utkusen/sast-skills
Agent skills that convert AI coding assistants into a multi-agent SAST scanner for vulnerability detection.

This project provides a collection of agent skills and workflow orchestration that enables AI coding assistants to perform static application security testing. The system uses a multi-agent architecture where 13 different vulnerability detection skills run in parallel as subagents, coordinated through CLAUDE.md or AGENTS.md files. The skills cover common vulnerability classes including SQL injection, XSS, RCE, SSRF, and others, with each skill following a discovery and verification phase before generating consolidated reports.