Sarif Parsing

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplicate alerts", or "process sarif output". Handles filtering, deduplication, format conversion, and CI/CD integration of SARIF data. Does NO...

概览

Sarif Parsing is a SKILL.md-based agent skill sourced from trailofbits/skills. It is categorized under security and is listed for Claude Code, Claude. The source description focuses on: Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplicate alerts", or "process sarif output". Handles filtering, deduplication, for... AIToolly summarizes this page as a directory entry rather than copying the full third-party skill content, so users can evaluate the source, compatibility, and practical fit before installing it.

使用场景

Evaluate Sarif Parsing before adding it to an AI agent workflow.
Use Sarif Parsing as a starting point for repeatable security tasks.
Compare Sarif Parsing with related skills from skills and other GitHub repositories.

安装说明

# Review source first
open https://github.com/trailofbits/skills/blob/main/plugins/static-analysis/skills/sarif-parsing/SKILL.md

Copy or clone the skill folder into your agent skills directory after reviewing its instructions and scripts.

安全提示

Review the source SKILL.md, referenced scripts, permissions, and external services before installing Sarif Parsing. Treat third-party skills like code dependencies, especially when they can read files, call APIs, or run commands.

相关 Skills

Yara Rule Authoring

trailofbits/skills

安全

指导编写用于恶意软件识别的高质量 YARA-X 检测规则。适用于编写、审查或优化 YARA 规则时使用。涵盖命名规范、字符串选择、性能优化、从旧版 YARA 迁移以及降低误报。触发条件:YARA、YARA-X、malware detection、threat hunting、IOC、signature、crx module、dex module。

Claude CodeClaude
designsecurity
7,069 Stars已链接来源

Cargo Fuzz

trailofbits/skills

安全

设置并运行 cargo-fuzz,这是基于 Cargo 的 Rust 项目的标准模糊测试工具。涵盖 cargo fuzz init、nightly 工具链要求、fuzz_target! 测试桩、Arbitrary 派生的结构化输入、sanitizer 选项、cargo fuzz coverage 以及重现崩溃产物。适用于模糊测试 Rust crate、编写 fuzz_target!、测试 Rust 中的 unsafe 块或 FFI,或排查 cargo fuzz 崩溃。

Claude CodeClaude
securityresearch
7,069 Stars已链接来源

Deep Agents Memory

langchain-ai/langchain-skills

安全

INVOKE THIS SKILL 当您的 Deep Agent 需要内存、持久化或文件系统访问时。涵盖了 StateBackend(临时)、StoreBackend(持久)、FilesystemMiddleware 和用于路由的 CompositeBackend。

CodexClaude
typescriptpython
1,213 Stars已链接来源

Security Audit

TerminalSkills/skills

安全

通过扫描 OWASP Top 10 漏洞、检查依赖项中的已知 CVE、检测泄露的机密和 API 密钥,并生成优先修复建议,对代码库进行全面的安全审计。此技能结合了静态分析模式与依赖项审计工具。

CodexClaude Code
securityaudit
72 StarsApache-2.0