用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/Dev-Toolbelt/dev-team-agents --skill sast-pipeline命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | sast-pipeline |
| description | SAST — tool selection, CI integration, severity thresholds. |
| Language / Ecosystem | Recommended Tool | Notes |
|---|---|---|
| Any (polyglot) | Semgrep | Rule-based; custom rules; OWASP ruleset available |
| Python | Bandit | Focused on common Python security issues |
| Java / Kotlin | SpotBugs + FindSecBugs | Bytecode analysis; integrates with Maven/Gradle |
| Ruby on Rails | Brakeman | Rails-specific; fast; actionable output |
| JavaScript / TypeScript | npm audit + ESLint security plugin | Dependency CVEs + code patterns |
| Go | gosec | Go-idiomatic; checks crypto, SQL, file perms |
| PHP | PHPCS Security Audit | PSR-compatible; detects SQLi, XSS, CSRF patterns |
| .NET / C# | Security Code Scan | Roslyn analyzer; integrates with VS/Rider |
| iOS / Swift | MobSF | Mobile-specific; covers Swift and Obj-C |
| Android / Kotlin | MobSF | APK and source scanning |
Baseline recommendation: always run Semgrep with the OWASP ruleset as a first pass, then add the language-specific tool.
main / developmain and release branches| Severity | CI Behavior |
|---|---|
| CRITICAL | Block merge; require immediate fix or explicit security-team sign-off |
| HIGH | Block merge; must be resolved or triaged before merge |
| MEDIUM | Warning only; logged in PR comment; does not block |
| LOW / INFO | Informational; aggregated in weekly report |
name: SAST
on: [pull_request]
jobs:
semgrep:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: returntocorp/semgrep-action@v1
with:
config: >-
p/owasp-top-ten
p/secrets
.semgrep/custom-rules.yml
env:
SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }}
semgrep:
image: returntocorp/semgrep
script:
- semgrep --config p/owasp-top-ten --config .semgrep/custom-rules.yml
--error --severity ERROR --severity WARNING
rules:
- if: $CI_PIPELINE_SOURCE == "merge_request_event"
Never suppress a finding without written justification.
user_data = request.get_json() # nosemgrep: direct-use-of-jinja2
.semgrepignore file (file/path-level suppression)# Auto-generated migration files — SQL is template-controlled, not user input
db/migrate/
database/migrations/
# Third-party vendored code — not our responsibility to fix
vendor/
node_modules/
Rule: every suppression must include a comment explaining:
.semgrepignore with comment; request security review for HIGH/CRITICAL suppressionsStore project-specific rules in .semgrep/custom-rules.yml.
rules:
- id: no-raw-sql-format
patterns:
- pattern: cursor.execute("..." % ...)
- pattern: cursor.execute("..." .format(...))
message: "Possible SQL injection via string formatting. Use parameterized queries."
languages: [python]
severity: ERROR
When to write custom rules: