byhardw00t· 12 skills
Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.
$npx -y skills add hardw00t/ai-security-arsenal --skill sast-orchestrationInstalls into the current project.
Run `npx skills use "https://github.com/hardw00t/ai-security-arsenal" --skill "hardw00t/ai-security-arsenal/sast-orchestration"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/hardw00t/ai-security-arsenal" that are relevant to the current task. Run `npx skills add "https://github.com/hardw00t/ai-security-arsenal"` and select the relevant skills, then follow their instructions.