Skip to content

Static Analysis

Finding bugs and vulnerabilities by inspecting source code without running it.

2 skills and 2 MCP servers tagged Static Analysis.

Skills

All skills

Trail of Bits' CodeQL skill: build databases, run taint-tracking and data-flow queries across eight languages, and model project-specific sources and sinks.

4 views

Trail of Bits' skill for writing production-quality Semgrep rules — pattern design, taint mode for data-flow bugs, and mandatory test-driven validation.

4 views

MCP servers

All MCP servers

MCP: Semgrep MCP

by Semgrep

Semgrep's official MCP server — scan code for security vulnerabilities, write and test custom rules, and pull findings from Semgrep Cloud, from inside an agent session.

Official SonarSource MCP server — pull code-quality issues, security hotspots, quality gates and rule explanations from SonarQube Cloud or Server into your agent.

Related tags

Tags that appear alongside this one, ranked by how often.

All tags