content-creator
88Create Brand-Consistent Marketing Content
Marketing teams need content that stays consistent across channels. This skill helps plan, write, analyze, and optimize content for brand voice and SEO.
Configure SAST Pipelines and Rules
Teams need consistent SAST coverage across repositories and CI systems. This skill guides tool selection, pipeline setup, rule tuning, and result triage.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "sast-configuration" from https://skillstore.io/skills/sickn33-sast-configuration.md and its manifest at https://skillstore.io/api/skills/sickn33-sast-configuration/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "sast-configuration". We need SAST for a Python API in GitHub Actions.
Expected outcome:
Recommended plan: start with Semgrep for fast security checks, add CodeQL for deeper analysis, and fail builds only on high confidence critical issues during the first baseline period.
Using "sast-configuration". Our scan has many false positives in generated files.
Expected outcome:
Expected output: an exclusion plan for generated paths, a suppression review checklist, and guidance for documenting accepted findings.
Using "sast-configuration". Compare Semgrep, SonarQube, and CodeQL for our program.
Expected outcome:
Expected output: a concise tool matrix with recommended roles, integration points, cost notes, and rollout priorities.
The static findings are false positives caused by markdown code fences, documented SAST setup commands, a public Semgrep repository URL, and relative links to related skill documents. No prompt injection, exfiltration intent, or hidden execution path was found in SKILL.md.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/sickn33-sast-configuration/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/sickn33-sast-configuration?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/sickn33-sast-configuration?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-sast-configuration/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/sickn33-sast-configuration.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>sickn33. (2026). sast-configuration security audit report (audit version 5) [Author version unspecified]. Skillstore. https://skillstore.io/skills/sickn33-sast-configuration/audits/5@techreport{sickn33-sickn33-sast-configuration-2026,
author = {sickn33},
title = {sast-configuration security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/sickn33-sast-configuration/audits/5},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "sast-configuration security audit report (audit version 5)"
version: "unspecified"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/sickn33-sast-configuration/audits/5"
identifiers:
- type: other
value: "skillstore:sickn33-sast-configuration:audit:5"
description: "Skillstore immutable audit report identifier"
Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
wshobson-sast-configuration
2026-08-21
sickn33-sast-configuration
2026-08-21
Select suitable scanners, define an initial baseline, and add CI checks before release.
Review false positives, document suppressions, and adjust rules so developers receive useful findings.
Plan recurring scans, produce SARIF or report outputs, and prioritize remediation for audit workflows.
Help me choose a SAST tool for a repository using [languages]. My CI system is [CI system], and my main goal is [goal].
Design a SAST CI workflow for [repository type]. Include scanner choice, trigger points, failure thresholds, and artifact handling.
Review this SAST finding summary and propose a tuning plan. Separate real risks, likely false positives, suppressions, and developer guidance.
Create a SAST operating model for [organization]. Include Semgrep, SonarQube, CodeQL, quality gates, ownership, metrics, and rollout phases.
Author
sickn33License
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/sast-configurationRef
9f814fc6a43fd99946f2da5e0df231c65a38bc76
Maintenance freshness
7/18/2026
Usage
9 downloads ยท 78 views
File structure
๐ SKILL.md
Create Brand-Consistent Marketing Content
Marketing teams need content that stays consistent across channels. This skill helps plan, write, analyze, and optimize content for brand voice and SEO.
Improve LLM Prompts With Proven Patterns
Inconsistent prompts waste time and make AI outputs hard to trust. This skill guides prompt design with reusable patterns, examples, evaluation steps, and optimization workflows.
Build Fullstack Apps with Senior Patterns
Teams need consistent setup, architecture, and review guidance for modern web applications. This skill provides scaffolders, workflow references, and quality prompts for React, Next.js, Node.js, GraphQL, and PostgreSQL projects.
Design Scalable Software Architectures
Architecture decisions are hard to compare across web, mobile, backend, and cloud systems. This skill provides structured guides and local scaffold scripts for reports, dependency review, and trade-off documentation.
Optimize AI Prompts With Prompt Engineer
Writing clear prompts is hard when goals are vague or complex. This skill turns rough requests into structured prompts using proven prompt frameworks.
Prioritize Product Work With Research Insights
Product teams need faster ways to rank features, synthesize interviews, and document decisions. This skill provides RICE scoring, interview analysis, and PRD templates for structured planning.
Audit Code with Semgrep
by AgentSecOps
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
Integrate Reviewdog Security Feedback into CI
by AgentSecOps
Security scanner results are often fragmented across CI logs. This skill helps configure reviewdog to publish focused findings in pull requests and local hooks.
Automate SecOps Checks
by alirezarezvani
Security teams need consistent review workflows across projects. This skill provides SecOps CLI scaffolds and reference guides for repeatable checks.
Build pytm Threat Models as Code
by AgentSecOps
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Detect Exposed Secrets in Code
by CuriousLearner
Leaked credentials can give attackers access to cloud accounts, databases, and payment systems. This skill helps Claude, Codex, and Claude Code find likely secrets and produce clear remediation steps.
Secure Dockerfiles with Hadolint
by AgentSecOps
Dockerfile mistakes can create insecure and unreliable container images. This skill provides Hadolint workflows, rule guidance, remediation examples, and reusable CI configurations.