
hardcodes
find hardcoded strings from source code

find hardcoded strings from source code

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

A static analysis tool for securing Go code

grep rough audit - source code auditing tool

This skill helps Claude write secure code and prevent common vulnerabilities.

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.

a static analysis tool for finding vulnerabilities in C/C++ source code

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Link sources to sinks in C# applications.

Vulnerability research assistant that extracts pseudocode from the IDA Hex-Rays decompiler.

Static code analysis tool based on Elasticsearch

Detect compiler-invented memory loads that turn secure C into TOCTOU vulnerabilities. Includes automated source audits, Unicorn-based binary…

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…