All skills
hardw00t avatar

/sast-orchestration

@f9bb3b2

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration

This session only. Nothing lands on disk.

referencessarif_format.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

SARIF Reference

Static Analysis Results Interchange Format (OASIS SARIF 2.1.0). The lingua franca for SAST tool output — every major tool emits it, GitHub code scanning ingests it, and it's the right intermediate for multi-tool aggregation.

Minimal schema

{
  "version": "2.1.0",
  "$schema": "https://json.schemastore.org/sarif-2.1.0.json",
  "runs": [
    {
      "tool": {
        "driver": {
          "name": "Semgrep",
          "version": "1.60.0",
          "informationUri": "https://semgrep.dev",
          "rules": [
            {
              "id": "python.lang.security.audit.dangerous-system-call",
              "name": "dangerous-system-call",
              "shortDescription": {"text": "Subprocess with shell=True"},
              "fullDescription": {"text": "..."},
              "helpUri": "https://semgrep.dev/r/...",
              "properties": {
                "security-severity": "8.8",
                "tags": ["security", "CWE-78"]
              }
            }
          ]
        }
      },
      "results": [
        {
          "ruleId": "python.lang.security.audit.dangerous-system-call",
          "level": "error",
          "message": {"text": "Subprocess with shell=True is dangerous"},
          "locations": [
            {
              "physicalLocation": {
                "artifactLocation": {"uri": "src/app.py"},
                "region": {"startLine": 42, "startColumn": 5, "endLine": 42, "endColumn": 40}
              }
            }
          ],
          "partialFingerprints": {
            "primaryLocationLineHash": "abc123..."
          }
        }
      ]
    }
  ]
}

Key objects

Object Purpose
run.tool.driver Which tool produced the run
run.tool.driver.rules[] Rule definitions, referenced by ruleId
run.results[] Actual findings
result.ruleId Links to rule definition
result.level none / note / warning / error
result.locations[].physicalLocation File + region
result.codeFlows[] Taint path (source → intermediate → sink)
result.partialFingerprints Stable ID for dedup across runs
result.suppressions[] Explicit suppression with justification
result.properties.security-severity CVSS-like numeric 0.0-10.0

Taint paths (codeFlows)

"codeFlows": [{
  "threadFlows": [{
    "locations": [
      {"location": {"physicalLocation": {"artifactLocation": {"uri": "src/routes.py"}, "region": {"startLine": 10}}}, "message": {"text": "user input read"}},
      {"location": {"physicalLocation": {"artifactLocation": {"uri": "src/utils.py"}, "region": {"startLine": 25}}}, "message": {"text": "passed to helper"}},
      {"location": {"physicalLocation": {"artifactLocation": {"uri": "src/db.py"},    "region": {"startLine": 77}}}, "message": {"text": "reaches SQL sink"}}
    ]
  }]
}]

CodeQL path-problem queries emit codeFlows; Semgrep taint mode emits them with --sarif; Bandit does not.

Level → severity mapping (for aggregation)

SARIF level Normalized severity
error high / critical
warning medium
note low
none info

Use properties.security-severity when present for finer ranking (CVSS-style 0.0-10.0).

Fingerprinting for dedup

Prefer partialFingerprints.primaryLocationLineHash when tools provide it. Fallback: hash of (ruleId, file_path, line, snippet). Across tools, match on (cwe, file_path, ±3 lines) to merge duplicates.

Tool emission commands

Tool Flag
Semgrep --sarif -o out.sarif
CodeQL --format=sarif-latest --output=out.sarif
Bandit -f sarif -o out.sarif (with bandit[sarif])
gosec -fmt=sarif -out=out.sarif
Brakeman -f sarif -o out.sarif
SpotBugs sarifOutput=true in plugin config
ESLint --format @microsoft/eslint-formatter-sarif

Upload

  • GitHub: github/codeql-action/upload-sarif@v3
  • GitLab: native SAST report artifact (converts SARIF subset)
  • Defect Dojo / Dradis: direct SARIF import

Tools for manipulation

  • jq for quick queries: jq '.runs[0].results | length' out.sarif
  • Microsoft sarif-multitool (dotnet): sarif rewrite, sarif page
  • Python: sarif-om, jschema-to-python

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security orchestration suite designed to run and aggregate results from various Static Application Security Testing (SAST) tools. It includes workflows for scanning codebases, triaging findings, and authoring custom detection rules. No malicious patterns or security risks were identified; the skill correctly manages its capabilities to provide a comprehensive security analysis environment.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1 file scanned · No issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sast-orchestration