Skip to content
Security
Skill

/sast-bandit

Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns, (2) Identifying hardcoded secrets, SQL injection, command injection, and insecure APIs, (3) Generating

From plugin
secopsagentkit
18331 skills
Install
$ npx -y skills add AgentSecOps/SecOpsAgentKit --skill sast-bandit --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/sast-bandit

Context preview

The summary Claude sees to decide when to auto-load this skill.

Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns, (2) Identifying hardcoded secrets, SQL injection, command injection, and insecure APIs, (3) Generating

SKILL.md

sast-bandit.SKILL.md
name: sast-bandit
description: >
  Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping.
  Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns,
  (2) Identifying hardcoded secrets, SQL injection, command injection, and insecure APIs,
  (3) Generating security reports with severity classifications for CI/CD pipelines,
  (4) Providing remediation guidance with security framework references,
  (5) Enforcing Python security best practices in development workflows.
version: 0.1.0
maintainer: SirAppSec
category: appsec
tags: [sast, bandit, python, vulnerability-scanning, owasp, cwe, security-linting]
frameworks: [OWASP, CWE]
dependencies:
  python: ">=3.8"
  packages: [bandit]
references:
  - https://github.com/PyCQA/bandit
  - https://bandit.readthedocs.io/
  - https://owasp.org/www-project-top-ten/

Bandit Python SAST

Overview

Bandit is a security-focused static analysis tool for Python that identifies common security vulnerabilities and coding anti-patterns. It parses Python code into Abstract Syntax Trees (AST) and executes security plugins to detect issues like hardcoded credentials, SQL injection, command injection, weak cryptography, and insecure API usage. Bandit provides actionable reports with severity classifications aligned to industry security standards.

Quick Start

Scan a Python file or directory for security vulnerabilities:

# Install Bandit
pip install bandit

# Scan single file
bandit suspicious_file.py

# Scan entire directory recursively
bandit -r /path/to/python/project

# Generate JSON report
bandit -r project/ -f json -o bandit_report.json

# Scan with custom config
bandit -r project/ -c .bandit.yaml

Core Workflow

Step 1: Install and Configure Bandit

Install Bandit via pip:

pip install bandit

Create a configuration file `.bandit` or `.bandit.yaml` to customize scans:

# .bandit.yaml
exclude_dirs:
  - /tests/
  - /venv/
  - /.venv/
  - /node_modules/

skips:
  - B101  # Skip assert_used checks in test files

tests:
  - B201  # Flask app run with debug=True
  - B301  # Pickle usage
  - B601  # Shell injection
  - B602  # Shell=True in subprocess

Step 2: Execute Security Scan

Run Bandit against Python codebase:

# Basic scan with severity threshold
bandit -r . -ll  # Report only medium/high severity

# Comprehensive scan with detailed output
bandit -r . -f json -o report.json -v

# Scan with confidence filtering
bandit -r . -i  # Show only high confidence findings

# Exclude specific tests
bandit -r . -s B101,B601

Step 3: Analyze Results

Bandit reports findings with:

  • **Issue Type**: Vulnerability category (e.g., hardcoded_password, sql_injection)
  • **Severity**: LOW, MEDIUM, HIGH
  • **Confidence**: LOW, MEDIUM, HIGH
  • **CWE**: Common Weakness Enumeration reference
  • **Location**: File path and line number

Example output:

>> Issue: [B105:hardcoded_password_string] Possible hardcoded password: 'admin123'
   Severity: Medium   Confidence: Medium
   CWE: CWE-259 (Use of Hard-coded Password)
   Location: app/config.py:12

Step 4: Prioritize Findings

Focus remediation efforts using this priority matrix:

1. **Critical**: HIGH severity + HIGH confidence 2. **High**: HIGH severity OR MEDIUM severity + HIGH confidence 3. **Medium**: MEDIUM severity + MEDIUM confidence 4. **Low**: LOW severity OR LOW confidence

Step 5: Remediate Vulnerabilities

For each finding, consult the bundled `references/remediation_guide.md` for secure coding patterns. Common remediation strategies:

  • **Hardcoded Secrets (B105, B106)**: Use environment variables or secret management services
  • **SQL Injection (B608)**: Use parameterized queries with SQLAlchemy or psycopg2
  • **Command Injection (B602, B605)**: Avoid `shell=True`, use `shlex.split()` for argument parsing
  • **Weak Cryptography (B303, B304)**: Replace MD5/SHA1 with SHA256/SHA512 or bcrypt for passwords
  • **Insecure Deserialization (B301)**: Avoid pickle, use JSON or MessagePack with schema validation

Step 6: Integrate into CI/CD

Add Bandit to CI/CD pipelines to enforce security gates:

# .github/workflows/security-scan.yml
name: Security Scan
on: [push, pull_request]

jobs:
  bandit:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3
      - uses: actions/setup-python@v4
        with:
          python-version: '3.11'
      - name: Install Bandit
        run: pip install bandit
      - name: Run Bandit
        run: bandit -r . -f json -o bandit-report.json
      - name: Check for high severity issues
        run: bandit -r . -ll -f txt || exit 1

Use the bundled script `scripts/bandit_analyzer.py` for enhanced reporting with OWASP mapping.

Security Considerations

  • **Sensitive Data Handling**: Bandit reports may contain code snippets with hardcoded credentials. Ensure reports are stored securely and access is restricted. Use `--no-code` flag to exclude code snippets from reports.
  • **Access Control**: Run Bandit in sandboxed CI/CD environments with read-only access to source code. Restrict write permissions to prevent tampering with security configurations.
  • **Audit Logging**: Log all Bandit executions with timestamps, scan scope, findings count, and operator identity for security auditing and compliance purposes.
  • **Compliance**: Bandit supports SOC2, PCI-DSS, and GDPR compliance by identifying security weaknesses. Document scan frequency, remediation timelines, and exception approvals for audit trails.
  • **False Positives**: Review LOW confidence findings manually. Use inline `# nosec` comments sparingly and document justifications in code review processes.

Bundled Resources

Scripts (`scripts/`)

  • `bandit_analyzer.py` - Enhanced Bandit wrapper that parses JSON output, maps findings to OWASP Top 10, generates HTML reports, and integrates with ticketing systems. Use for comprehensive security reporting.

Referen

Read more
Ships withsecopsagentkit

An assortment of security operations skills for AI coding agents. A collaborative approach to shift-left security using Claude Code skills.

Get the whole plugin
Stats
184
Stars
35
Forks
Maintained
Maintenance
Python
Language
3mo ago
Last commit
8mo ago
Created

Repo: AgentSecOps/SecOpsAgentKit

Other skills on secopsagentkit.