Skip to content
Back to skills

Security Scanning Security Sast

ASecurity

Static Application Security Testing (SAST) for code vulnerability

  • 508 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
developmentjavascripttypescriptpythonrustgojavarubyphpsqlreact

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 17 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add Dokhacgiakhoa/antigravity-ide --skill security-scanning-security-sast --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Security Scanning Security Sast?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Security Scanning Security Sast
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dokhacgiakhoa-security-scanning-security-sast/badge)](https://www.skillsdirectory.com/skills/dokhacgiakhoa-security-scanning-security-sast)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
version: 4.1.0-fractal
name: security-scanning-security-sast
description: Static Application Security Testing (SAST) for code vulnerability
  analysis across multiple languages and frameworks
metadata:
  globs: "**/*.py, **/*.js, **/*.ts, **/*.java, **/*.rb, **/*.go, **/*.rs, **/*.php"
  keywords: sast, static analysis, code security, vulnerability scanning, bandit,
    semgrep, eslint, sonarqube, codeql, security patterns, code review, ast
    analysis
---
# SAST Security Plugin

Static Application Security Testing (SAST) for comprehensive code vulnerability detection across multiple languages, frameworks, and security patterns.

## Capabilities

- **Multi-language SAST**: Python, JavaScript/TypeScript, Java, Ruby, PHP, Go, Rust
- **Tool integration**: Bandit, Semgrep, ESLint Security, SonarQube, CodeQL, PMD, SpotBugs, Brakeman, gosec, cargo-clippy
- **Vulnerability patterns**: SQL injection, XSS, hardcoded secrets, path traversal, IDOR, CSRF, insecure deserialization
- **Framework analysis**: Django, Flask, React, Express, Spring Boot, Rails, Laravel
- **Custom rule authoring**: Semgrep pattern development for organization-specific security policies

## Use this skill when

Use for code review security analysis, injection vulnerabilities, hardcoded secrets, framework-specific patterns, custom security policy enforcement, pre-deployment validation, legacy code assessment, and compliance (OWASP, PCI-DSS, SOC2).

**Specialized tools**: Use `security-secrets.md` for advanced credential scanning, `security-owasp.md` for Top 10 mapping, `security-api.md` for REST/GraphQL endpoints.

## Do not use this skill when

- You only need runtime testing or penetration testing
- You cannot access the source code or build outputs
- The environment forbids third-party scanning tools

## Instructions

1. Identify the languages, frameworks, and scope to scan.
2. Select SAST tools and configure rules for the codebase.
3. Run scans in CI or locally with reproducible settings.
4. Triage findings, prioritize by severity, and propose fixes.

## Safety

- Avoid uploading proprietary code to external services without approval.
- Require review before enabling auto-fix or blocking releases.

## SAST Tool Selection

## 🧠 Knowledge Modules (Fractal Skills)

### 1. [Python: Bandit](./sub-skills/python-bandit.md)
### 2. [JavaScript/TypeScript: ESLint Security](./sub-skills/javascripttypescript-eslint-security.md)
### 3. [Multi-Language: Semgrep](./sub-skills/multi-language-semgrep.md)
### 4. [Other Language Tools](./sub-skills/other-language-tools.md)
### 5. [SQL Injection](./sub-skills/sql-injection.md)
### 6. [Cross-Site Scripting (XSS)](./sub-skills/cross-site-scripting-xss.md)
### 7. [Hardcoded Secrets](./sub-skills/hardcoded-secrets.md)
### 8. [Path Traversal](./sub-skills/path-traversal.md)
### 9. [Insecure Deserialization](./sub-skills/insecure-deserialization.md)
### 10. [Command Injection](./sub-skills/command-injection.md)
### 11. [Insecure Random](./sub-skills/insecure-random.md)
### 12. [Django](./sub-skills/django.md)
### 13. [Flask](./sub-skills/flask.md)
### 14. [Express.js](./sub-skills/expressjs.md)
### 15. [GitHub Actions](./sub-skills/github-actions.md)
### 16. [GitLab CI](./sub-skills/gitlab-ci.md)

Files in this skill

  • SKILL.md3.2 KB
  • sub-skills/command-injection.md252 B
  • sub-skills/cross-site-scripting-xss.md399 B
  • sub-skills/django.md490 B
  • sub-skills/expressjs.md4.6 KB
  • sub-skills/flask.md268 B
  • sub-skills/github-actions.md745 B
  • sub-skills/gitlab-ci.md1.1 KB
  • sub-skills/hardcoded-secrets.md198 B
  • sub-skills/insecure-deserialization.md228 B
  • sub-skills/insecure-random.md215 B
  • sub-skills/javascripttypescript-eslint-security.md643 B
  • sub-skills/multi-language-semgrep.md1.8 KB
  • sub-skills/other-language-tools.md224 B
  • sub-skills/path-traversal.md429 B
  • sub-skills/python-bandit.md379 B
  • sub-skills/sql-injection.md249 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…