Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
.claude/skills/davila7-sast-configuration/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-13 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-21 | ✗→✓ | ▲ Improved | -5% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 23% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 57% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 49% | 0% |
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
This skill provides comprehensive guidance for setting up and configuring SAST tools including Semgrep, SonarQube, and CodeQL.
bash# Semgrep quick start pip install semgrep semgrep --config=auto --error # SonarQube with Docker docker run -d --name sonarqube -p 9000:9000 sonarqube:latest # CodeQL CLI setup gh extension install github/gh-codeql codeql database create mydb --language=python
yaml# GitHub Actions example - name: Run Semgrep uses: returntocorp/semgrep-action@v1 with: config: >- p/security-audit p/owasp-top-ten
bash# .pre-commit-config.yaml - repo: https://github.com/returntocorp/semgrep rev: v1.45.0 hooks: - id: semgrep args: ['--config=auto', '--error']
bash./scripts/run-sast.sh --setup --language python --tools semgrep,sonarqube
yaml# See references/semgrep-rules.md for detailed examples rules: - id: hardcoded-jwt-secret pattern: jwt.encode($DATA, "...", ...) message: JWT secret should not be hardcoded severity: ERROR
bash# PCI-DSS focused scan semgrep --config p/pci-dss --json -o pci-scan-results.json
| Tool | Best For | Language Support | Cost | Integration | |------|----------|------------------|------|-------------| | Semgrep | Custom rules, fast scans | 30+ languages | Free/Enterprise | Excellent | | SonarQube | Code quality + security | 25+ languages | Free/Commercial | Good | | CodeQL | Deep analysis, research | 10+ languages | Free (OSS) | GitHub native |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 18,138 | 13,199 | -27% | 1 | 1 | 0% | 3,017 | 3,717 | +23% | 0 | 0 | — |
case-02 | pass→pass | 13,446 | 13,147 | -2% | 1 | 1 | 0% | 2,304 | 3,621 | +57% | 0 | 0 | — |
case-03 | pass→pass | 14,222 | 11,749 | -17% | 1 | 1 | 0% | 2,320 | 3,446 | +49% | 0 | 0 | — |
case-04 | pass→pass | 5,686 | 4,225 | -26% | 1 | 1 | 0% | 1,031 | 2,201 | +113% | 0 | 0 | — |
case-05 | pass→pass | 5,623 | 3,182 | -43% | 1 | 1 | 0% | 1,077 | 1,941 | +80% | 0 | 0 | — |
case-06 | fail→fail | 11,873 | 13,083 | +10% | 1 | 1 | 0% | 1,802 | 3,380 | +88% | 0 | 0 | — |
case-07 | pass→pass | 6,002 | 5,148 | -14% | 1 | 1 | 0% | 1,113 | 2,265 | +104% | 0 | 0 | — |
case-08 | pass→pass | 3,452 | 4,369 | +27% | 1 | 1 | 0% | 576 | 1,618 | +181% | 0 | 0 | — |
case-09 | fail→fail | 6,587 | 4,437 | -33% | 1 | 1 | 0% | 1,268 | 2,285 | +80% | 0 | 0 | — |
case-10 | pass→pass | 9,941 | 5,511 | -45% | 1 | 1 | 0% | 1,806 | 2,319 | +28% | 0 | 0 | — |
case-11 | pass→pass | 13,076 | 10,519 | -20% | 1 | 1 | 0% | 2,119 | 3,160 | +49% | 0 | 0 | — |
case-12 | pass→pass | 16,082 | 14,151 | -12% | 1 | 1 | 0% | 2,462 | 3,787 | +54% | 0 | 0 | — |
case-13 | fail→pass | 12,367 | 4,525 | -63% | 1 | 1 | 0% | 2,097 | 1,840 | -12% | 0 | 0 | — |
case-14 | pass→pass | 13,709 | 13,145 | -4% | 1 | 1 | 0% | 2,156 | 3,388 | +57% | 0 | 0 | — |
case-15 | pass→pass | 11,349 | 4,883 | -57% | 1 | 1 | 0% | 1,788 | 2,227 | +25% | 0 | 0 | — |
case-16 | pass→pass | 9,191 | 7,404 | -19% | 1 | 1 | 0% | 1,456 | 2,652 | +82% | 0 | 0 | — |
case-17 | pass→pass | 4,938 | 5,681 | +15% | 1 | 1 | 0% | 813 | 2,322 | +186% | 0 | 0 | — |
case-18 | pass→pass | 7,087 | 4,950 | -30% | 1 | 1 | 0% | 1,132 | 2,139 | +89% | 0 | 0 | — |
case-19 | pass→pass | 5,852 | 5,689 | -3% | 1 | 1 | 0% | 1,144 | 1,893 | +65% | 0 | 0 | — |
case-20 | pass→pass | 12,394 | 10,655 | -14% | 1 | 1 | 0% | 2,337 | 3,131 | +34% | 0 | 0 | — |
case-21 | fail→pass | 8,613 | 1,498 | -83% | 1 | 1 | 0% | 1,711 | 1,619 | -5% | 0 | 0 | — |
case-22 | pass→pass | 11,970 | 11,308 | -6% | 1 | 1 | 0% | 2,013 | 3,292 | +64% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.