static-analysis-sweep
Installation
SKILL.md
Static Analysis Sweep
Reading code for bugs finds what you thought to look for. A scanner finds the rest. This skill runs the tools, then does the part the tools cannot: deciding which findings are real.
Core Behavior
Scan the diff first, the repo second. Triage every finding. Never hand over a raw scanner dump — an unfiltered report is how real findings get ignored.
The Tools
Semgrep — fast, pattern-based, good defaults, no build required.
semgrep --config=auto --error --quiet . # whole repo
semgrep --config=auto --quiet --baseline-commit=origin/main # diff only
Secret scanning — the highest-value scan per second spent.