sast agents

20 tagged sast, measured the same way as everything else here.

Browse within: appsec 12semgrep 9threat-modeling 9ide 6

Agent Author

01

agentgg-dev/agentgg

Agent

Distills a past security report into a reusable agentgg agent that catches the same anti-pattern if it recurs in this codebase.

194 3d ago A 30 tokens original Apache-2.0

Smart Exclude

02

agentgg-dev/agentgg

Agent

Picks folders a SAST run doesn't need to scan (test directories, fixtures, docs, generated code, vendored deps) so the scan skips them.

194 3d ago A 36 tokens original Apache-2.0

Project Recon

03

agentgg-dev/agentgg

Agent

Fast, high-level survey that orients the security agents — what the project is, its stack, auth model, integrations, and notable areas.

194 3d ago A 32 tokens original Apache-2.0

coder

04

snyk/snyk-ls

Agent Cursor

Implementation specialist that writes production code using TDD and commits changes. Use proactively when implementing features, fixing bugs, or writing code for a confirmed plan. Delegates to planner when requirements are unclear or need updating. Hands over to qa when implementation is complete.

83 2d ago A 53 tokens original Apache-2.0

planner

05

snyk/snyk-ls

Agent Cursor

Planning specialist that creates structured implementation plans for Jira issues. Use proactively when starting a new task, beginning work on a Jira issue, or when asked to plan a feature. Creates the plan and hands over to the implementation agent.

83 2d ago A 47 tokens original Apache-2.0

qa

06

snyk/snyk-ls

Agent Cursor

QA specialist that deeply analyzes code produced by the coder agent. Runs the verification skill, traces code paths, checks logic for gaps, unintended changes, edge cases, and omissions. Use proactively after implementation is complete, when coder says "done", or when asked to review/verify code quality.

83 2d ago A 60 tokens original Apache-2.0

allsmog/vuln-scout

Agent

Use this agent to verify security findings and eliminate false positives. Analyzes code context, data flow paths, and exploitability with structured evidence to determine if a finding is a true positive or false positive.

24 2mo ago A 46 tokens original MIT

poc-developer

08

allsmog/vuln-scout

Agent

Use this agent when the user wants to "write an exploit", "create a PoC", "develop proof of concept", "automate the attack", or needs help creating exploit scripts during Phase 3 of whitebox security review.

24 2mo ago A 52 tokens original MIT

threat-modeler

09

allsmog/vuln-scout

Agent

Use this agent when the user asks to "create a threat model", "analyze threats", "STRIDE analysis", "what are the threats", "threat modeling", "identify attack vectors", "map attack surface", or needs systematic threat identification with data flow diagrams.

24 2mo ago A 60 tokens original MIT

function-analyzer

13

Yashvendra/claude-security-skills

Agent

Performs ultra-granular per-function deep analysis for security audit context building. Use when analyzing dense functions, data-flow chains, cryptographic implementations, or state machines.

2 5mo ago A 38 tokens original MIT