All skills
hardw00t avatar

/sast-orchestration

@f9bb3b2

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration

This session only. Nothing lands on disk.

referenceseslint_security.md

≈861 tokens on demand. Your agent reads this file only when SKILL.md points to it.

ESLint Security Reference (JavaScript / TypeScript)

ESLint is a linter; the security plugins add rule sets. Best for fast, in-editor feedback and PR gating. Lower depth than Semgrep/CodeQL on dataflow.

Install

npm install --save-dev \
  eslint \
  eslint-plugin-security \
  eslint-plugin-no-unsanitized \
  eslint-plugin-security-node       # optional: Node.js extras

For TypeScript:

npm install --save-dev \
  @typescript-eslint/parser \
  @typescript-eslint/eslint-plugin

Config (.eslintrc.json — classic)

{
  "parser": "@typescript-eslint/parser",
  "plugins": ["security", "no-unsanitized", "@typescript-eslint"],
  "extends": [
    "plugin:security/recommended-legacy",
    "plugin:@typescript-eslint/recommended"
  ],
  "rules": {
    "security/detect-object-injection": "error",
    "security/detect-non-literal-require": "error",
    "security/detect-non-literal-fs-filename": "error",
    "security/detect-eval-with-expression": "error",
    "security/detect-child-process": "error",
    "security/detect-buffer-noassert": "error",
    "security/detect-pseudoRandomBytes": "error",
    "security/detect-unsafe-regex": "error",
    "no-unsanitized/method": "error",
    "no-unsanitized/property": "error"
  }
}

Flat config (ESLint >= 9, eslint.config.js)

import security from "eslint-plugin-security";
import noUnsanitized from "eslint-plugin-no-unsanitized";
export default [
  security.configs.recommended,
  { plugins: { "no-unsanitized": noUnsanitized },
    rules: {
      "no-unsanitized/method": "error",
      "no-unsanitized/property": "error"
    }
  }
];

Invocation

npx eslint --ext .js,.ts,.jsx,.tsx src/

# SARIF output via formatter
npm install --save-dev @microsoft/eslint-formatter-sarif
npx eslint --format @microsoft/eslint-formatter-sarif \
           --output-file eslint.sarif \
           src/

High-value rules

Rule Class
security/detect-eval-with-expression eval with dynamic content
security/detect-child-process child_process.exec with variable
security/detect-non-literal-fs-filename Path traversal via fs
security/detect-non-literal-regexp ReDoS via dynamic regex
security/detect-non-literal-require RCE via dynamic require
security/detect-object-injection Prototype pollution / property injection
security/detect-pseudoRandomBytes Weak random in crypto context
security/detect-unsafe-regex Known ReDoS patterns
no-unsanitized/method el.insertAdjacentHTML with user data
no-unsanitized/property el.innerHTML = userInput

Known FP patterns

  • detect-object-injection is the noisiest rule in the plugin — often fires on safe obj[key] where key is from a typed enum. Consider downgrading to warn.
  • detect-non-literal-fs-filename fires on any fs.readFile(variable) — needs taint context.
  • detect-child-process fires on static imports of child_process even if unused.

Pair with

  • Semgrep p/javascript p/nodejs p/react p/express for higher-fidelity framework patterns.
  • CodeQL JavaScript suite for inter-procedural taint.
  • npm audit / osv-scanner for dependency CVEs — see sca-security.

Framework packs

  • React-specific: eslint-plugin-react, eslint-plugin-jsx-a11y (accessibility, adjacent).
  • Node.js extras: eslint-plugin-security-node (HTTP header checks, timing attacks).

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security orchestration suite designed to run and aggregate results from various Static Application Security Testing (SAST) tools. It includes workflows for scanning codebases, triaging findings, and authoring custom detection rules. No malicious patterns or security risks were identified; the skill correctly manages its capabilities to provide a comprehensive security analysis environment.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1 file scanned · No issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sast-orchestration