sast-configuration

Configure Semgrep, SonarQube, and CodeQL for automated vulnerability detection.

3|1|Updated Dec 30, 2025
One-click install
npx skills add https://github.com/48Nauts-Operator/opencode-baseline --skill sast-configuration-48nauts-operator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: sast-configuration
Source: https://github.com/48Nauts-Operator/opencode-baseline/tree/main/.opencode/skill/security/sast-configuration
Command: npx skills add https://github.com/48Nauts-Operator/opencode-baseline --skill sast-configuration-48nauts-operator

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes assets (resource) and scripts (resource) and references (resource) components.

What problem does it solve?

Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code.

Core Features & Use Cases

  • Semgrep, SonarQube, and CodeQL configuration and rule management
  • CI/CD integration and quality gates
  • False positive tuning and remediation guidance

Quick Start

Initialize Semgrep config and wire it into a GitHub Actions workflow for baseline scanning.