static analysis skills

328 tagged static analysis, measured the same way as everything else here.

Browse within: agent-security 65formal-verification 59supply-chain-security 59openclaw 52skill-scanner 52graph-database 39graphs 39vscode-extension 39reverse-engineering 23typescript 19code-quality 15linter 15python 15software-graph 14

scan

01

sentrux/sentrux

Skill Claude CodeCodex

Scan a project with sentrux to get structural health grades (A-F) across 14 dimensions including coupling, cycles, cohesion, dead code, and test coverage. Use when the user wants to check code quality, architecture health, or before/after an agent session.

2.9k 5mo ago A 57 tokens original MIT

jar-audit-agent

02

jar-analyzer/jar-analyzer

Skill Claude CodeCodex

A procedure for auditing Java archive files for security problems using evidence stored in SQLite. A Java archive, or JAR, is a packaged file containing Java code and resources.

2.2k 5d ago A 51 tokens GPL-3.0

architecture-review

03

ludo-technologies/pyscn

Skill Claude CodeCodex

Analyze Python module architecture using pyscn - class coupling (CBO), cohesion (LCOM), dependency cycles, and module communities. Use when user asks about architecture, module structure, coupling, circular dependencies, or which files to review or change together.

1.0k 3d ago A 53 tokens original MIT

cli-analysis

04

ludo-technologies/pyscn

Skill Claude CodeCodex

Run the pyscn command-line tool for Python code quality analysis - CI/CD quality gates, HTML/JSON/CSV reports, full analysis runs, and project configuration. Use when user wants a CI check, a shareable report file, or to configure pyscn for a project.

1.0k 3d ago A 59 tokens original MIT

health-check

05

ludo-technologies/pyscn

Skill Claude CodeCodex

Get an overall Python code quality health score using pyscn. Use when user asks how healthy or good the code is, wants a quality overview, a grade, a summary of technical debt, or a before/after quality comparison.

1.0k 3d ago A 49 tokens original MIT

semia

06

berabuddies/Semia

Skill Claude CodeCodex

Audit an agent skill with Semia inside Claude Code. Use when the user asks to run semia scan , "Run Semia audit on this skill", or audit a skill/plugin for behavior risk.

595 1mo ago A 47 tokens original Apache-2.0

berabuddies/Semia

Skill Claude CodeCodex

Deploy a serverless Spark Bitcoin L2 proxy on Vercel with spending limits, auth, and Redis logging. Use when user wants to set up a new proxy, configure env vars, deploy to Vercel, or manage the proxy infrastructure.

595 1mo ago A 59 tokens original Apache-2.0

copywriting

08

berabuddies/Semia

Skill Claude CodeCodex

Write persuasive copy for landing pages, emails, ads, sales pages, and marketing materials. Use when you need to write headlines, CTAs, product descriptions, ad copy, email sequences, or any text meant to drive action. Covers copywriting formulas (AIDA, PAS, FAB), headline writing, emotional triggers, objection…

595 1mo ago A 123 tokens original Apache-2.0

benchmark-rbs

11

Shopify/rubydex

Skill Claude CodeCodex

Benchmark Rubydex indexing performance on RBS core/stdlib, comparing the current branch against main. Measures maximum RSS and execution time.

326 5d ago A 31 tokens

send-private-method

13

Shopify/rubydex

Skill Claude CodeCodex

Remediate a send/send call that reaches a private method, restoring a real public seam instead of bypassing visibility. Use when send is being used to invoke private functionality in a class.

326 5d ago A 49 tokens

commit

14

aviatesk/JETLS.jl

Skill Claude CodeCodex

Use when writing a commit message, and MUST invoke before creating any git commit. Provides commit message format and safety rules.

305 3d ago A 26 tokens original MIT

run-test

15

aviatesk/JETLS.jl

Skill Claude CodeCodex

Use when choosing or running JETLS tests after code changes. Prefer component-specific tests, avoid the full suite unless needed, and use TestRunner for focused iteration.

305 3d ago A 36 tokens original MIT

write-test

16

aviatesk/JETLS.jl

Skill Claude CodeCodex

Use when adding or modifying JETLS tests. Covers test file and module structure, @testset organization, let blocks, withserver usage, and when subroutine tests are sufficient for language-server features.

305 3d ago A 50 tokens original MIT

openlore-brainstorm

17

clay-good/OpenLore

Skill Claude CodeCodex

Transform a feature idea into an annotated story using a Domain Sketch or Constrained Option Tree. Use when asked to brainstorm, explore, or shape a feature before implementation.

290 yesterday A 40 tokens original MIT

clay-good/OpenLore

Skill Claude CodeCodex

Apply a confirmed .openlore/refactor-plan.md with a test gate after each change. Use when asked to execute or continue an OpenLore refactoring plan.

290 yesterday A 41 tokens original MIT

clay-good/OpenLore

Skill Claude CodeCodex

Implement a brownfield story with OpenLore orientation, risk checks, spec validation, tests, and drift detection. Use when asked to implement or continue a story in an existing codebase.

290 yesterday A 44 tokens original MIT

ubs

20

Dicklesworthstone/ultimate_bug_scanner

Skill Claude CodeCodex

Ultimate Bug Scanner - Pre-commit static analysis for AI coding workflows. 18 detection categories, 8 languages, 4-layer analysis engine. The AI agent's quality gate.

285 10d ago C 38 tokens

brainblast-fleet

21

DSB-117/brainblast

Skill Claude CodeCodex

Autonomous VTI sourcing. Discovers popular repositories that depend on a target SDK, fans out a fleet of subagents to scout each one for silent footguns, proves every candidate RED→GREEN, auto-promotes the proven ones into the corpus, logs results to the shared ledger so other fleets skip them, and reports. Run it…

100 1mo ago A 79 tokens original MIT

brainblast-scout

22

DSB-117/brainblast

Skill Claude CodeCodex

Sends an agent on a scouting mission to find real-world coding traps (footguns in popular SDKs/protocols), synthesize the finding into a proven brainblast rule pack, and submit it to the pack registry. Staking $BRAIN on the pack is an optional, opt-in bond (Phase 5) — never required to produce or sell the data.

100 1mo ago A 80 tokens original MIT

brainblast

23

DSB-117/brainblast

Skill Claude CodeCodex

Research external APIs and SDKs before coding. Identifies every external component in a requirements file, browses official sources, and produces a structured handoff report with facts, risks, and answered questions.

100 1mo ago A 43 tokens original MIT

agents-shipgate

24

ThreeMoonsLab/agents-shipgate

Skill Claude CodeCodex

Use when the user wants to run the prominent Agents Shipgate flows — shipgate check, agents-shipgate verify, or shipgate audit --host — for AI agent capability changes, PR release readiness, or coding-agent host grants.

87 2d ago A 56 tokens original Apache-2.0