sast plugins

13 tagged sast, measured the same way as everything else here.

Browse within: owasp 5

opentaint

01

seqra/opentaint

Plugin Claude Code

OpenTaint skills extend built-in security rules and code models for your dependencies and frameworks, then find vulnerabilities with whole-program static taint analysis.

149 2d ago A tokens not measured original Apache-2.0

opentaint

02

seqra/opentaint

Plugin Claude Code

Find application-specific vulnerabilities with whole-program static taint analysis and write rules and dependency models for future scans.

149 2d ago A tokens not measured original Apache-2.0

vuln-scout

03

allsmog/vuln-scout

Plugin Claude Code

VulnScout plugins for AI-assisted whitebox security review, deterministic local quick scans, evidence-backed verification, portable reports, and one-release whitebox-pentest compatibility aliases.

24 2mo ago A tokens not measured original MIT

vuln-scout

04

allsmog/vuln-scout

Plugin Claude Code

Claude Code plugin for whitebox security review. Stable: deterministic offline quick scan, shared findings.json with stable keys and hotspot-aware findings, SARIF/Markdown/HTML/bundle reports, suppressions, CI fail-on gate, Kuzushi parity. Beta: deep profile with Joern/CodeQL/Slither/Trivy/Checkov when installed.…

24 2mo ago A tokens not measured original MIT

security-sweep

06

Onome-AJ/security-sweep-plugin

Plugin Claude Code

Comprehensive security scanner for codebases — finds hardcoded secrets, injection flaws, auth issues, misconfigurations, AI-specific vulnerabilities, and more. Covers OWASP Top 10, Mobile Top 10, and LLM Top 10.

6 4mo ago A tokens not measured original MIT

vantage

08

tinoimammp/vantage-security-agent

Plugin Claude Code

Artifact-driven, plugin-based multi-agent SAST pipeline for web and mobile app repositories. Web agents cover the OWASP Top 10; mobile agents cover the OWASP Mobile Top 10 (2024, M1-M10). Both share global validation/PoC/reporting agents. Run /vantage:scan-web or /vantage:scan-mobile to scan, then /vantage:fix-issue…

4 1mo ago A tokens not measured original MIT

zzop

09

eezz4/zzop

Plugin Claude Code

Self-hosted marketplace for the zzop plugin — deterministic cross-repo contract analysis (frontend calls x backend routes x DB tables) for AI agents.

2 16d ago A tokens not measured original MIT

zzop

10

eezz4/zzop

Plugin Claude Code

Deterministic cross-repo contract analysis for AI agents: which frontend calls hit which backend endpoints (and which don't) — exact joins, disclosed blind spots, no guessing. TypeScript/JavaScript, Python, Java, C#, Rust, Go, Prisma, SQL natively; anything else via a documented adapter envelope. First install only…

2 16d ago A tokens not measured original MIT

security-audit

13

ReeperReepx/Security-Audit-Claude-Skill

Plugin Claude Code

Enterprise-grade security audit skill for Claude Code. Performs comprehensive SAST, secrets detection, dependency auditing, IaC review, API security, and auto-remediation across any codebase with PDF report generation.

2 5mo ago A tokens not measured original MIT