All skills
hardw00t avatar

/sast-orchestration

@f9bb3b2

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by exploitability. Use this skill when asked to scan code for vulnerabilities, write Semgrep/CodeQL rules, triage SAST output, reduce false positives, or integrate SAST into CI/CD. Triggers on phrases like 'scan this code', 'write a Semgrep rule', 'triage these findings', 'SARIF', 'SAST in CI', or when a repo is handed over for a security review.

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/sast-orchestration

This session only. Nothing lands on disk.

referencesspotbugs.md

≈748 tokens on demand. Your agent reads this file only when SKILL.md points to it.

SpotBugs + Find Security Bugs Reference (Java/JVM)

Bytecode-level analysis — works on compiled .class / .jar, not source. Find Security Bugs (FSB) is the security plugin for SpotBugs.

Install / invoke

Maven

<plugin>
  <groupId>com.github.spotbugs</groupId>
  <artifactId>spotbugs-maven-plugin</artifactId>
  <version>4.8.6.0</version>
  <configuration>
    <plugins>
      <plugin>
        <groupId>com.h3xstream.findsecbugs</groupId>
        <artifactId>findsecbugs-plugin</artifactId>
        <version>1.13.0</version>
      </plugin>
    </plugins>
    <effort>Max</effort>
    <threshold>Low</threshold>
    <includeFilterFile>spotbugs-security-include.xml</includeFilterFile>
    <sarifOutput>true</sarifOutput>
  </configuration>
</plugin>
mvn compile spotbugs:check        # fail build on findings
mvn compile spotbugs:spotbugs     # generate report only
mvn compile spotbugs:gui          # interactive review UI

Gradle

plugins { id 'com.github.spotbugs' version '6.0.18' }
dependencies {
    spotbugsPlugins 'com.h3xstream.findsecbugs:findsecbugs-plugin:1.13.0'
}
spotbugs {
    effort = 'max'
    reportLevel = 'low'
}
spotbugsMain { reports { sarif.required = true } }

CLI

spotbugs -pluginList findsecbugs-plugin-1.13.0.jar \
  -effort:max -low -sarif -output spotbugs.sarif target/classes

Filter file (scope to security checks)

<!-- spotbugs-security-include.xml -->
<FindBugsFilter>
  <Match><Bug category="SECURITY"/></Match>
</FindBugsFilter>

High-value FSB detectors

Pattern Class
SQL_INJECTION_JDBC / HIBERNATE / JPA / SPRING_JDBC SQL injection variants
COMMAND_INJECTION Runtime.exec with user input
XXE_SAXPARSER / XXE_DOCUMENT / XXE_XMLREADER XML external entity
PATH_TRAVERSAL_IN / PATH_TRAVERSAL_OUT File path taint
XSS_SERVLET / XSS_REQUEST_WRAPPER Servlet XSS
LDAP_INJECTION LDAP injection
WEAK_MESSAGE_DIGEST_MD5 / SHA1 Weak hash
CIPHER_INTEGRITY / ECB_MODE / STATIC_IV Crypto misuse
HARD_CODE_PASSWORD / KEY Hardcoded secrets
INSECURE_COOKIE / HTTPONLY_COOKIE Cookie flags
TRUST_BOUNDARY_VIOLATION Session tainting
DESERIALIZATION_GADGET / OBJECT_DESERIALIZATION Unsafe deserialization
URL_REWRITING Session-in-URL

Suppression

@edu.umd.cs.findbugs.annotations.SuppressFBWarnings(
    value = "SQL_INJECTION_JDBC",
    justification = "Query literal is constant; @varValue is validated allowlist"
)

Known limits

  • Requires compiled bytecode — cannot scan source-only.
  • No Kotlin-specific patterns (analyze compiled Kotlin, but detector coverage is Java-centric).
  • Deserialization gadget detection is pattern-based; pair with CodeQL Java suite.

Pair with

  • Semgrep p/java p/spring for source-level patterns.
  • CodeQL Java suite for inter-procedural taint.
  • Dependency-Check / OWASP DC for dependency CVEs — see sca-security.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a security orchestration suite designed to run and aggregate results from various Static Application Security Testing (SAST) tools. It includes workflows for scanning codebases, triaging findings, and authoring custom detection rules. No malicious patterns or security risks were identified; the skill correctly manages its capabilities to provide a comprehensive security analysis environment.

  • Socket16d

    1 alert: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    1 file scanned · No issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/sast-orchestration