Topic · Security

Best Static analysis and SAST skills, page 6

Skills #241–284 of 284, ranked by score.

Static analysis and SAST skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Static analysis and SAST skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
241

Reviews a design or change for security before it ships — authentication and authorization, data handling, secrets, dependencies, and the secure-development practices around it.

cbrock84/headcount2k—~1.1kAutomated safety check: PassMIT21 days ago
242

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

BankrBot/skills1.2k—~858Automated safety check: PassNo licence3 days ago
243

A skill your agent uses when running Slither static analysis on Solidity contracts.

ccashwell/evm-cortex131—~1.5kAutomated safety check: PassMIT9 days ago
244

This skill should be used when analyzing binaries, executables, or bytecode to understand what they do or how they work.

aiskillstore/marketplace4301 repo~2.6kAutomated safety check: PassNo licencetoday
245

Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle

deonmenezes/mantishack504—~312Automated safety check: PassApache-2.05 days ago
246

Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices

Hack23/cia239—~1.7kAutomated safety check: PassApache-2.0today
247

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

ericrisco/rsc-harness174—~2.8kAutomated safety check: NotesMITyesterday
248

Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

ccplugins/awesome-claude-code-plugins970—~486Automated safety check: NotesApache-2.01 mo ago
249

Validate API consistency between two versions of Java libraries.

ArabelaTso/Skills-4-SE253—~660Automated safety check: PassApache-2.01 mo ago
250

Validate API consistency between two versions of Python libraries.

ArabelaTso/Skills-4-SE253—~609Automated safety check: PassApache-2.01 mo ago
251

Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
252

MCP server security registry and trust assessment — look up servers in the 427+ server security metadata registry, run pre-install marketplace checks, batch fleet risk scoring, assess skill file…

LeoYeAI/openclaw-master-skills2.2k—~969Automated safety check: PassApache-2.02 mo ago
253

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT2 mo ago
254

Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases.

LeoYeAI/openclaw-master-skills2.2k—~5.1kAutomated safety check: PassApache-2.02 mo ago
255

CI/CD pipeline security gate design guide. An agent skill from revfactory/harness-100.

revfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.06 mo ago
256

Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~750Automated safety check: NotesMITtoday
257

Static analysis skill for C/C++ codebases. An agent skill from mohitmishra786/low-level-dev-skills.

mohitmishra786/low-level-dev-skills253—~1.4kAutomated safety check: PassMIT3 mo ago
258

Guide for resolving NullAway static analysis errors. An agent skill from nwjs/chromium.src.

nwjs/chromium.src160—~3kAutomated safety check: PassBSD-3-Clause5 days ago
259

Generate abstract Control Flow Graph (CFG) representations of programs showing loops, branches, and function calls for static analysis or verification.

ArabelaTso/Skills-4-SE253—~2.8kAutomated safety check: PassApache-2.01 mo ago
260

Analyze source code statically to detect potential functional bugs including null dereferences, incorrect condition checks, unreachable code, inconsistent state updates, logic errors, resource…

ArabelaTso/Skills-4-SE253—~3.4kAutomated safety check: PassApache-2.01 mo ago
261

Applies abstract interpretation using different abstract domains (intervals, octagons, polyhedra, sign, congruence) to statically analyze program variables and infer invariants, value ranges, and…

ArabelaTso/Skills-4-SE253—~2.4kAutomated safety check: PassApache-2.01 mo ago
262

Performs abstract interpretation over source code to infer possible program states, variable ranges, and data properties without executing the program.

ArabelaTso/Skills-4-SE253—~1.8kAutomated safety check: PassApache-2.01 mo ago
263

Explain why counterexamples violate specifications by analyzing formal specifications (temporal logic, invariants, pre/postconditions, code contracts), informal requirements (user stories…

ArabelaTso/Skills-4-SE253—~3.5kAutomated safety check: PassApache-2.01 mo ago
264

Subagent for figma-from-code Phase 0b. An agent skill from bitovi/ai-enablement-prompts.

bitovi/ai-enablement-prompts121—~1.4kAutomated safety check: PassMIT28 days ago
265

Security vulnerability scanner and OWASP compliance auditor for codebases.

curiositech/some_claude_skills243—~2.2kAutomated safety check: PassMIT1 mo ago
266

Maintainer workflow for the pre-PR secure loop: code, build/test, SAST/CodeQL, dynamic sanitizer checks, fixes, and concise handoff.

InternationalColorConsortium/iccDEV183—~1.4kAutomated safety check: PassBSD-3-Clausetoday
267

Reverse-engineer any website's, repo's, or local project's design system into a Claude-ready skill via the SkillUI CLI.

CraftOS-dev/CraftBot392—~1.2kAutomated safety check: PassMITtoday
268

Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy

Hack23/cia239—~5.8kAutomated safety check: PassApache-2.0today
269

Identify performance bottlenecks, inefficient patterns, and optimization opportunities through static analysis.

EmeaAppGbb/spec2cloud100—~2.2kAutomated safety check: PassMIT5 mo ago
270

Configure PHP ecosystem tooling, dependency management, and static analysis.

HoangNguyen0403/agent-skills-standard571—~615Automated safety check: PassMITtoday
271

Tool to get the program slice for a given function using Joern.

opensage-agent/opensage-adk127—~189Automated safety check: PassApache-2.02 mo ago
272

Tool to search for a function in the codebase. An agent skill from opensage-agent/opensage-adk.

opensage-agent/opensage-adk127—~153Automated safety check: PassApache-2.02 mo ago
273

Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…

sundial-org/awesome-openclaw-skills663—~875Automated safety check: PassNo licence7 mo ago
274

For a batch of findings from a non-security audit tool (<audit-tool — ruff / flake8 / mypy / pylint / CodeQL / Apache Verum / Apache Caer / equivalent; full list in the body) against <upstream…

apache/magpie113—~4.9kAutomated safety check: PassApache-2.0today
275

A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now…

OneWave-AI/claude-skills328—~836Automated safety check: PassMIT7 days ago
276

Perform a broad, authorized security audit across application, infrastructure, identity, dependencies, and operations.

seb1n/awesome-ai-agent-skills206—~2.4kAutomated safety check: NotesMIT2 mo ago
277

Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

seb1n/awesome-ai-agent-skills206—~2.6kAutomated safety check: PassMIT2 mo ago
278

This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work…

bitwarden/ai-plugins154—~2.2kAutomated safety check: PassUnknowntoday
279

安全自动化顶级专业技能:DevSecOps全流程集成、CI/CD安全管道、SAST/DAST/SCA/容器/IaC自动化扫描编排、安全工具链集成实战、攻防双视角自动化(红队打点/蓝队检测响应)、SOAR深度编排、Agentic AI安全自动化(LLM Agent编排扫描与响应)、大模型安全运营(AI告警降噪/剧本生成)、误报治理与质量保障、合规自动化(证据收集/报告)

langbyyi/CyberStrikeAI-SRC135—~6kAutomated safety check: PassApache-2.0yesterday
280

A skill your agent uses when auditing an Anchor or bare-Rust Solana program end to end; because Solana ships no static analyzers, the coverage strategy is compiler-warning triage, manual source…

mtarcure/claude-vibe-squad164—~1.4kAutomated safety check: PassMIT18 days ago
281

MASTER SECURITY: OWASP Top 10, SAST/DAST, PenTest. An agent skill from Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI.

Dokhacgiakhoa/Agent-Skills-4-Vibe-Coding-CLI508—~440Automated safety check: PassUnknown4 mo ago
282

DevSecOps, secure software development lifecycle (SSDLC), and application security (AppSec) practices covering secret handling, input validation, dependency hygiene, authentication/authorization…

Mindrally/skills269—~2.2kAutomated safety check: NotesApache-2.0today
283

Run code quality tools: PHP-CS-Fixer for style, PHPStan for static analysis, and type safety checks

dev-toolings/superpowers-symfony223—~381Automated safety check: NotesMIT3 days ago
284

CI/CD 파이프라인 보안 게이트 설계 가이드. An agent skill from revfactory/harness-100.

revfactory/harness-1001.3k—~1.1kAutomated safety check: PassApache-2.06 mo ago