{
  "markdown": "# LLM SAST Skills\n\nA collection of agent skills that turn your LLM coding assistant into a fully functional SAST scanner to find vulnerabilities in your codebase. Works natively with Claude Code, Codex, Opencode, Cursor and any other assistant that supports agent skills. No third-party tools required.\n\nClaude Code with Opus model is recommended. But if the cost is a concern, use any IDE and model you trust.\n\n![Process in Claude Code](demo.gif)\n\n## How It Works\n\n`CLAUDE.md` (for Claude Code) or `AGENTS.md` (for Opencode and other IDEs) orchestrates the entire assessment workflow automatically. The assessment runs in three steps:\n\n1. **Codebase Analysis** -- The `sast-analysis` skill maps the technology stack, architecture, entry points, data flows, and trust boundaries. It writes its findings to `sast/architecture.md`.\n\n2. **Vulnerability Detection (parallel)** -- All 13 vulnerability detection skills run in parallel as subagents. Each skill follows a two-phase approach: first a recon/discovery phase to find candidate sections, then a verification phase to confirm exploitability. Results are written to `sast/*-results.md`.\n\n3. **Report Generation** -- The `sast-report` skill consolidates all findings into a single `sast/final-report.md`, ranked by severity with full remediation guidance and dynamic test instructions.\n\n## What It Detects\n\n| Skill | Vulnerability Class |\n|---|---|\n| sast-analysis | Codebase reconnaissance, architecture mapping, threat modeling |\n| sast-sqli | SQL Injection |\n| sast-graphql | GraphQL injection |\n| sast-xss | Cross-Site Scripting (XSS) |\n| sast-rce | Remote Code Execution (command injection, eval, unsafe deserialization) |\n| sast-ssrf | Server-Side Request Forgery |\n| sast-idor | Insecure Direct Object Reference |\n| sast-xxe | XML External Entity |\n| sast-ssti | Server-Side Template Injection |\n| sast-jwt | Insecure JWT implementations |\n| sast-missingauth | Missing authentication and broken function-level authorization |\n| sast-pathtraversal | Path / directory traversal |\n| sast-fileupload | Insecure file upload |\n| sast-businesslogic | Business logic flaws (price manipulation, workflow bypass, race conditions, etc.) |\n| sast-report | Consolidated final report ranked by severity |\n\n\n## Installation\n\nCopy your project into the `sast-files` folder, then open `sast-files` as your workspace in your AI coding assistant.\n\n```bash\ncp -r /path/to/your/project sast-files/\n```\n\n> **Note:** If your project already contains a `CLAUDE.md` or `AGENTS.md` file, remove it before running the assessment — otherwise it will conflict with the orchestration file provided by this toolkit.\n\n\n## Usage\n\nAfter copying the files, open your project in your AI coding assistant and ask:\n\n> Run vulnerability scan\n\nor\n\n> Find vulnerabilities in this codebase\n\nThe entry point file (`CLAUDE.md` or `AGENTS.md`) orchestrates the full workflow automatically. It will skip any steps whose output files already exist, so you can safely re-run it after fixing issues.\n\n## Output\n\nAll output is written to a `sast/` folder in your project root:\n\n| File | Description |\n|---|---|\n| `sast/architecture.md` | Technology stack, architecture, entry points, data flows |\n| `sast/*-results.md` | Per-vulnerability-class findings with proof and remediation |\n| `sast/final-report.md` | Consolidated report ranked by severity |\n",
  "bytes": 3360,
  "sha": "00521e729ee10871e8643f4f79235c610625dc907a83f7a31e4580d6c1f533f3",
  "repo_slug": "utkusen/sast-skills",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_utkusen_sast_skills_sast_analysis_f004c915/readme"
}