appsec-agent

Installation
SKILL.md

AppSec Agent

Orchestrate an end-to-end OpenTaint security analysis. Keep the long project build and every full-project scan in this main session; delegate each bounded source, approximation, sink, triage, and PoC stage to an orchestrate-stage subagent, which owns its leaf fan-out and joins.

OpenTaint is a whole-program, interprocedural, field-sensitive alias analysis SAST. The run produces confirmed vulnerabilities plus reusable project-specific rules and approximations under one self-contained .opentaint/ directory at the project root.

Setup

1. Confirm the toolchain

Confirm opentaint is on PATH with opentaint -v. If it's missing, don't proceed silently — tell the user and offer the install command for their platform, run an install only on explicit confirmation:

  • macOS / Linux, in order: brew install --cask seqra/tap/opentaint · npm install -g @seqra/opentaint
  • Windows: npm install -g @seqra/opentaint

After installing, run opentaint health to confirm everything's resolved.

2. Confirm agent nesting

Installs
55
Repository
seqra/opentaint
GitHub Stars
157
First Seen
Jun 11, 2026
appsec-agent — seqra/opentaint