sast-configuration
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
npx skills add sickn33/agentic-awesome-skills --skill sast-configuration --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# SAST Configuration Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages. ## Use this skill when - Set up SAST scanning in CI/CD pipelines - Create custom security rules for your codebase - Configure quality gates and compliance policies - Optimize scan performance and reduce false positives - Integrate multiple SAST tools for defense-in-depth ## Do not use this skill when - You only need DAST or manual penetration testing guidance - You cannot access source code or CI/CD pipelines - You need organizational policy decisions rather than tooling setup ## Instructions 1. Identify languages, repos, and compliance requirements. 2. Choose tools and define a baseline policy. 3. Integrate scans into CI/CD with gating thresholds. 4. Tune rules and suppressions based on false positives. 5. Track remediation and verify fixes. ## Safety - Avoid scanning sensitive repos with third-party services without approval. - Prevent leaks of secrets in scan artifacts and logs. ## Overview This skill provides comprehensive guidance for setting up and configuring SAST tools including Semgrep
- Use this skill when
- Do not use this skill when
- Instructions
- Safety
- Overview
- Core Capabilities
- 1. Semgrep Configuration
- 2. SonarQube Setup
- 3. CodeQL Analysis
- Quick Start
- Initial Assessment
- Basic Setup
- Reference Documentation
- Templates & Assets
Semgrep quick start pip install semgrep semgrep --config=auto --error SonarQube with Docker docker run -d --name sonarqube -p 9000:9000 sonarqube:latest CodeQL CLI setup gh extension install github/gh-codeql codeql database create mydb --language=python PCI-DSS focused scan semgrep --config p/pci-dss --json -o pci-scan-results.json
What does the sast-configuration skill do?
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
How do I install it?
Run `npx skills add sickn33/agentic-awesome-skills --skill sast-configuration --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From sickn33/agentic-awesome-skills, a repository with 44,414 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.