static-analysis collection: 3 agent skills
- codeql โ Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis.
- sarif-parsing โ Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.
- semgrep โ json, and merges the output to SARIF.