vchirrav-eng/owasp-secure-coding-md · Archived

sast-flawfinder

Run Flawfinder SAST scans on C/C++ code. Detects buffer overflows, format string vulnerabilities, race conditions, and other memory safety issues.

First seen Feb 10, 2026

Installation

$ npx skills add vchirrav-eng/owasp-secure-coding-md --skill sast-flawfinder

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Also in this package

Other skills from vchirrav-eng/owasp-secure-coding-md · top by installs.

npx skills add vchirrav-eng/owasp-secure-coding-md

Browse all from vchirrav-eng/owasp-secure-coding-md

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 17
License license-scan-scancode
Default branch main
Open issues 0
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,888 B
  • docs SUMMARY.md 169 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2 installs

SKILL.md

SAST Scan with Flawfinder (C/C++)

You are a security engineer running static analysis on C/C++ code using Flawfinder.

When to use

Use this skill when asked to perform a SAST scan or security review on C or C++ code.

Prerequisites

  • Flawfinder installed (pip install flawfinder)
  • Verify: flawfinder --version

Instructions

  1. Identify the target — Determine the C/C++ source file(s) or directory to scan.
  2. Run the scan:

``bash flawfinder --json <target-path> > flawfinder-results.json ` - With minimum risk level: flawfinder --minlevel=3 --json <target> - With column info: flawfinder --columns --json <target> - CSV output: flawfinder --csv <target> > results.csv`

  1. Parse the results — Read JSON output and present findings:
| # | Risk Level (0-5) | CWE | File:Line:Column | Function | Finding | Remediation |
|---|-------------------|-----|------------------|----------|---------|-------------|
  1. Summarize — Provide total hits by risk level, critical findings (level 4-5) first, safe alternatives.

Key Risk Categories

Category Dangerous Functions Safe Alternatives
Buffer overflow strcpy, strcat, gets, sprintf strncpy, strncat, fgets, snprintf
Format string printf(user_input) printf("%s", user_input)
Race condition access() + open() (TOCTOU) open() with proper flags
Integer overflow atoi, unchecked malloc strtol with bounds checking
Memory memcpy without bounds Bounded memcpy_s or size checks
Crypto rand(), srand() getrandom(), /dev/urandom