Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    SAST Configuration Kit

    1

    It doesn't just "turn on" security; it builds a sustainable workflow that developers actually trust.

    $7

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    SAST Configuration Kit

    SAST Configuration Kit

    Example session with this skill installed

    We added Semgrep with --config auto to GitHub Actions on our Django + React monorepo. It fails every PR on about 400 existing findings, so developers now merge with admin override. Can you fix the setup?

    • Read your context and instructions
    • Compiled the sast configuration kit
    • Generated the document

    Mode: TUNE. The scanner has lost trust because it gates on legacy findings and on every severity. Baseline first, then narrow the rules.

    IDProblemEvidenceEffectFixEffort
    T1No baseline on a legacy repo~400 existing findings fail every PR5Scan only changes vs main1
    T2Blocks on all severitiesAdmin overrides are routine4Block ERROR only, report the rest1
    T3Broad --config autoMixed-signal rules3Use p/django, p/react, p/secrets2
    T4No suppression policyUnknown2nosemgrep requires a reason and owner2

    Sorted by Effect² / Effort. Top 3: T1, T2, T3.

    - uses: actions/checkout@v4
      with: { fetch-depth: 0 }
    - run: pip install semgrep
    - run: >
        semgrep scan --config p/django --config p/react --config p/secrets
        --baseline-commit origin/main --severity ERROR --error
    

    The one change that restores trust: T1. Once only newly introduced issues fail a PR, the override habit has no reason to exist.

    Residual risk: SAST does not see runtime behaviour or most business-logic flaws such as broken authorization between tenants. A green check is not a security review.

    Next steps

    • Remove admin override on the Semgrep check once T1 is merged.
    • Export the 400 baseline findings and burn down secrets and injection first.
    • Add a weekly full scan without the baseline flag.

    sast-configuration-kit.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Deploy high-signal Semgrep/CodeQL configurations from scratch.Fix a noisy SAST setup that developers are currently ignoring.Implement 'baseline-then-ratchet' gates for legacy codebases.Write custom Semgrep rules for internal API security patterns.Configure secret-scanning to prevent credential leaks in CI/CD.

    About this skill

    Turn Static Analysis from a Nuisance into a Security Asset

    Most AI agents can run a linter, but they often leave you with hundreds of false positives that your developers will ignore. This skill transforms your agent into a seasoned DevSecOps engineer who specializes in high-signal SAST (Static Application Security Testing) architecture. It doesn't just "turn on" security; it builds a sustainable workflow that developers actually trust.

    What it does

    • Intelligent Tooling: Evaluates your stack and CI/CD environment to select the right tool—whether it's Semgrep for speed, CodeQL for deep dataflow analysis, or SonarQube for quality dashboards.
    • High-Signal Configuration: Drafts language-specific rulesets and custom exclusions to ensure the engine only flags actionable security vulnerabilities like injection, SSRF, or hardcoded secrets.
    • CI Integrated Gates: Configures GitHub Actions, GitLab CI, or Jenkins to block PRs on new critical issues while using "baseline-then-ratchet" strategies for legacy codebases.
    • Noise Reduction (TUNE Mode): Audits existing, noisy scanners to suppress false positives and re-calibrate severity rankings.

    Why use this skill?

    Unlike a basic prompt, this skill understands the social and technical friction of security tooling. It prioritizes signal-over-coverage, ensuring your security gates don't become a bottleneck. It provides ready-to-commit CI YAML and configuration files rather than generic advice.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • Passed all security checks, Safe to install

    Listed3 months ago
    Updated11 days ago

    What's inside

    Frequently Asked Questions