LLM SAST Skills
A set of skills that turns the agent into a static code analyzer: finds vulnerabilities and builds a prioritized report
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- The skills read the entire project source, including areas with secrets and authorization
- A language model performs the review, completeness is not guaranteed and findings need verification
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add skills/llm-sast-skillsDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a claude-code -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a cursor -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a github-copilot -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a codex -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a gemini-cli -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a cline -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a roo -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
A fork of Roo Code, same .roo folders.
Run in a terminal in the project folder
npx skills add utkusen/sast-skills --skill sast-analysis sast-businesslogic sast-fileupload sast-graphql sast-hardcodedsecrets sast-idor sast-jwt sast-missingauth sast-pathtraversal sast-rce sast-report sast-sqli sast-ssrf sast-ssti sast-xss sast-xxe -a opencode -yThe skills tool installs the current version from the repository. Add the -g flag to use the skill in every project.
Clone the repository, copy your project into the sast-files folder and open sast-files as the workspace in your agent. Then ask: run a vulnerability scan. The CLAUDE.md or AGENTS.md file drives the orchestration.
Other ways from the author
git clone https://github.com/utkusen/sast-skills.git
cp -r /path/to/your/project sast-skills/sast-files/Your project is copied into the sast-files folder, which is opened as the agent workspace. If the project has a CLAUDE.md or AGENTS.md, remove it before running.
This is third-party code. Review the repository files before installing.
What it does
The set gives the agent a static security analysis method with no third-party tools. Work runs in three steps: first the sast-analysis skill maps the tech stack, architecture, entry points, data flows and trust boundaries and writes them to a file. Then a set of skills for vulnerability classes runs in parallel, each in two passes: first finding candidate spots, then verifying exploitability. Finally the sast-report skill consolidates findings into a single report ranked by severity with remediation guidance. It covers SQL injection, XSS, remote code execution, SSRF, IDOR, XXE, SSTI, weak JWT, missing authorization, path traversal, insecure file upload, GraphQL and business-logic flaws. Orchestration is set by a CLAUDE.md or AGENTS.md file.
Who it is for. For developers, QA and devops engineers who need a security review of their own code together with the agent.
Good fit when
- You need to find vulnerabilities in your own web or mobile code without a separate scanner
- You need a security report with priorities and remediation
- You need to re-check the code after fixes
Not a fit when
- You want to test someone else's system without permission to analyze its code
- You need a deterministic scanner with guaranteed coverage rather than model-based review
Example request
Find vulnerabilities in this codebase and build a prioritized reportLimitations
Analysis is performed by a language model, so quality depends on it; the authors recommend Claude Code with the Opus model. The set reads project source code and writes reports into a sast folder; it takes no external actions. Installation is non-standard: your project is copied into the sast-files folder, which becomes the workspace. If the project already has a CLAUDE.md or AGENTS.md file, it must be removed or it conflicts with the orchestration. Results should be verified; there is no guarantee of completeness.
How to disable. Remove the repository directory with its .claude/skills and .agents/skills folders, or the skill folders themselves from the agent's skills directory.
Security check
- The skills read the entire project source, including areas with secrets and authorization
- A language model performs the review, completeness is not guaranteed and findings need verification
README in short
The README describes a set of agent skills that turns an assistant into a static security analyzer with no third-party tools. It works with Claude Code, Codex, Opencode, Cursor and other skill-capable agents, with Claude Code on Opus recommended. The process has three steps: codebase analysis, parallel detection across vulnerability classes in two passes, and consolidation into a final report. Installation copies your project into the sast-files folder, which is opened as the workspace. It runs on a phrase about finding vulnerabilities, and a re-run skips steps whose output already exists. MIT licensed.
SKILL.md
--- name: sast-analysis description: >- Perform codebase analysis and architecture mapping as the first phase of a security assessment. Explores the tech stack, frameworks, entry points, data flows, and trust boundaries. Outputs sast/architecture.md. Run this before any vulnerability detection skill. Use when asked to analyze a codebase for security or when sast/architecture.md does not yet exist. --- # Codebase Analysis You are performing the first phase of a security assessment. Your goal is to deeply understand the codebase. You are NOT looking for specific vulnerabilities yet. This is pure reconnaissance.
FAQ
Are third-party scanners required?
No. The model performs the analysis using the method from the skills; separate tools are not needed.
Where do results go?
Into a sast folder in the project root: the architecture map, per-class findings and a consolidated severity report.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents