bagelhole/sast-scanning
Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. Identify security vulnerabilities in source code before deployment. Use when implementing secure SDLC, code review automation, or security gates in CI/CD pipelines.
npx skills add https://github.com/BagelHole/DevOps-Security-Agent-Skills --skill sast-scanning
Take bagelhole/sast-scanning from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.
The instructions reference pip, npm, brew, gem.
Without those the skill loads but fails at the first command.