All skills
hardw00t avatar

/sast-orchestration

@f9bb3b2

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration

This session only. Nothing lands on disk.

referencesbandit.md

≈584 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Bandit Reference (Python)

AST-based Python security linter from PyCQA. Fast, noisy. Best as a first-pass Python filter.

Install

pip install bandit              # base
pip install 'bandit[toml]'      # pyproject.toml config support
pip install 'bandit[sarif]'     # SARIF output

Invocation

# Recursive scan
bandit -r ./src

# Severity floor (-l low, -ll medium, -lll high)
bandit -r ./src -ll

# Confidence floor (-i, -ii, -iii)
bandit -r ./src -iii

# Combine for high-signal output
bandit -r ./src -ll -ii

# Specific tests / skip
bandit -r ./src -t B301,B302,B303      # include
bandit -r ./src -s B101                 # skip assert_used

# Output formats
bandit -r ./src -f json   -o bandit.json
bandit -r ./src -f sarif  -o bandit.sarif
bandit -r ./src -f html   -o bandit.html

# Config file
bandit -r ./src -c bandit.yaml

Config (bandit.yaml)

skips: ['B101']   # assert_used is noisy in test code
tests:  # empty = run all
exclude_dirs:
  - tests
  - venv
  - .tox
  - migrations

High-value test IDs

ID Check
B102 exec use
B103 Bad file permissions (world-writable)
B105 / B106 / B107 Hardcoded password string/funcarg/default
B108 Hardcoded tmp directory
B301-B304 Pickle / marshal / md5 / sha1 / insecure cipher
B306 mktemp_q
B307 eval
B308 mark_safe (Django XSS)
B309 HTTPS without cert verification
B310 urllib urlopen
B311 Insecure random
B313-B320 XML parsing (XXE / billion-laughs)
B321 FTP
B324 weak hashlib.new
B501-B507 requests / ssl / paramiko host-key
B601-B612 Shell injection family
B701-B703 Jinja2 / Mako / Django template autoescape off

Known FP patterns

  • B101 (assert_used): fine in test code, exclude tests/.
  • B404 (subprocess import): informational only; filter by confidence.
  • B603/B607 (subprocess without shell): often safe when args are a list.
  • Hardcoded password checks flag variable names — verify value, not name.

When to pair with other tools

  • Bandit + Semgrep (p/python) catches different classes; run both in parallel.
  • For taint across functions, escalate to CodeQL (python-security-extended.qls).
  • For framework-specific (Django/Flask), Semgrep rule packs outperform Bandit.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security orchestration suite designed to run and aggregate results from various Static Application Security Testing (SAST) tools. It includes workflows for scanning codebases, triaging findings, and authoring custom detection rules. No malicious patterns or security risks were identified; the skill correctly manages its capabilities to provide a comprehensive security analysis environment.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1 file scanned · No issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sast-orchestration