SAST Pipeline Scanner
Runs static application security testing using Semgrep rules and CodeQL queries against pull request diffs. Supports SARIF output format and integrates with GitHub Advanced Security for findings management.
SAST Pipeline Scanner
Runs static application security testing using Semgrep rules and CodeQL queries against pull request diffs. Supports SARIF output format and integrates with GitHub Advanced Security for findings management.
Installation
Method 1, Agent Skill Exchange
- Install from the marketplace listing: https://agentskillexchange.com/skills/sast-pipeline-scanner/
Method 2, Git clone
git clone https://github.com/agentskillexchange/skills.git && cd skills/skills/sast-pipeline-scanner
Method 3, Download ZIP
- Download the repository ZIP and extract
skills/sast-pipeline-scanner.
Method 4, Manual copy
- Copy this skill folder into your local skills directory, then reload your agent tooling.
Method 5, Fork and sync
- Fork the repository if you want to maintain local edits while syncing upstream changes.