技能目录

为 AI Agent 发现可复用技能。

按任务搜索真实的 GitHub 技能,并在使用前查看 Stars、信任、审计、分类和安装路径。

每个推荐都保留与其仓库、审计和安装路径的明确关联。

搜索结果: sast

英文目录

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

2.7K
Stars
76/100
信任
分类: security审计

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...

1.7K
Stars
78/100
信任
分类: security审计

njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.

436
Stars
72/100
信任
分类: security审计

ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

657
Stars
73/100
信任
分类: security审计

Generic SAST Library

139
Stars
70/100
信任
分类: security审计

CI/CD pipeline configuration using GitHub Actions for Golang projects — testing, linting, SAST, security scanning, code coverage, Dependabot, Renovate, GoReleaser, code review automation, and release pipelines. Use when setting up or improving Go project CI, configuring GitHub Actions workflows, adding linters or security scanners, automating dependency updates, or adding quality gates.

3.0K
Stars
67/100
信任
分类: security审计

Collection of agent skills that turn your AI coder into a SAST scanner

661
Stars
69/100
信任
分类: agent-skills审计

High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!

146
Stars
63/100
信任
分类: security审计

PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. It leverages a powerful Rust core to deliver high-speed, accurate vulnerability scanning, wrapped in a developer-friendly Python CLI.

138
Stars
67/100
信任
分类: security审计

A collection of AI agent skills for using OpenText Fortify across SAST/DAST/SCA scanning, vulnerability triage, remediation, and CI/CD workflows in agent runtimes like Claude Code and Copilot.

16
Stars
62/100
信任
分类: security审计

"chanzi" is a simple and user-friendly JAVA SAST tool that utilizes taint analysis technology, includes built-in common vulnerability rules, supports decompile, custom rule, and is compatible with the technology stacks of Servlet&filter, Spring,struts,Dubbo,Thrift, jax-rs,jax-ws,JFinal,Netty,MyBatis,and JSP.

491
Stars
64/100
信任
分类: security审计

SAST and DAST Scan Supported with 400 plus rules available for secrets and allow you add your own wordlist as well. lightweight source code scanner and for URL that detects hardcoded secrets like API keys, credentials, and sensitive information across files and folders.

113
Stars
67/100
信任
分类: security审计