File contents Static Analysis
Comprehensive static analysis toolkit for security vulnerability detection, based on the Trail of Bits Application Security Testing Handbook .
When to Use
Running security scans on codebases (any language)
Writing custom CodeQL queries or Semgrep rules
Processing and triaging SARIF output files from analysis tools
Setting up static analysis in CI/CD pipelines
Comparing and aggregating results from multiple tools
When NOT to Use
Writing Semgrep rules from scratch (use semgrep-rule-creator skill instead)
Dynamic analysis or fuzzing (use testing-handbook-skills)
Smart contract auditing (use security-building-secure-contracts)
Sub-Skills
Tool
Purpose
Best For
Skill Path
CodeQL
Semantic code analysis with database queries
Deep data flow tracking, taint analysis, cross-function analysis
skills/codeql/SKILL.md
Semgrep
Fast pattern-matching static analysis
Quick scans, custom rules, CI integration, lightweight checks
skills/semgrep/SKILL.md
SARIF Parsing
Parse and process SARIF result files
Aggregating results, CI/CD integration, multi-tool triage
skills/sarif-parsing/SKILL.md
Tool Selection Guide
Scenario
Recommended Tool
Quick security scan
Semgrep
Deep vulnerability analysis
CodeQL
Data flow / taint tracking
CodeQL (best) or Semgrep taint mode
Custom pattern detection
Semgrep (simpler) or CodeQL (more powerful)
CI/CD integration
Semgrep (fastest) + CodeQL (thorough)
Processing scan results
SARIF Parsing
Non-building codebase
Semgrep (works on incomplete code)
Quick Start
Semgrep (fast scan)
# Install
pip install semgrep
# Run with recommended rulesets
semgrep --config=auto .
# Run specific ruleset
semgrep --config=p/security-audit .
CodeQL (deep analysis)
# Create database
codeql database create mydb --language=python --source-root=.
# Run security queries
codeql database analyze mydb codeql/python-queries:codeql-suites/python-security-extended.qls --format=sarif-latest --output=results.sarif
SARIF Processing
# Parse results with jq
jq '.runs[].results[] | {ruleId, message: .message.text, location: .locations[0].physicalLocation.artifactLocation.uri}' results.sarif
Workflow
Quick scan with Semgrep for fast results
Deep analysis with CodeQL for thorough coverage
Aggregate results using SARIF parsing
Triage findings by severity and exploitability
Custom rules for project-specific patterns
Related Skills
semgrep-rule-creator - Dedicated skill for writing production-quality Semgrep rules
variant-analysis - Find similar vulnerabilities using CodeQL/Semgrep patterns
security-differential-review - Security-focused code review using static analysis findings
1 --- 2 name: static-analysis 3 description: Static Analysis 4 --- 5 # Static Analysis 6 7 Comprehensive static analysis toolkit for security vulnerability detection, based on the [Trail of Bits Application Security Testing Handbook](https://appsec.guide/). 8 9 ## When to Use 10 11 - Running security scans on codebases (any language) 12 - Writing custom CodeQL queries or Semgrep rules 13 - Processing and triaging SARIF output files from analysis tools 14 - Setting up static analysis in CI/CD pipelines 15 - Comparing and aggregating results from multiple tools 16 17 ## When NOT to Use 18 19 - Writing Semgrep rules from scratch (use semgrep-rule-creator skill instead) 20 - Dynamic analysis or fuzzing (use testing-handbook-skills) 21 - Smart contract auditing (use security-building-secure-contracts) 22 23 ## Sub-Skills 24 25 | Tool | Purpose | Best For | Skill Path | 26 |------|---------|----------|------------| 27 | **CodeQL** | Semantic code analysis with database queries | Deep data flow tracking, taint analysis, cross-function analysis | [skills/codeql/SKILL.md](skills/codeql/SKILL.md) | 28 | **Semgrep** | Fast pattern-matching static analysis | Quick scans, custom rules, CI integration, lightweight checks | [skills/semgrep/SKILL.md](skills/semgrep/SKILL.md) | 29 | **SARIF Parsing** | Parse and process SARIF result files | Aggregating results, CI/CD integration, multi-tool triage | [skills/sarif-parsing/SKILL.md](skills/sarif-parsing/SKILL.md) | 30 31 ## Tool Selection Guide 32 33 | Scenario | Recommended Tool | 34 |----------|-----------------| 35 | Quick security scan | Semgrep | 36 | Deep vulnerability analysis | CodeQL | 37 | Data flow / taint tracking | CodeQL (best) or Semgrep taint mode | 38 | Custom pattern detection | Semgrep (simpler) or CodeQL (more powerful) | 39 | CI/CD integration | Semgrep (fastest) + CodeQL (thorough) | 40 | Processing scan results | SARIF Parsing | 41 | Non-building codebase | Semgrep (works on incomplete code) | 42 43 ## Quick Start 44 45 ### Semgrep (fast scan) 46 ```bash 47 # Install 48 pip install semgrep 49 50 # Run with recommended rulesets 51 semgrep --config=auto . 52 53 # Run specific ruleset 54 semgrep --config=p/security-audit . 55 ``` 56 57 ### CodeQL (deep analysis) 58 ```bash 59 # Create database 60 codeql database create mydb --language=python --source-root=. 61 62 # Run security queries 63 codeql database analyze mydb codeql/python-queries:codeql-suites/python-security-extended.qls --format=sarif-latest --output=results.sarif 64 ``` 65 66 ### SARIF Processing 67 ```bash 68 # Parse results with jq 69 jq '.runs[].results[] | {ruleId, message: .message.text, location: .locations[0].physicalLocation.artifactLocation.uri}' results.sarif 70 ``` 71 72 ## Workflow 73 74 1. **Quick scan** with Semgrep for fast results 75 2. **Deep analysis** with CodeQL for thorough coverage 76 3. **Aggregate results** using SARIF parsing 77 4. **Triage findings** by severity and exploitability 78 5. **Custom rules** for project-specific patterns 79 80 ## Related Skills 81 82 - **semgrep-rule-creator** - Dedicated skill for writing production-quality Semgrep rules 83 - **variant-analysis** - Find similar vulnerabilities using CodeQL/Semgrep patterns 84 - **security-differential-review** - Security-focused code review using static analysis findings
ComeOnOliver/skillshub/tree/main/skills/elizaOS/eliza/static-analysis commit c551041417
Frequently asked questions How do I install the Static Analysis skill? Run npx skillmds@latest add comeonoliver/static-analysis in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
What does the Static Analysis skill do? Static Analysis It is listed under Coding & Dev Tools on SkillMD.
Is Static Analysis safe to use? This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
Which AI agents work with Static Analysis? This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Is Static Analysis free to use? Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
Who published Static Analysis? ComeOnOliver (@comeonoliver) published this skill. Their other Agent Skills are listed on their SkillMD profile.