security-scanning

SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening

View on GitHub
Author Seth Hobson
Namespace @amurata/claude-code-workflows
Category security
Version 1.2.2
Stars 3
Downloads 3
self.md verified
Table of content

SAST analysis, dependency vulnerability scanning, OWASP Top 10 compliance, container security scanning, and automated security hardening

Installation

npx claude-plugins install @amurata/claude-code-workflows/security-scanning

Contents

Folders: agents, commands, skills

Included Skills

This plugin includes 1 skill definition:

sast-configuration

Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection.

View skill definition

SAST Configuration

Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

Overview

This skill provides comprehensive guidance for setting up and configuring SAST tools including Semgrep, SonarQube, and CodeQL. Use this skill when you need to:

Core Capabilities

1. Semgrep Configuration

2. SonarQube Setup

3. CodeQL Analysis

Quick Start

Initial Assessment

  1. Identify primary programming languages in your codebase
  2. Determine compliance requirements (PCI-DSS, SOC 2, etc.)
  3. Choose SAST tool based on lang

…(truncated)

Source

View on GitHub

Tags: security securitysastvulnerability-scanningowaspdevsecops