Static Analysis Tools Skill

SkillSecurity

Integration with security-focused static analysis tools

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Static Analysis Tools Skill skill

What this skill tells your AI

The instructions your AI receives, as published by a5c-ai/babysitter in library/specializations/security-research/skills/static-analysis-tools/SKILL.md and read by ahel’s review.

Overview

This skill provides integration with security-focused static analysis tools for comprehensive code security analysis.

Capabilities

  • Execute Semgrep rules and custom patterns
  • Run CodeQL queries for vulnerability detection
  • Execute Bandit (Python), Brakeman (Ruby), etc.
  • Parse and interpret static analysis results
  • Generate custom detection rules
  • Aggregate findings across tools
  • Map findings to CWE/CVE identifiers
  • Support SAST pipeline integration

Target Processes

  • static-code-analysis.js
  • variant-analysis.js
  • web-app-vuln-research.js
  • api-security-research.js

Dependencies

  • Semgrep CLI
  • CodeQL CLI and databases
  • Language-specific analyzers:
    • Bandit (Python)
    • Brakeman (Ruby)
    • gosec (Go)
    • SpotBugs (Java)
  • Python for result aggregation

Usage Context

This skill is essential for:

  • Security code review automation
  • Vulnerability pattern detection
  • Custom security rule development
  • CI/CD security gate integration
  • Variant analysis across codebases

Integration Notes

  • Supports multiple output formats (SARIF, JSON, custom)
  • Can run incrementally on changed files
  • Integrates with IDE and CI/CD workflows
  • Custom rules can be version controlled
  • Results can be deduplicated and triaged

Signals

GitHub stars
2k
Forks
112
Last commit
Sep 2026
Advanced
Item type
skill
Key
static-analysis-tools-skill
Source
github.com/a5c-ai/babysitter