Sast Code Scanner

Run Static Application Security Testing (SAST) on source code to detect common vulnerability patterns such as SQL injection, XSS, SSRF, insecure deserialization, path traversal, and more. Use this skill whenever the user wants to scan source code for security bugs, run SAST analysis, check for OWASP Top 10 vulnerabilities in code, use Semgrep, CodeQL, Bandit, or similar tools, or find insecure coding patterns. Trigger for requests like "scan my code for vulnerabilities", "run SAST on this file", "check for SQL injection", "find XSS in my codebase", "run Semgrep", "analyze this code for security issues", "find insecure code patterns", "check for OWASP Top 10 issues", or "detect injection flaws in my app". Do NOT trigger for scanning Docker images (use docker-security-scanner), auditing package dependencies for CVEs (use dependency-audit), or detecting hardcoded secrets (use secret-detector).

aibot88 Updated 3 repo stars

File contents

aibot88/sec_skill_store/tree/main/skills/github/dhivagar29-ci-workflow-optimizer-skills-sast-code-scanner commit 9c61f2f4d0

Frequently asked questions

npx skillmds@latest add aibot88/sast-code-scanner