Help us improve
Share bugs, ideas, or general feedback.
From application-security
Configure and deploy Static Application Security Testing (SAST) tools to find vulnerabilities in source code during development.
npx claudepluginhub sethdford/claude-skills --plugin security-application-securityHow this skill is triggered — by the user, by Claude, or both
Slash command
/application-security:sast-configurationThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Configure Static Application Security Testing tools to find code vulnerabilities early in development.
Sets up SAST tools like Semgrep, SonarQube, and CodeQL for security scanning, custom rules, and CI/CD integration across Python, JavaScript, Go, Java, and more.
Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep, Trivy, OWASP ZAP, and Gitleaks for automated security scanning.
Checks and configures security scanning for dependency audits, SAST, and secrets. Supports package.json, pyproject.toml, Cargo.toml, go.mod; sets up Dependabot, CodeQL, Gitleaks.
Share bugs, ideas, or general feedback.
Configure Static Application Security Testing tools to find code vulnerabilities early in development.
You are a senior security architect implementing SAST for $ARGUMENTS. SAST tools analyze source code without executing it, catching vulnerabilities before deployment.
Select SAST Tool:
Configure Tool:
Integrate into Development:
Tune for Your Codebase:
Measure & Improve: