SAST Security Plugin
Static Application Security Testing (SAST) for comprehensive code vulnerability detection across multiple languages, frameworks, and security patterns.
Capabilities
- Multi-language SAST: Python, JavaScript/TypeScript, Java, Ruby, PHP, Go, Rust
- Tool integration: Bandit, Semgrep, ESLint Security, SonarQube, CodeQL, PMD, SpotBugs, Brakeman, gosec, cargo-clippy
- Vulnerability patterns: SQL injection, XSS, hardcoded secrets, path traversal, IDOR, CSRF, insecure deserialization
- Framework analysis: Django, Flask, React, Express, Spring Boot, Rails, Laravel
- Custom rule authoring: Semgrep pattern development for organization-specific security policies
Use this skill when
Use for code review security analysis, injection vulnerabilities, hardcoded secrets, framework-specific patterns, custom security policy enforcement, pre-deployment validation, legacy code assessment, and compliance (OWASP, PCI-DSS, SOC2).
Specialized tools: Use security-secrets.md for advanced credential scanning, security-owasp.md for Top 10 mapping, security-api.md for REST/GraphQL endpoints.
Do not use this skill when
- You only need runtime testing or penetration testing
- You cannot access the source code or build outputs
- The environment forbids third-party scanning tools
Instructions
- Identify the languages, frameworks, and scope to scan.
- Select SAST tools and configure rules for the codebase.
- Run scans in CI or locally with reproducible settings.
- Triage findings, prioritize by severity, and propose fixes.
Safety
- Avoid uploading proprietary code to external services without approval.
- Require review before enabling auto-fix or blocking releases.
SAST Tool Selection
🧠 Knowledge Modules (Fractal Skills)
1---2name: security-scanning-security-sast3description: Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks4---5# SAST Security Plugin
6
7Static Application Security Testing (SAST) for comprehensive code vulnerability detection across multiple languages, frameworks, and security patterns.
8
9## Capabilities
10
11- **Multi-language SAST**: Python, JavaScript/TypeScript, Java, Ruby, PHP, Go, Rust
12- **Tool integration**: Bandit, Semgrep, ESLint Security, SonarQube, CodeQL, PMD, SpotBugs, Brakeman, gosec, cargo-clippy
13- **Vulnerability patterns**: SQL injection, XSS, hardcoded secrets, path traversal, IDOR, CSRF, insecure deserialization
14- **Framework analysis**: Django, Flask, React, Express, Spring Boot, Rails, Laravel
15- **Custom rule authoring**: Semgrep pattern development for organization-specific security policies
16
17## Use this skill when
18
19Use for code review security analysis, injection vulnerabilities, hardcoded secrets, framework-specific patterns, custom security policy enforcement, pre-deployment validation, legacy code assessment, and compliance (OWASP, PCI-DSS, SOC2).
20
21**Specialized tools**: Use `security-secrets.md` for advanced credential scanning, `security-owasp.md` for Top 10 mapping, `security-api.md` for REST/GraphQL endpoints.
22
23## Do not use this skill when
24
25- You only need runtime testing or penetration testing
26- You cannot access the source code or build outputs
27- The environment forbids third-party scanning tools
28
29## Instructions
30
311. Identify the languages, frameworks, and scope to scan.
322. Select SAST tools and configure rules for the codebase.
333. Run scans in CI or locally with reproducible settings.
344. Triage findings, prioritize by severity, and propose fixes.
35
36## Safety
37
38- Avoid uploading proprietary code to external services without approval.
39- Require review before enabling auto-fix or blocking releases.
40
41## SAST Tool Selection
42
43## 🧠 Knowledge Modules (Fractal Skills)
44
45### 1. [Python: Bandit](./sub-skills/python-bandit.md)
46### 2. [JavaScript/TypeScript: ESLint Security](./sub-skills/javascripttypescript-eslint-security.md)
47### 3. [Multi-Language: Semgrep](./sub-skills/multi-language-semgrep.md)
48### 4. [Other Language Tools](./sub-skills/other-language-tools.md)
49### 5. [SQL Injection](./sub-skills/sql-injection.md)
50### 6. [Cross-Site Scripting (XSS)](./sub-skills/cross-site-scripting-xss.md)
51### 7. [Hardcoded Secrets](./sub-skills/hardcoded-secrets.md)
52### 8. [Path Traversal](./sub-skills/path-traversal.md)
53### 9. [Insecure Deserialization](./sub-skills/insecure-deserialization.md)
54### 10. [Command Injection](./sub-skills/command-injection.md)
55### 11. [Insecure Random](./sub-skills/insecure-random.md)
56### 12. [Django](./sub-skills/django.md)
57### 13. [Flask](./sub-skills/flask.md)
58### 14. [Express.js](./sub-skills/expressjs.md)
59### 15. [GitHub Actions](./sub-skills/github-actions.md)
60### 16. [GitLab CI](./sub-skills/gitlab-ci.md)