CldKit
HOMEEXPLORERECIPESSUBMITCLIAI CURATORSIGN IN
SIGN IN
CldKit
ExploreRecipesSubmitCLI·AboutPrivacyTerms

Built for AI developers. Every component reviewed.

© 2026 CldKit

Language
Home>Explore>Static Analysis Skill

Static Analysis Skill

90/100
Skill
by Trail of Bits@trailofbits
CC-BY-SA-4.0

Runs CodeQL and Semgrep for automated security vulnerability detection in codebases.

Source

Review Scores

Security34/35Maintain.30/35Usability26/30
Security34/35
Maintain.30/35
Usability26/30
Evidence:
high
Reviewed Feb 20, 2026
Review soon

Reviewed Version

1.0.0

Latest Version

1.0.0

Freshness

Review is 120 days old; refresh it soon.

Scores reflect the version reviewed and may change with updates.

Security Audit - Pending

Security audit has not been performed yet for this version.

Live Playground

Open Full Page

Live Sandbox

Run this skill in an isolated environment

$ ls
skill.md src/ package.json
$ claude -p "review the code in src/"
Analyzing source files...

Sign in to try this skill in a live sandbox.

Overview

When to Use

When NOT to Use

Setup

ls /workspace

Troubleshooting

Scenes

Tags

Used in Recipes

  • Security Pipeline(Scans codebase for vulnerability patterns using SAST rules)
  • AI-Powered Review Pipeline(Scans for security vulnerabilities and code quality patterns)
  • Agent Security Review(Finds unsafe code patterns in agent implementation)
  • Secure File Operations(Reviews touched code for unsafe patterns)

More by Trail of Bits

  • Agentic Actions Auditor
    Skill
    90/100
  • C/C++ Security Review
    Skill
    90/100
  • Constant Time Analysis
    Skill
    90/100
  • CodeQL Analysis
    Skill
    90/100
Skill

Install

ls /workspace

CldKit CLI

cldkit install static-analysis
cldkit info static-analysis

Install CLI: npm i -g @cldkit/cli

Version

1.0.0

Stars

3,400

License

CC-BY-SA-4.0

Compatibility

claude-code

Links

GitHub Source@trailofbits
security
code
codeql
semgrep
sast
vulnerability