sast-skills
Run a parallel agent-driven SAST assessment without third-party scanners
- Stars
- 763
- Forks
- 36
- Updated
- Updated Jul 14, 2026
Run a parallel agent-driven SAST assessment without third-party scanners
LLM SAST Skills turns a compatible coding assistant into a coordinated static-analysis workflow. It first maps the stack, architecture, entry points, data flows, and trust boundaries, then runs thirteen vulnerability-focused skills in parallel to discover and verify issues such as SQL injection, XSS, RCE, SSRF, authorization flaws, path traversal, unsafe uploads, and business-logic bugs. A final skill consolidates evidence, remediation guidance, and dynamic test instructions by severity. Existing CLAUDE.md or AGENTS.md files may conflict with its orchestrator.
Resource types
Use cases
Platforms
Install security auditing, vulnerability research, and development skills for Claude Code or Codex.
Give Agent Skills-compatible coding agents reusable workflows for diverse CTF challenges.
Runtime
Capabilities
Public GitHub facts last synced Jul 14, 2026.
Load specialized Claude skills for authorized offensive security testing.
Structure external reconnaissance for authorized red-team and bug-bounty engagements.