Static Value-Flow Analysis Framework for Source Code
$ npx skills add SVF-tools/SVFDecision filters
52 skills matching "static-analysis"
Best blend of quality, stars, freshness, and agent usage
Static Value-Flow Analysis Framework for Source Code
$ npx skills add SVF-tools/SVFInteractive architecture diagrams for codebases
$ npx skills add CodeBoarding/CodeBoardingNode.js dependency tracing utility
$ npx skills add vercel/nftNext-gen phpDoc parser with support for intersection types and generics
$ npx skills add phpstan/phpdoc-parserPHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards.
$ npx skills add PHPCSStandards/PHP_CodeSnifferSecurity risk analysis for Kubernetes resources
$ npx skills add controlplaneio/kubesecRadare2 and Frida better together.
$ npx skills add nowsecure/r2fridaHorusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
$ npx skills add ZupIT/horusecDocker image that provides static analysis tools for PHP
$ npx skills add jakzal/phpqaAn analysis tool for Python that blurs the line between testing and type systems.
$ npx skills add pschanely/CrossHairSonarSource Static Analyzer for JavaScript and TypeScript
$ npx skills add SonarSource/SonarJS:coffee: SonarSource Static Analyzer for Java Code Quality and Security
$ npx skills add SonarSource/sonar-javaSemgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.
$ npx skills add semgrep/semgrep-rulesA powerful C# Roslyn analyzer that uses static analysis to detect bugs, surface security issues, and enforce best practices—helping developers and AI write more reliable code.
$ npx skills add meziantou/Meziantou.AnalyzerOpenSCA is an open source software supply chain security solution that supports the detection of open source dependencies, vulnerabilities and license compliance with a widely noticed accuracy by the community.
$ npx skills add XmirrorSecurity/OpenSCA-cliAn artifact of fully-specified annotations to power static-analysis checks, beginning with nullness analysis.
$ npx skills add jspecify/jspecifyPython Type Checker / Language Server
$ npx skills add zubanls/zubanProtect against malicious open source packages 🤖
$ npx skills add safedep/vetA LLVM-based static analysis framework.
$ npx skills add secure-software-engineering/phasarAn Intelligent Python Code Quality Analyzer
$ npx skills add ludo-technologies/pyscnAn easy-to-learn/use static analysis framework for Java
$ npx skills add pascal-lab/Tai-eAppshark is a static taint analysis platform to scan vulnerabilities in an Android app.
$ npx skills add bytedance/appsharkPySonar2: a semantic indexer for Python with interprocedual type inference
$ npx skills add yinwang0/pysonar2A reactive Python kernel for Jupyter notebooks.
$ npx skills add ipyflow/ipyflow✔️ PHP Architecture Tester - Easy architecture testing for PHP
$ npx skills add carlosas/phpatFlowDroid Static Data Flow Tracker
$ npx skills add secure-software-engineering/FlowDroidCode analyzer for C# and VB.NET projects
$ npx skills add SonarSource/sonar-dotnetA code analyzer for Julia. No need for additional type annotations.
$ npx skills add aviatesk/JET.jlAll-in-one devtool to automatically analyze, search and visualize project modules and dependencies from JavaScript, TypeScript (JSX/TSX) and Node.js (ES6, CommonJS)
$ npx skills add antoine-coulon/skottT.J. Watson Libraries for Analysis, with front ends for Java, Android, and JavaScript, and many common static program analyses.
$ npx skills add wala/WALACode style checking for RSpec files.
$ npx skills add rubocop/rubocop-rspecA new version of Soot with a completely overhauled architecture
$ npx skills add soot-oss/SootUpSymfony extension for PHPStan
$ npx skills add phpstan/phpstan-symfonyExtra strict and opinionated rules for PHPStan
$ npx skills add phpstan/phpstan-strict-rulesCake a C23 front end and transpiler written in C
$ npx skills add thradams/cakeDoctrine extensions for PHPStan
$ npx skills add phpstan/phpstan-doctrineSonarQube plugin for JetBrains IDEs providing code quality and security feedback directly in the IDE
$ npx skills add SonarSource/sonarlint-intellijA GitHub :octocat: app to automatically review Python code style over Pull Requests
$ npx skills add pep8speaks-org/pep8speaksSonarQube extension for Visual Studio Code providing code quality and security feedback directly in the editor
$ npx skills add SonarSource/sonarlint-vscodeCodeCompass is a software comprehension tool for large scale software written in C/C++, C# and Python.
$ npx skills add Ericsson/CodeCompass:ab: Tool to compare two revisions of a class API to check for BC breaks
$ npx skills add Roave/BackwardCompatibilityCheckProtect your secrets using Gitleaks-Action
$ npx skills add gitleaks/gitleaks-actionA common base representation of python source code for pylint and other projects
$ npx skills add pylint-dev/astroidGenerate interactive call graphs for various languages
$ npx skills add chanhx/crabvizTai-e assignments for static program analysis
$ npx skills add pascal-lab/Tai-e-assignmentsMy collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
$ npx skills add bl4de/security-toolsA collection of my Semgrep rules to facilitate vulnerability research.
$ npx skills add 0xdea/semgrep-rulesmobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and Objective C Code. mobsfscan uses MobSF static analysis rules and is powered by semgrep and libsast pattern matcher.
$ npx skills add MobSF/mobsfscanPackj stops :zap: Solarwinds-, ESLint-, and PyTorch-like attacks by flagging malicious/vulnerable open-source dependencies ("weak links") in your software supply-chain
$ npx skills add ossillate-inc/packjprealloc is a Go static analysis tool to find slice declarations that could potentially be preallocated.
$ npx skills add alexkohler/preallocPHP Magic Number Detector
$ npx skills add povils/phpmndSecurity-focused static analysis for the Phoenix Framework
$ npx skills add nccgroup/sobelow