AgentReadyHomeAgent ListingRuntimePricing

← Agent Listing

sast-configuration

Agent SkillsFreeOpen Source

Configure Semgrep, SonarQube, and CodeQL SAST scanning and custom rules in CI/CD.

🛡️ AgentReady threat assessment

MAESTRO 7-layer threat model + OWASP AIVSS risk score for sast-configuration, derived from its capabilities.

AIVSS 8.4 · High
View MAESTRO 7-layer threat model →

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.

Overview

An Agent Skill that guides the agent to set up static application security testing: Semgrep, SonarQube, and CodeQL configuration, custom rule authoring, quality gates, and false-positive tuning. It injects DevSecOps pipeline patterns and can compose multiple SAST tools for defense-in-depth.

Key features and capabilities

Use cases