sast

Installation
SKILL.md

Source code hunt on: $ARGUMENTS

ALL agents dispatched by this command MUST use model: "inherit" in the Agent tool call, EXCEPT sast-flow-tracer and sast-gap-analyzer which MUST use model: "opus" (these require cross-file reasoning that benefits from maximum reasoning depth regardless of what the orchestrator inherits).

Read rules/hunting.md FIRST. Rules 0, 2, 9, 14 apply to SAST. Read skills/sast-methodology/SKILL.md for reference.

Why This Pipeline Exists

A single agent asked to "find vulnerabilities" will hallucinate plausible-looking bugs. This pipeline decomposes the task into focused steps:

Installs
17
GitHub Stars
812
First Seen
May 10, 2026
sast — h-mmer/pentest-agents