跳到主要内容
知仓学习社ZHICANG

Static Analysis Tools Skill

Integration with security-focused static analysis tools

不碰外部(只输出文字)无严重或高危命中a5c-ai/babysitter

它会碰到什么

扫了多少2 个文本文件,2 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Static Analysis Tools Skill

Overview

This skill provides integration with security-focused static analysis tools for comprehensive code security analysis.

Capabilities

  • Execute Semgrep rules and custom patterns
  • Run CodeQL queries for vulnerability detection
  • Execute Bandit (Python), Brakeman (Ruby), etc.
  • Parse and interpret static analysis results
  • Generate custom detection rules
  • Aggregate findings across tools
  • Map findings to CWE/CVE identifiers
  • Support SAST pipeline integration

Target Processes

  • static-code-analysis.js
  • variant-analysis.js
  • web-app-vuln-research.js
  • api-security-research.js

Dependencies

  • Semgrep CLI
  • CodeQL CLI and databases
  • Language-specific analyzers:
  • Bandit (Python)
  • Brakeman (Ruby)
  • gosec (Go)
  • SpotBugs (Java)
  • Python for result aggregation

Usage Context

This skill is essential for:

  • Security code review automation
  • Vulnerability pattern detection
  • Custom security rule development
  • CI/CD security gate integration
  • Variant analysis across codebases

Integration Notes

  • Supports multiple output formats (SARIF, JSON, custom)
  • Can run incrementally on changed files
  • Integrates with IDE and CI/CD workflows
  • Custom rules can be version controlled
  • Results can be deduplicated and triaged

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 1,796
本站分层T1
该仓技能数2115
原文件路径library/specializations/security-research/skills/static-analysis-tools/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 2115 个技能