# What Is the Code-Audit SAST Workflow? A Deep Dive into the reverse‑skill Security Framework

> Understand the code-audit SAST workflow a four-stage process for threat modeling, automated scanning, manual verification, and deliverable production. Enhance your security.

- Repository: [ZhaoXu/reverse-skill](https://github.com/zhaoxuya520/reverse-skill)
- Tags: deep-dive
- Published: 2026-08-20

---

**The code‑audit SAST workflow is a four‑stage human‑in‑the‑loop process covering threat‑model scoping, automated scanning, manual verification of findings, and structured deliverable production.**

The `reverse-skill` repository by zhaoxuya520 provides a comprehensive, reusable methodology for conducting **Static Application Security Testing (SAST)** audits. According to the source code, this workflow is defined in [`skills/code-audit/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/code-audit/SKILL.md) and emphasizes combining automated tooling with analyst judgment to produce actionable security findings. Security teams use it to systematically identify and validate vulnerabilities in production codebases across multiple languages.

---

## The Four Stages of the SAST Workflow

The code‑audit skill structures every engagement into sequential phases. Each stage includes concrete artifacts and checklists to ensure consistent, defensible results.

### Stage 1: Scope Definition and Threat Modeling

Before any scanning begins, analysts map the attack surface. The workflow mandates documenting **trust boundaries**, **high‑value assets**, and **input vectors** in [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md) lines 25–30.

Key checklist items from the source include:

- **Trust boundaries**: User input, file operations, deserialization, SSRF endpoints, and authentication middleware
- **High‑value assets**: Authentication systems, payment flows, administrative interfaces, and cryptographic key handling

This scoping prevents "tool‑spray" audits and directs attention to code paths with actual security impact.

### Stage 2: Automated SAST Scanning

The workflow supports **language‑agnostic and language‑specific scanners**. The [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md) file (lines 32–38) provides ready‑to‑run commands for popular tools:

```bash

# Semgrep with auto‑detection of framework and language

semgrep --config auto .

# OWASP Top‑10 coverage via Semgrep ruleset

semgrep --config p/owasp-top-ten .

```

Additional tool invocations supported by the repository:

```bash

# CodeQL database creation and query execution for Python

codeql database create --language=python --source-root=. codeql-db
codeql query run --database=codeql-db python/ql/src/security/CWE-798.ql

# Bandit for Python‑specific checks

bandit -r .

# Gosec for Go projects

gosec ./...

```

The [`skills/tool-index.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/tool-index.md) (generated) tracks which tools are active per project and their configuration file locations.

### Stage 3: Manual Verification of Findings

Automated hits require human validation. As specified in [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md) lines 40–47, analysts must answer three questions for every finding:

- **Reachability?** — Can attacker‑controlled data actually reach this code path?
- **Exploitability?** — Is there a practical proof of concept?
- **False positive risk?** — Is the tool misinterpreting safe patterns?

The companion file [`skills/code-audit/references/sast-review-checklist.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/code-audit/references/sast-review-checklist.md) provides supplemental coverage checks for:

- External input handling
- Authentication and authorization gaps
- Unsafe deserialization
- Server‑Side Request Forgery (SSRF)
- Secret leakage and hardcoded credentials
- Dangerous system calls

### Stage 4: Structured Deliverable Production

Verified findings are documented in a standardized format. Per [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md) lines 49–54, each entry must include:

| Component | Description |
|-----------|-------------|
| **Location** | File path and line number |
| **Data flow** | How untrusted input propagates to the sink |
| **PoC** | Reproduction command or payload |
| **Remediation** | Specific code‑level fix |
| **ATT&CK ID** | (Optional) MITRE technique mapping |
| **CWE ID** | (Optional) Weakness taxonomy reference |

Example deliverable template:

```bash
cat <<EOF > findings.md
**Finding:** Potential SQL injection in src/app/user.py:42
- **Data flow:** User‑controlled username → execute(sql)  
- **PoC:** curl -X POST ...  
- **Remediation:** Use parameterized queries (cursor.execute(sql, params))
- **ATT&CK:** T1190 (Exploit Public‑Facing Application)  
- **CWE:** 89 (Improper Neutralization of Special Elements used in an SQL Command)
EOF

```

---

## Key Implementation Files

The SAST workflow is materialized through specific files in the repository:

| File | Purpose |
|------|---------|
| [`skills/code-audit/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/code-audit/SKILL.md) | Primary workflow definition, threat model checklist, tool commands, and output format |
| [`skills/code-audit/references/sast-review-checklist.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/code-audit/references/sast-review-checklist.md) | Concise verification reference for manual review |
| [`skills/MASTER-ROUTING.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/MASTER-ROUTING.md) | Skill registration in the repository's routing matrix |
| [`skills/tool-index.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/tool-index.md) | Generated index of active SAST tools and configs |
| [`docs/ARCHITECTURE.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/docs/ARCHITECTURE.md) | Platform‑agnostic architecture context |

---

## Summary

- The **code‑audit SAST workflow** combines **automated scanning** with **mandatory manual verification** to reduce false positives and improve finding quality.
- Four stages—**scope/threat model**, **automated scan**, **manual verification**, and **deliverable production**—provide repeatable structure.
- Core definitions live in [`skills/code-audit/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/code-audit/SKILL.md) with tool‑agnostic and tool‑specific commands for Semgrep, CodeQL, Bandit, and gosec.
- The **human‑in‑the‑loop** requirement ensures only validated, exploitable issues reach final reports with complete remediation guidance.

---

## Frequently Asked Questions

### What SAST tools does the reverse‑skill workflow support?

The workflow supports **Semgrep**, **CodeQL**, **Bandit**, **gosec**, and **SpotBugs** according to [`SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/SKILL.md). Commands are provided for both general‑purpose scanning (`semgrep --config auto`) and security‑focused rulesets (`semgrep --config p/owasp-top-ten`).

### How does the workflow reduce false positives from automated scanners?

Stage 3 mandates **manual verification** where analysts assess reachability, exploitability, and false‑positive risk for every automated hit. The [`sast-review-checklist.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/sast-review-checklist.md) reference file provides additional coverage checks to guide this validation.

### What must be included in a code‑audit deliverable?

Each finding requires six elements: **location**, **data flow description**, **proof of concept**, **remediation advice**, and optional **ATT&CK** and **CWE** identifiers. This structure ensures findings are actionable for development teams.

### Where is the SAST workflow defined in the repository?

The primary definition is in [`skills/code-audit/SKILL.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/code-audit/SKILL.md) (lines 25–54), with supporting checklists in [`skills/code-audit/references/sast-review-checklist.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/code-audit/references/sast-review-checklist.md). The skill is registered in [`skills/MASTER-ROUTING.md`](https://github.com/zhaoxuya520/reverse-skill/blob/main/skills/MASTER-ROUTING.md) for integration with the broader reverse‑skill framework.