github.com/utkusen/sast-skills
| Skill | Added | Review |
|---|---|---|
sast-report sast-files/.agents/skills/sast-report/SKILL.md Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. Reads all *-results.md files and produces sast/final-report.md. Run after all vulnerability detection skills complete. Use when asked to generate a final report, consolidate findings, or summarize security results. | 76 76 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: db52227 | |
sast-report sast-files/.claude/skills/sast-report/SKILL.md Consolidate all SAST vulnerability results from the sast/ folder into a single final report ranked by severity and confidentiality impact. Reads all *-results.md files and produces sast/final-report.md. Run after all vulnerability detection skills complete. Use when asked to generate a final report, consolidate findings, or summarize security results. | 69 69 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: db52227 | |
sast-sqli sast-files/.agents/skills/sast-sqli/SKILL.md Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3 sites each), and merge (consolidate batch results). Covers string concat, f-strings, unsafe ORM methods, and dynamic identifiers. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/sqli-results.md. Use when asked to find SQLi or database injection bugs. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 | |
sast-sqli sast-files/.claude/skills/sast-sqli/SKILL.md Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3 sites each), and merge (consolidate batch results). Covers string concat, f-strings, unsafe ORM methods, and dynamic identifiers. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/sqli-results.md. Use when asked to find SQLi or database injection bugs. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 | |
sast-ssrf sast-files/.agents/skills/sast-ssrf/SKILL.md Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/ssrf-results.md. Use when asked to find SSRF or server-side request forgery bugs. | 72 72 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: db52227 | |
sast-ssrf sast-files/.claude/skills/sast-ssrf/SKILL.md Detect Server-Side Request Forgery (SSRF) vulnerabilities in a codebase using a three-phase approach: recon (find outbound call sites), batched verify (trace user input to destinations in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/ssrf-results.md. Use when asked to find SSRF or server-side request forgery bugs. | 66 66 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: db52227 | |
sast-ssti sast-files/.agents/skills/sast-ssti/SKILL.md Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user input to those sites in parallel subagents, 3 candidates each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/ssti-results.md. Use when asked to find SSTI or template injection bugs. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 | |
sast-ssti sast-files/.claude/skills/sast-ssti/SKILL.md Detect Server-Side Template Injection (SSTI) vulnerabilities in a codebase using a three-phase approach: recon (find template rendering sites that use dynamic strings), batched verify (trace user input to those sites in parallel subagents, 3 candidates each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/ssti-results.md. Use when asked to find SSTI or template injection bugs. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 | |
sast-xss sast-files/.agents/skills/sast-xss/SKILL.md Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3 sink sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/xss-results.md. Use when asked to find XSS or cross-site scripting bugs. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 | |
sast-xss sast-files/.claude/skills/sast-xss/SKILL.md Detect Cross-Site Scripting (XSS) vulnerabilities in a codebase using a three-phase approach: recon (find HTML/JS/DOM sink sites), batched verify (trace user input to sinks in parallel subagents, 3 sink sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/xss-results.md. Use when asked to find XSS or cross-site scripting bugs. | 67 67 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 | |
sast-xxe sast-files/.agents/skills/sast-xxe/SKILL.md Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to each site in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/xxe-results.md. Use when asked to find XXE or XML injection bugs. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 | |
sast-xxe sast-files/.claude/skills/sast-xxe/SKILL.md Detect XML External Entity (XXE) vulnerabilities in a codebase using a three-phase approach: recon (find XML parsing sites without external-entity hardening), batched verify (trace user input to each site in parallel subagents, 3 sites each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/xxe-results.md. Use when asked to find XXE or XML injection bugs. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: db52227 |