Vulny Code Static Analysis

STRONG · 73
Community indexed

Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex

Downloads 0
Stars 423
Version 1.0.0
Quality 47/100 · Needs review
Trust 73/100 · Strong shortlist
Audit 64/100 · Needs review

Supply asset profile

Research and knowledge work

Deep research, source comparison, literature review, RAG, knowledge search, and reports.

Browse track

Scenario

RAG and knowledge

I need my agent to build a RAG workflow over documents and retrieve reliable context.

Agent fit

Claude Code + CLI + Codex

Codex, Claude Code, Cursor, CLI, or custom agents.

Install

Ready

npx skills add swisskyrepo/Vulny-Code-Static-Analysis

Maintenance

stale

1y since push

Risk

Needs review

License is unclear

GitHub quality

423

47/100 quality · 73/100 trust

Coverage tags

ResearchRAG and knowledgesecurityscanneraudit

Review notes

License is unclear · Repository appears stale

Agent adoption scorecard

Trust, audit, and install readiness at a glance

These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.

Quality

Needs review
47

Inspect the repository carefully before adding it to an agent workflow.

Trust

Strong shortlist
73

Good trust signals with a few areas worth checking before rollout.

Audit

Needs review
64

Install readiness, security metadata, maintenance, and adoption risk.

Trust Score v3

Human review before install

Test in a sandbox workflow and compare its install path with close alternatives.

PHPSecurityCodexClaude CodeCursor

Stars

423 GitHub stars

Repo activity

423 stars, 142 forks

Maintenance

1y since push

License

Unknown

Install

npx skills add swisskyrepo/Vulny-Code-Static-Analysis

Install safety

standard package or runtime install path

Permission surface

filesystem or document access

Docs

Strong README/SKILL.md context

Risk summary

Review before production

  • License is unclear
  • Repository looks stale
  • Quality score needs review
  • Recent maintenance: 1y since push

Install readiness

Install path available

  • Install path is available
  • Repository evidence is available
  • License is unclear
  • 1y since push

Agent-readable metadata

Machine-readable decision data for this skill.

Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.

Open JSON

Suited tasks

  • Coding agents workflows
  • Claude Code teams
  • builders willing to evaluate younger projects
  • Inspect source files
  • Explain architecture

Suited agents

PHPSecurityCodexClaude CodeCursorOpenAgentSkill CLICLI

Trust and risk

Trust score
73/100
Risk level
Needs review
Auto install
review

Install command

npx skills add swisskyrepo/Vulny-Code-Static-Analysis

Do not use when

  • teams that require actively maintained dependencies
  • production agents without a repository review
  • Repository looks stale
  • License is unclear
  • Repository appears stale

Agent safety v2

48/100 · Avoid automatic install

Experimentalreview

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Resolve via API

medium

Network access

Skill likely fetches remote pages, APIs, repositories, or external services.

medium

Filesystem access

Skill may read or write project files, documents, generated artifacts, or local workspace state.

  • License is unclear

Install targets

Install this skill in your agent workflow

Copy the registry command or an agent-specific install prompt for Codex, Claude Code, and Cursor.

skill install

OpenAgentSkill CLI

Use the registry command when your workflow supports the OpenAgentSkill installer.

$ npx skills add swisskyrepo/Vulny-Code-Static-Analysis

Agent resolve plan

Let an agent verify fit before installing.

The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.

Open text plan

Agent should check

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copy prompt

Task: Use Vulny Code Static Analysis in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20Vulny%20Code%20Static%20Analysis%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/swisskyrepo-vulny-code-static-analysis/install
Install command: npx skills add swisskyrepo/Vulny-Code-Static-Analysis
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent handoff

Give an agent the install path, not another directory page.

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

Open install API

Agent prompt

Use Vulny Code Static Analysis for this task. Review https://www.openagentskill.com/api/skills/swisskyrepo-vulny-code-static-analysis/install, then install with: npx skills add swisskyrepo/Vulny-Code-Static-Analysis

Registry metadata

Agent-readable profile for automatic skill selection.

This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.

Open manifest

Agent fit

37/100

Coding agents

Platforms

PHP, Security, Claude Code

Audit report

Needs review · 64/100

Review install readiness, maintenance, trust, quality, and metadata warnings before adding this skill to an agent workflow.

View audit report

Agent decision cockpit

Needs validation for Coding agents

Do a manual repository review before adding this to an agent workflow.

37
Readiness
Review
Stage

Role in stack

Needs validation

Primary fit

Coding agents

Trust label

Needs manual review

Install path

Command ready

Use when

  • Coding agents workflows
  • Claude Code teams
  • builders willing to evaluate younger projects

Evidence

  • install command or GitHub repo available
  • 47/100 quality profile
  • 1 OpenAgentSkill engagement events

Review first

  • Repository looks stale

Implementation path

  1. 1Install it in a sandbox agent and run one Coding agents task end to end.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Trust profile

Strong shortlist

Good trust signals with a few areas worth checking before rollout.

73
Trust score

GitHub adoption

INFO

423 GitHub stars

Stars/forks activity

INFO

423 stars, 142 forks; issue activity unavailable in current metadata

Recent maintenance

FIX

1y since push

License clarity

CHECK

Unknown

Good signals

  • AI review approved
  • Install path is available
  • Repository evidence is available
  • Install command has no obvious high-risk pattern

Review before install

  • License is unclear
  • Repository looks stale
  • Quality score needs review
  • Recent maintenance: 1y since push
  • License clarity: Unknown

Recommended action

Test in a sandbox workflow and compare its install path with close alternatives.

Quality profile

Needs review candidate for agent workflows

Inspect the repository carefully before adding it to an agent workflow.

47
GitHub stars
423
Freshness
1y ago
Install ready
Yes
License
Unknown
Check before install: Repository looks stale

Workflow fit

Use this skill in these scenarios

Stack fit

Add it to a complete workflow

Alternative shortlist

Compare before you install

Similar skills in this category, ranked with the same readiness and quality signals.

Compare all

Overview

Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex

Imported by the skill-only GitHub discovery pipeline because it matches agent skill, automation, domain workflow, RAG, document-processing, data, finance, security, or developer-tool signals. Protocol-server projects are excluded from automated imports.

Platform Compatibility

phpFULL
securityFULL

Technical Details

Version
1.0.0
License
Unknown
Last Updated
6/16/2026
Published
6/16/2026

Frameworks & Tools

PHPSecurity

Decision snapshot

Needs validation

37
Ready
Review
Stage

install command or GitHub repo available

Audit Snapshot

Install and adoption review

64
Needs review
Security
81/100
Maintenance
38/100
Install
92/100
Open full audit

Growth loop

Share this skill

X

Scenario-led draft for Vulny Code Static Analysis, with the OpenAgentSkill Update theme and canonical URL.

OpenAgentSkill Update
Today: Vulny Code Static Analysis

Use it when you want your coding agent to carry more repo context and ship repetiti...

423 stars - security
Link: https://www.openagentskill.com/skills/swisskyrepo-vulny-code-static-analysis?ref=x
#AIAgents #OpenAgentSkill
Open X draft
Optional reply with install command
Link for Vulny Code Static Analysis:
https://www.openagentskill.com/skills/swisskyrepo-vulny-code-static-analysis?ref=x

Install: npx skills add swisskyrepo/Vulny-Code-Static-Analysis

Listing source

Community indexed

Claimable

This listing was indexed from public sources and is not marked official until a maintainer claim is approved.

Indexed by
OpenAgentSkill community index

Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.

Claim this skill

Owner claim

Claim this skill listing

This community indexed listing is attributed to swisskyrepo but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.

README badge

Add this badge to your GitHub README to show the listing, trust score, and install handoff.

[![OpenAgentSkill](https://www.openagentskill.com/api/badge/swisskyrepo-vulny-code-static-analysis)](https://www.openagentskill.com/skills/swisskyrepo-vulny-code-static-analysis)

Author

S

swisskyrepo

@swisskyrepo

Platform Fit

Health Signals

GitHub stars
423
Quality score
37/100
Last GitHub push
Feb 27, 2025
Framework hints
2
OpenAgentSkill views
1
Install copies
0
Outbound clicks
0

Community Signal

Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.

Trust & Safety

Strong shortlist

73
  • GitHub adoption423 GitHub starsINFO
  • Stars/forks activity423 stars, 142 forks; issue activity unavailable in current metadataINFO
  • Recent maintenance1y since pushFIX
  • License clarityUnknownCHECK
  • README/SKILL.md completenessMetadata includes enough usage and workflow contextPASS
  • Dependency/runtime riskno major dependency risk hints in public metadataPASS