sast-skills
FreeCollection of agent skills that turn your AI coder into a SAST scanner
About sast-skills
Sast-skills is an open-source collection of agent skills designed to enhance AI coding assistants with Static Application Security Testing (SAST) capabilities. By integrating these skills, an AI coder can analyze source code for security vulnerabilities, such as SQL injection, cross-site scripting, or insecure cryptographic practices, directly within the development workflow. The project is hosted on GitHub and appears to be freely available under an open-source license, allowing developers to inspect, modify, and deploy the skills as needed. The tool is focused on code analysis and does not extend to image, video, or audio processing based on the available information.
Key Features
Pros & Cons
- Open-source and freely available, with no licensing costs
- Designed to augment existing AI coding tools with security scanning
- Source code is accessible for customization and auditing
- Potential to catch security issues early in the development process
- Requires an AI coding assistant to function; not a standalone SAST tool
- Effectiveness depends on the underlying AI model and the quality of the skills
- Coverage of programming languages and vulnerability types should be verified from the repository
- May require technical expertise to set up and integrate
Best For
Alternatives to sast-skills
giskard-oss
🐢 Open-Source Evaluation & Testing library for LLM Agents
ai-captcha-bypass
AI Captcha Bypass
backdoor-learning-resources
A list of backdoor learning resources
claude-bug-bounty
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
agentic-radar
A security scanner for your LLM agentic workflows