vchirrav-eng/owasp-secure-coding-md · Archived

sast-detekt

Run detekt static analysis on Kotlin code with security-focused rules. Detects hardcoded secrets, insecure crypto, and code quality issues affecting security.

First seen Feb 10, 2026

Installation

$ npx skills add vchirrav-eng/owasp-secure-coding-md --skill sast-detekt

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Also in this package

Other skills from vchirrav-eng/owasp-secure-coding-md · top by installs.

npx skills add vchirrav-eng/owasp-secure-coding-md

Browse all from vchirrav-eng/owasp-secure-coding-md

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 17
License license-scan-scancode
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,895 B
  • docs SUMMARY.md 177 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2 installs

SKILL.md

SAST Scan with detekt (Kotlin)

You are a security engineer running static analysis on Kotlin code using detekt.

When to use

Use this skill when asked to perform a SAST scan or security review on Kotlin code.

Prerequisites

  • detekt installed (Gradle plugin or standalone CLI)
  • Verify: detekt --version or check Gradle task ./gradlew detekt

Instructions

  1. Identify the target — Determine the Kotlin source directory.
  2. Run the scan:

Standalone CLI: ``bash detekt --input <src-path> --report json:detekt-results.json ``

Gradle: ``bash ./gradlew detekt ` - Custom config: detekt --input <src> --config detekt-config.yml --report json:results.json`

  1. Parse the results — Read JSON output and present findings:
| # | Severity | Rule | Rule Set | File:Line | Finding | Remediation |
|---|----------|------|----------|-----------|---------|-------------|
  1. Summarize — Provide total issues by severity, security-relevant findings first, and fixes.

Key Security-Relevant detekt Rules

Rule Description
TooGenericExceptionCaught Catching generic exceptions hides security errors
SwallowedException Swallowed exceptions may hide security failures
PrintStackTrace Stack traces may leak sensitive information
ThrowingExceptionsWithoutMessageOrCause Missing context in security-related errors
MagicNumber Hardcoded values (may include ports, keys)
MaxLineLength / ComplexMethod Complex code harder to audit for security

Tip: For deeper Kotlin security analysis, combine detekt with Semgrep (--config=p/kotlin).