All skills
hardw00t avatar

/sast-orchestration

@f9bb3b2

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration

This session only. Nothing lands on disk.

referencessemgrep.md

≈960 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Semgrep Reference

Fast, multi-language pattern-based SAST with a simple YAML rule DSL. Best for custom patterns, secrets, framework-specific rules, and quick scans.

Install

pip install semgrep
# or
brew install semgrep
# Verify: semgrep --version (target >= 1.60)

Invocation

# Default auto-config
semgrep --config=auto .

# Curated rule packs
semgrep --config=p/security-audit \
        --config=p/secrets \
        --config=p/supply-chain \
        --config=p/owasp-top-ten \
        --config=p/cwe-top-25 .

# Language packs: p/python p/javascript p/java p/golang p/ruby p/php
# Framework packs: p/django p/flask p/react p/nodejs p/express p/spring

# Custom rules directory
semgrep --config=./rules/ .

# Output (SARIF is preferred for triage interop)
semgrep --config=auto --sarif -o results.sarif .
semgrep --config=auto --json -o results.json .

# CI mode (non-zero exit on findings, honors .semgrepignore)
semgrep ci

Rule pack selection matrix

Goal Config
Quick audit --config=auto
OWASP coverage p/owasp-top-ten p/cwe-top-25
Secret detection p/secrets p/gitleaks
Supply chain p/supply-chain
Python web p/python p/django p/flask
JS/TS web p/javascript p/react p/nodejs p/express
Java web p/java p/spring
Dockerfile p/dockerfile

Rule authoring essentials

Minimal rule skeleton:

rules:
  - id: <kebab-case-id>
    message: <one-line finding text>
    languages: [python]  # or generic, javascript, java, go, ruby, php, etc.
    severity: ERROR      # ERROR | WARNING | INFO
    metadata:
      cwe: "CWE-89"
      owasp: "A03:2021 - Injection"
      confidence: HIGH
    pattern: <code pattern>

Pattern operators

  • pattern: single pattern match
  • patterns: AND of conditions
  • pattern-either: OR of conditions
  • pattern-inside / pattern-not-inside: contextual scoping
  • pattern-not: negation
  • metavariable-pattern: nested match on a metavariable
  • metavariable-regex: regex filter on metavariable text
  • metavariable-comparison: numeric/string comparison

Metavariables: $X matches one AST node; $...X matches a sequence; ... matches any code.

Taint mode (preferred for injection classes)

rules:
  - id: xss-taint
    mode: taint
    languages: [python]
    severity: ERROR
    pattern-sources:
      - pattern: request.args.get(...)
      - pattern: request.form.get(...)
    pattern-sanitizers:
      - pattern: markupsafe.escape(...)
    pattern-sinks:
      - pattern: render_template_string(...)
      - pattern: Markup(...)
    message: Untrusted input reaches HTML sink

Autofix

Add fix: with a replacement template that can reference metavariables:

fix: hmac.compare_digest($SECRET, $USER_INPUT)

Path filters

paths:
  include: ["src/**", "**/*prod*.py"]
  exclude: ["tests/**", "vendor/**"]

Starter rules (see examples/semgrep_rules/)

  • sql_injection.yaml
  • ssrf.yaml
  • hardcoded_secret.yaml

Tuning and FP reduction

  • Prefer mode: taint over textual patterns for injection, SSRF, path traversal, XXE.
  • Add pattern-not-inside for safe wrappers in the codebase (ORMs, sanitizers).
  • Use paths.exclude for test fixtures and vendored code.
  • Set metadata.confidence for downstream triage ranking.
  • semgrep --severity ERROR to fail CI only on high-signal findings.

Known limits

  • Inter-procedural taint requires Semgrep Pro (--pro) for deep flow.
  • No call-graph outside a single file without Pro.
  • Regex rules (pattern-regex) scan byte-wise and miss AST structure.

Troubleshooting

  • --verbose prints rule compile errors.
  • semgrep --test runs rule unit tests (adjacent *.yaml + target file).
  • Cache: ~/.semgrep/ — delete if rules feel stale.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security orchestration suite designed to run and aggregate results from various Static Application Security Testing (SAST) tools. It includes workflows for scanning codebases, triaging findings, and authoring custom detection rules. No malicious patterns or security risks were identified; the skill correctly manages its capabilities to provide a comprehensive security analysis environment.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1 file scanned · No issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sast-orchestration