sast-skills
Collection of agent skills that turn your AI coder into a SAST scanner
sast-skills is a collection of agent skills that transform AI coding assistants into fully functional Static Application Security Testing (SAST) scanners. Developed by utkusen, it enables AI agents to automatically detect 13 classes of security vulnerabilities—including SQL injection, XSS, RCE, SSRF, and IDOR—across your entire codebase. The toolkit orchestrates a three-phase workflow: codebase analysis, parallel vulnerability detection with verification, and consolidated reporting with remediation guidance. It works natively with Claude Code, Cursor, Codex, Opencode, and any AI assistant that supports agent skills, requiring no external security tools.
Key Features
Use Cases
- 01Automatically scanning application codebases for SQL injection and command injection vulnerabilities before deployment
- 02Identifying authentication gaps and broken authorization in API endpoints during development
- 03Discovering business logic flaws like price manipulation and race conditions in e-commerce applications
- 04Performing comprehensive security audits on inherited or legacy codebases using AI assistants
- 05Integrating automated SAST checks into IDE workflows without configuring external security scanners
- 06Generating actionable security reports with remediation guidance for development teams
Related Skills
View moresuperpowers
An agentic skills framework & software development methodology that works.
skills
Skills for Real Engineers. Straight from my .agents directory.
skills
Public repository for Agent Skills
ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
sast-skills — FAQ
What is sast-skills?+
sast-skills is a collection of agent skills that turns AI coding assistants like Claude Code, Cursor, and Codex into SAST scanners. It detects 13 classes of security vulnerabilities including SQL injection, XSS, RCE, and SSRF without requiring external security tools.
How do I install sast-skills in my AI coding assistant?+
Copy your project into the sast-files folder, then open that folder as your workspace in your AI assistant. Remove any existing CLAUDE.md or AGENTS.md files from your project to avoid conflicts with the orchestration file.
Which AI coding assistants work with sast-skills?+
sast-skills works with Claude Code, Codex, Opencode, Cursor, and any other AI assistant that supports agent skills. Claude Code with the Opus model is recommended for best results.
Do I need API keys or external SAST tools?+
No external SAST tools are required. You only need an AI coding assistant that supports agent skills; the vulnerability scanning runs entirely through the AI agent itself.
Is sast-skills free to use?+
Yes, sast-skills is open source and free. However, you'll incur costs from your AI assistant provider (e.g., Claude API usage) depending on the model and codebase size you analyze.
How do I run a vulnerability scan after installation?+
Open your project in your AI coding assistant and ask "Run vulnerability scan" or "Find vulnerabilities in this codebase." The orchestration file automatically manages the three-phase workflow and writes results to the sast/ folder.
How do I install sast-skills?+
Open the source repository on GitHub and follow its README. sast-skills is a skill — MCP Agents Market links you directly to the official repo.
Is sast-skills free?+
sast-skills is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.