From sast-sca
Run or ingest static application security testing (SAST) results on a codebase, triage them to remove false positives, and confirm the real issues with code evidence and remediation. Use when reviewing source code for security flaws or cleaning up noisy scanner output.
How this skill is triggered — by the user, by Claude, or both
Slash command
/sast-sca:sast-reviewThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A triaged SAST finding set: confirmed, code-evidenced issues mapped to CWE and
A triaged SAST finding set: confirmed, code-evidenced issues mapped to CWE and ranked — with the false positives filtered out.
web-app-security / api-security).security-reporting:cvss) weighted by reachability;
prioritize reachable, high-impact issues.A triaged findings table: id · CWE · file:line · class · reachability · TP/FP ·
severity · remediation. Confirmed issues → security-reporting:finding.
SAST is high-recall, low-precision — the value you add is triage. Always trace source→sink before accepting a finding, and flag what needs dynamic confirmation rather than over-claiming. Tune rules to cut recurring false positives.
Provides UI/UX resources: 50+ styles, color palettes, font pairings, guidelines, charts for web/mobile across React, Next.js, Vue, Svelte, Tailwind, React Native, Flutter. Aids planning, building, reviewing interfaces.
Fetches up-to-date documentation from Context7 for libraries and frameworks like React, Next.js, Prisma. Use for setup questions, API references, and code examples.
npx claudepluginhub jassics/awesome-claude-security --plugin sast-sca