sast
Installation
SKILL.md
Source code hunt on: $ARGUMENTS
ALL agents dispatched by this command MUST use model: "inherit" in the Agent tool call,
EXCEPT sast-flow-tracer and sast-gap-analyzer which MUST use model: "opus" (these
require cross-file reasoning that benefits from maximum reasoning depth regardless of
what the orchestrator inherits).
Read rules/hunting.md FIRST. Rules 0, 2, 9, 14 apply to SAST. Read skills/sast-methodology/SKILL.md for reference.
Why This Pipeline Exists
A single agent asked to "find vulnerabilities" will hallucinate plausible-looking bugs. This pipeline decomposes the task into focused steps: