All skills
hardw00t avatar

/sast-orchestration

@f9bb3b2

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration

This session only. Nothing lands on disk.

referencesbrakeman.md

≈660 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Brakeman Reference (Ruby on Rails)

Rails-aware, AST-based scanner. Understands ActiveRecord, routes, controllers, views. Highest signal-to-noise for Rails apps.

Install

gem install brakeman
# Verify: brakeman --version (target >= 6.0)

Invocation

# Scan current Rails app
brakeman

# Explicit app path
brakeman /path/to/rails/app

# Output formats
brakeman -f json   -o brakeman.json
brakeman -f sarif  -o brakeman.sarif
brakeman -f html   -o brakeman.html
brakeman -f markdown -o brakeman.md

# Severity / confidence
brakeman -w 1   # warn level (1=high, 2=medium, 3=weak)
brakeman --confidence-level 2   # 1=high, 2=medium, 3=weak

# Skip / include checks
brakeman --skip-checks CheckCrossSiteScripting,CheckSQL
brakeman -t SQL,CrossSiteScripting

# Diff mode (PR/CI)
brakeman --only-files app/controllers/users_controller.rb
brakeman --compare old_report.json > diff.json

High-value checks

Check CWE Note
SQL CWE-89 where("name = #{params[:name]}")
CrossSiteScripting CWE-79 Unescaped output in ERB
Redirect CWE-601 redirect_to params[:url]
MassAssignment CWE-915 Missing strong_parameters
SessionSettings CWE-614 Cookies without secure/httponly
DefaultRoutes — Wildcard match ':controller(/:action(/:id))'
UnsafeReflection CWE-470 params[:klass].constantize
CommandInjection CWE-78 backticks / system with user input
FileAccess CWE-22 File.open(params[:path])
Deserialize CWE-502 YAML.load / Marshal.load on user data
RegexDoS CWE-1333 Catastrophic backtracking
CSRFTokenSkipped CWE-352 skip_before_action :verify_authenticity_token

Config (config/brakeman.yml)

:skip_checks:
  - CheckForceSSL
:exclude_paths:
  - vendor/
  - node_modules/
:run_all_checks: true
:confidence_level: 2

Suppression

Inline comment above the flagged line:

# brakeman:ignore:SQL -- validated by strong_parameters on controller #create
User.where("name = #{params[:name]}")

Or in config/brakeman.ignore (JSON fingerprint file generated via brakeman -I).

Known FP patterns

  • ActiveRecord where("...", value) (2-arg form) flagged identically to string interp — verify arg count.
  • raw in helpers marked safe after sanitization: suppress with justification.
  • Redirect check fires on any redirect_to with variable even when allowlisted.

Pair with

  • bundler-audit (dependency vulns) — not SAST; see sca-security skill.
  • Semgrep p/ruby for non-Rails Ruby code.
  • CodeQL Ruby suite for inter-procedural taint.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security orchestration suite designed to run and aggregate results from various Static Application Security Testing (SAST) tools. It includes workflows for scanning codebases, triaging findings, and authoring custom detection rules. No malicious patterns or security risks were identified; the skill correctly manages its capabilities to provide a comprehensive security analysis environment.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1 file scanned · No issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sast-orchestration