static-analysis - Static Analysis
static-analysis
Static Analysis
Community Security
Description
Code static analysis skill to identify security vulnerabilities, code smells, and quality issues
Use Cases
- Security vulnerability detection
- Code quality review
- Dependency security checks
- CI/CD integration checks
- Compliance verification
Core Capabilities
- Vulnerability Detection: SQL injection, XSS, etc.
- Code Standards: Best practice checks
- Dependency Analysis: Third-party library security
- Report Generation: Clear issue reports
Example
Please perform static security analysis on this code:
```javascriptconst user = req.query.user;const query = `SELECT * FROM users WHERE name = '${user}'`;db.query(query);Identify:
- Security vulnerabilities
- Severity level
- Fix recommendations
- Secure alternative implementation
## Notes
- Static analysis has limitations- Combine with dynamic testing- Focus on high-risk vulnerabilities first- Update rule library regularlyApplicable Roles
Developer DevOps/IT