aist (ai sast)
Official@aist-ai-sast
Offers specialized static analysis, security auditing, and regression testing capabilities for enterprise software development pipelines and infrastructure.
Agent Skills by aist (ai sast)
Showing 12 vetted skills indexed across 1 GitHub repositories.
mcp-regression-fix
Diagnose MCP regression failures and implement durable fixes across test suites.
aist-security-check
Audit changed files for security risks and produce remediation findings.
mcp-tool-add
Automate secure MCP server tool additions with logging, path guards, and isolated tests.
aist-init-script-generator
Generate project-specific AIST initialization scripts for SAST analysis.
aist-debug
Diagnose root causes of regressions in aist APIs, Celery tasks, and sast-pipeline workflows.
aist-project-profile-analyzer
Generate deterministic path exclusion patterns for AIST project profiles from cloned repositories.
aist-finding-triage
Classify AIST pipeline findings as True Positive or False Positive with evidence.
sast-analyzer-add
Validate and scaffold Dockerfile, analyze.sh, analyzers.yaml entry, and isolated tests for new SAST analyzers.
aist-plan
Decompose complex development work into atomic 2-5 minute test-first tasks.
context-extractor-mcp-audit
Extract contextual information from MCP findings to generate regression tests.
aist-api-review
Review REST API endpoints for isolation, permissions, and serializer usage.
aist-jira-description
Group SAST findings by group_name and project path prefix into Jira tickets.
Frequently Asked Questions About aist (ai sast)
FAQPage SchemaWhat specific security tasks are enabled by these capabilities?▼
These capabilities enable automated security auditing of changed files, triage of pipeline findings into true or false positives, and the systematic review of REST endpoints for permission and serializer vulnerabilities. It further supports the generation of Jira tickets grouped by project path for streamlined remediation tracking.
Which personas benefit most from these technical capabilities?▼
Security engineers, DevOps practitioners, and software developers focused on maintaining secure codebases benefit from these capabilities. They are designed for teams managing complex SAST pipelines who require granular control over regression testing, finding classification, and the rapid integration of new security analysis modules.
What are the prerequisites for implementing these security analysis functions?▼
Implementation requires an existing environment configured for SAST analysis, including access to project repositories and established pipeline infrastructure. Users must provide project-specific profiles and context to enable the generation of initialization scripts, path exclusion patterns, and the scaffolding of new analyzer components.