Sast Orchestration

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

hardw00t Updated

File contents

hardw00t/ai-security-arsenal/tree/main/skills/sast-orchestration commit 45bf88dcf7

Frequently asked questions

npx skillmds@latest add hardw00t/sast-orchestration