All skills
hardw00t avatar

/sast-orchestration

@f9bb3b2

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration

This session only. Nothing lands on disk.

referencesgosec.md

≈545 tokens on demand. Your agent reads this file only when SKILL.md points to it.

gosec Reference (Go)

AST-based Go security scanner. Fast. Run on every package in a Go module.

Install

go install github.com/securego/gosec/v2/cmd/gosec@latest
# Verify: gosec --version

Invocation

# Entire module
gosec ./...

# Severity floor
gosec -severity medium ./...

# Confidence floor
gosec -confidence high ./...

# Include / exclude rules
gosec -include=G101,G102,G103 ./...
gosec -exclude=G104 ./...

# Output
gosec -fmt=json  -out=gosec.json  ./...
gosec -fmt=sarif -out=gosec.sarif ./...
gosec -fmt=text  -out=gosec.txt   ./...

# Excluding test files (default includes them)
gosec -exclude-dir=vendor -tests=false ./...

# Config file
gosec -conf=.gosec.json ./...

Rule IDs

ID Check
G101 Hardcoded credentials
G102 Binding to all interfaces
G103 Audit unsafe block
G104 Unchecked errors
G106 ssh.InsecureIgnoreHostKey
G107 URL from variable in HTTP request (SSRF)
G108 net/http/pprof exposed
G109 Integer overflow on strconv.Atoi → int32
G110 Potential DoS via decompression bomb
G201-G204 SQL injection family
G301-G307 File perm / path traversal / symlink
G401-G408 Weak crypto (DES, RC4, MD5, SHA1, small RSA/DSA)
G501-G505 Insecure imports (md5, des, rc4, etc.)
G601 Implicit memory aliasing in for-range

Config (.gosec.json)

{
  "global": {
    "nosec": "enabled",
    "audit": "enabled"
  },
  "G101": {
    "pattern": "(?i)(passwd|password|pass|secret|token|key|pw|apiKey|bearer)"
  },
  "G104": {
    "ignore": ["fmt.Print", "fmt.Println"]
  }
}

Suppression

Inline: // #nosec G104 -- reason

Known FP patterns

  • G104 (unchecked errors): often informational; filter by use case.
  • G107 (URL from variable): fires on any dynamic URL; pair with taint analysis before triaging as exploitable SSRF.
  • G204 (subprocess via variable): flags exec.Command(userVar, ...) even with a validated allowlist.

Pair with

  • staticcheck (quality, not security) — run alongside.
  • Semgrep p/golang for pattern rules not in gosec.
  • CodeQL Go suite for inter-procedural taint.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security orchestration suite designed to run and aggregate results from various Static Application Security Testing (SAST) tools. It includes workflows for scanning codebases, triaging findings, and authoring custom detection rules. No malicious patterns or security risks were identified; the skill correctly manages its capabilities to provide a comprehensive security analysis environment.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1 file scanned · No issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sast-orchestration