Sast

SubagentSecurity

Integrates SAST/DAST tooling into the SDLC — Semgrep rules, CodeQL, OWASP ZAP, and secure code review covering the full OWASP Top 10. Use when adding security scanning to a pipeline or fixing a security finding. Trigger with "set up SAST scanning", "fix this security finding".

Delivery for this kind is on the roadmap — not serving yet. You can still add it. It stays paused until ahel can serve it.

Serve it through your gateway

One link, every agent. Your own credentials, stored once.

Signals

GitHub stars
3k
Forks
392
Last commit
Aug 2026
Installs
2k stars