sast-configuration - Configure SAST tools for automated vulnerability detection
Provides guidance for setting up and configuring SAST tools including Semgrep, SonarQube, and CodeQL for automated vulnerability detection.
Tags
Updated: 2026-09-16Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Create custom security rules
- Configure SonarQube quality gates
- Integrate SAST into CI/CD
- Tune rules and suppressions
- Set up CodeQL analysis
Inputs
- Source code repositories
- CI/CD pipeline configurations
- Compliance requirements
- API tokens and credentials
Outputs
- Semgrep configuration files
- SonarQube quality profiles
- SARIF result files
- Automated SAST execution scripts
Requirements
- Source code and pipeline access
- Installed SAST tools or Docker
- Network connectivity and API credentials
