, and static analysis. | HoangNguyen0403/ | 571 | — | ~615 | Automated safety check: Pass | MIT | today |
| 271 | 271.Joern Slice Tool to get the program slice for a given function using Joern. | opensage-agent/ | 127 | — | ~189 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 272 | 272.Search Function Tool to search for a function in the codebase. An agent skill from opensage-agent/opensage-adk. | opensage-agent/ | 127 | — | ~153 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 273 | 273.Security Audit 2 Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or… | sundial-org/ | 663 | — | ~875 | Automated safety check: Pass | No licence | 7 mo ago |
| 274 | For a batch of findings from a non-security audit tool (<audit-tool — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer / equivalent; full list in the body) against <upstream… | apache/ | 113 | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | today |
| 275 | A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now… | OneWave-AI/ | 328 | — | ~836 | Automated safety check: Pass | MIT | 7 days ago |
| 276 | 276.Security Audit Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations. | seb1n/ | 206 | — | ~2.4k | Automated safety check: Notes | MIT | 2 mo ago |
| 277 | Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. | seb1n/ | 206 | — | ~2.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 278 | This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work… | bitwarden/ | 154 | — | ~2.2k | Automated safety check: Pass | Unknown | today |
| 279 | 安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告) | langbyyi/ | 135 | — | ~6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 280 | A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source… | mtarcure/ | 164 | — | ~1.4k | Automated safety check: Pass | MIT | 18 days ago |
| 281 | 281.Security Auditor MASTER SECURITY: OWASP Top 10, SAST/DAST, PenTest. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI. | Dokhacgiakhoa/ | 508 | — | ~440 | Automated safety check: Pass | Unknown | 4 mo ago |
| 282 | DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization… | Mindrally/ | 269 | — | ~2.2k | Automated safety check: Notes | Apache-2.0 | today |
| 283 | 283.Quality Checks Run code quality tools: PHP-CS-Fixer for style, PHPStan for static analysis, and type safety checks | dev-toolings/ | 223 | — | ~381 | Automated safety check: Notes | MIT | 3 days ago |
| 284 | CI/CD 파이프라인 보안 게이트 설계 가이드. An agent skill from revfactory/harness-100. | revfactory/ | 1.3k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
Explore related skills
Category
More topics in Security
- Security review637
- Web application vulnerabilities468
- Vulnerability scanning305
- Security operations246
- Supply chain security232
- Threat modeling227
- Penetration testing181
- Cryptography160
- Prompt injection and agent security154
- Red teaming and adversary simulation149
- Reverse engineering and malware129
- OSINT120
- Secure coding113
- Cloud security96
- Digital forensics88
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38