本文へ移動
cccskills
無料GitHub で公開

sast-scan

Static application security testing (SAST) for changed source files — Vulnetix's built-in rule set plus optional Semgrep augmentation when `.semgrep` config is present. Use when reviewing a PR for code-level vulnerabilities, scanning a feature branch before merge, gating CI on critical findings, or running rule-specific checks for a known weakness class.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md3.6 KB
  • evals/evals.json2.6 KB
  • evals/trigger-eval.json1.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix SAST Skill

Use when

  • Pre-commit / pre-merge: scan changed source files for SAST findings.
  • Targeted rule check: "did we just write an XXE pattern?" via --rule-id VNX-XXE-001.
  • CI gate: exit non-zero if SAST finds critical-severity issues.
  • Audit a specific weakness class with --paths <dir> --rule-id VNX-CWE-89-*.
  • Augment Vulnetix's rules with the repo's own Semgrep policy.

Don't use for

  • Dependency vulnerability scanning — use vulnetix scan --sca.
  • Secret detection — use secret-scan.
  • Container/IaC scanning — use container-scan / iac-scan.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

Static analysis on source code. Capability-aware: optionally augmented with the user's own Semgrep rules.

Step 1: Load capabilities

Read .vulnetix/capabilities.yaml. Note binaries.semgrep, repo.semgrep_config.

Step 2: Decide scope

If --paths given → scan those paths. Else scan files changed since git merge-base origin/main HEAD (or whole repo if not a git repo).

Step 3: Run scan

vulnetix sast --paths "$PATHS" -o json-sarif > .vulnetix/sast.${TIMESTAMP}.sarif

If --rule-id provided, pass through. If --baseline, also run vulnetix scan --evaluate-sast --list-default-rules -o json to record the rule set used.

Step 4: Augment with local Semgrep (conditional)

If binaries.semgrep: true AND repo.semgrep_config: true:

semgrep --config .semgrep --json --quiet "$PATHS" > .vulnetix/sast.semgrep.${TIMESTAMP}.json

Merge findings into the SARIF report (de-duped by file:line:rule).

Step 5: Render

| Severity | Rule | File:Line | Message | Source |

Group by severity (critical → low). Suggest secure-code-write for repeated rule violations.

Memory update

If running on a PR / branch, write a .vulnetix/sast/<branch>.summary.yaml with finding counts so the pr-security-reviewer agent can pick it up.

Edge cases & gotchas

  • Scope defaults to files changed vs origin/main; pass --paths for explicit scope. CWD without a manifest = empty results.
  • Output is SARIF — pipe through a SARIF viewer (VS Code SARIF Viewer extension) or render the JSON yourself.
  • Semgrep augmentation requires binaries.semgrep: true AND repo.semgrep_config: true. Otherwise the skill silently runs Vulnetix rules only.
  • Built-in rules are organisation-agnostic; rule IDs like VNX-GQL-004 (GraphQL injection) are not customisable per-repo.
  • Findings are deduped by <file>:<line>:<rule_id> across both sources — same logical finding from Semgrep + Vulnetix appears once.
  • Performance: 10K+ file repos benefit from --paths "src/**/*.ts" instead of full-repo scan.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する