🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
$ npx skills add WerWolv/ImHexDecision filters
78 skills matching "static"
Best blend of quality, stars, freshness, and agent usage
🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
$ npx skills add WerWolv/ImHexAn extremely fast Python linter and code formatter, written in Rust.
$ npx skills add astral-sh/ruffShellCheck, a static analysis tool for shell scripts
$ npx skills add koalaman/shellcheckMobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
$ npx skills add MobSF/Mobile-Security-Framework-MobSFA tool to enforce Swift style and conventions.
$ npx skills add realm/SwiftLintA static analyzer for Java, C, C++, and Objective-C
$ npx skills add facebook/inferLightweight static analysis for many languages. Find bug variants with patterns that look like source code.
$ npx skills add semgrep/semgrep⚡A CLI tool for code structural search, lint and rewriting. Written in Rust
$ npx skills add ast-grep/ast-grepPHP Static Analysis Tool - discover bugs in your code without running it!
$ npx skills add phpstan/phpstanA tool to automatically fix PHP Coding Standards issues
$ npx skills add PHP-CS-Fixer/PHP-CS-FixerThe OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
$ npx skills add OWASP/mastgA vulnerability scanner for container images and filesystems
$ npx skills add anchore/grypeDockerfile linter, validate inline bash, written in Haskell
$ npx skills add hadolint/hadolintVulnerability Static Analysis for Containers
$ npx skills add quay/clairProgram for determining types of files for Windows, Linux and MacOS.
$ npx skills add horsicq/Detect-It-EasyContinuous Inspection
$ npx skills add SonarSource/sonarqubeA Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
$ npx skills add Konloch/bytecode-viewerCLI tool and library for generating a Software Bill of Materials from container images and filesystems
$ npx skills add anchore/syftCheckstyle is a development tool to help programmers write Java code that adheres to a coding standard. By default it supports the Google Java Style Guide and Sun Code Conventions, but is highly configurable. It can be invoked with an ANT task and a command line program.
$ npx skills add checkstyle/checkstyleA powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
$ npx skills add We5ter/Scanners-BoxGo security checker
$ npx skills add securego/gosecPrevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
$ npx skills add bridgecrewio/checkovBandit is a tool designed to find common security issues in Python code.
$ npx skills add PyCQA/banditA static analysis security vulnerability scanner for Ruby on Rails applications
$ npx skills add presidentbeef/brakemanThe modern Java bytecode editor
$ npx skills add Col-E/RecafCatch common Java mistakes as compile-time errors
$ npx skills add google/error-pronePerformant type-checking for python.
$ npx skills add facebook/pyre-checkStatic code analysis for Kotlin
$ npx skills add detekt/detektStaticcheck - The advanced Go linter
$ npx skills add dominikh/go-toolsValidate and visualize dependencies. Your rules. JavaScript, TypeScript, CoffeeScript. ES6, CommonJS, AMD.
$ npx skills add sverweij/dependency-cruiserstatic analysis of C/C++ code
$ npx skills add cppcheck-opensource/cppcheckStatic Analyzer for Solidity and Vyper
$ npx skills add crytic/slitherA PHP static analysis tool for finding errors and security vulnerabilities in PHP applications
$ npx skills add vimeo/psalmIt's not just a linter that annoys you!
$ npx skills add pylint-dev/pylintPhan is a static analyzer for PHP. Phan prefers to avoid false-positives and attempts to prove incorrectness rather than correctness.
$ npx skills add phan/phan🔥 ~6x faster, stricter, configurable, extensible, and beautiful drop-in replacement for golint
$ npx skills add mgechev/reviveStatic analysis for GitHub Actions
$ npx skills add zizmorcore/zizmorAn extensible multilanguage static code analyzer.
$ npx skills add pmd/pmdA static code analysis tool for the Elixir language with a focus on code consistency and teaching.
$ npx skills add rrrene/credoOfficial ESLint plugin for Vue.js
$ npx skills add vuejs/eslint-plugin-vue🦩 Tools for Go projects
$ npx skills add nikolaydubina/go-recipesAnalyze ELF binaries like a boss 😼🕵️♂️
$ npx skills add orhun/binsiderCode smell detector for Ruby
$ npx skills add troessner/reekA tool to help eliminate NullPointerExceptions (NPEs) in your Java code with low build-time overhead
$ npx skills add uber/NullAwaySpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
$ npx skills add spotbugs/spotbugsStatic analysis tool to detect potential nil panics in Go code
$ npx skills add uber-go/nilawayflake8 is a python tool that glues together pycodestyle, pyflakes, mccabe, and third-party plugins to check the style and quality of some python code.
$ npx skills add PyCQA/flake8KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.
$ npx skills add stackrox/kube-linterCodebase intelligence for TypeScript and JavaScript. Free static layer: unused code, duplication, circular deps, complexity hotspots, architecture boundaries. Optional paid runtime layer: hot-path review and cold-path deletion evidence from real production traffic. Rust-native, sub-second, zero-config framework support.
$ npx skills add fallow-rs/fallowGitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and various tools.
$ npx skills add shivammathur/setup-phpMago is a toolchain for PHP that aims to provide a set of tools to help developers write better code.
$ npx skills add carthage-software/magoStatic analyzer for C/C++ based on the theory of Abstract Interpretation.
$ npx skills add NASA-SW-VnV/ikosSoot - A Java optimization framework
$ npx skills add soot-oss/soot💎 Code quality CLI for universal linting, auto-formatting, security scanning, and maintainability
$ npx skills add qltysh/qltyKubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your Kubernetes YAML and Charts. Static code analysis for Kubernetes.
$ npx skills add zegl/kube-scoreFlowistry is an IDE plugin for Rust that helps you focus on relevant code.
$ npx skills add willcrichton/flowistryA PHP parser written in PHP
$ npx skills add nikic/PHP-ParserCode security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
$ npx skills add Bearer/bearerTfsec is now part of Trivy
$ npx skills add aquasecurity/tfsecCodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools.
$ npx skills add Ericsson/codecheckerPHPMD is a spin-off project of PHP Depend and aims to be a PHP equivalent of the well known Java tool PMD. PHPMD can be seen as an user friendly frontend application for the raw metrics stream measured by PHP Depend.
$ npx skills add phpmd/phpmdWork-in-progress tool to reverse unity's IL2CPP toolchain.
$ npx skills add SamboyCoding/Cpp2ILTypeScript Compiler API wrapper for static analysis and programmatic code changes.
$ npx skills add dsherret/ts-morphConverts JavaScript to TypeScript and TypeScript to better TypeScript. 🧫
$ npx skills add JoshuaKGoldberg/TypeStat☔ 敏捷开发最强大易用的接口工具,机器学习零代码测试与 AI 问答、生成代码与静态检查、生成文档与光标悬浮注释,腾讯、华为、SHEIN、传音、工行等使用 ☔ The most advanced tool for HTTP API. Machine learning no-code testing and AI assistant, generating codes and static analysis, generating comments and floating hints. Used by Tencent, Huawei, SHEIN, TRANSSION, ICBC, etc.
$ npx skills add TommyLemon/APIAutoManage translation and localization with static analysis, for Ruby i18n
$ npx skills add glebm/i18n-tasksInteractive architecture diagrams for codebases
$ npx skills add CodeBoarding/CodeBoardingSpoon is a metaprogramming library to analyze and transform Java source code. :spoon: is made with :heart:, :beers: and :sparkles:. It parses source files to build a well-designed AST with powerful analysis and transformation API.
$ npx skills add INRIA/spoon🚀Optimizer for mobile applications
$ npx skills add didi/boosterA static type analyzer for Python code
$ npx skills add google/pytypeStatic analyzer and linter for Clojure code that sparks joy
$ npx skills add clj-kondo/clj-kondoAn easy-to-learn/use static analysis framework for Java and Android
$ npx skills add pascal-lab/Tai-eStatic Value-Flow Analysis Framework for Source Code
$ npx skills add SVF-tools/SVFNode.js dependency tracing utility
$ npx skills add vercel/nftNext-gen phpDoc parser with support for intersection types and generics
$ npx skills add phpstan/phpdoc-parserPHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.
$ npx skills add PHPCSStandards/PHP_CodeSnifferSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecRadare2 and Frida better together.
$ npx skills add nowsecure/r2frida