Developer tool

Semgrep agent skills for Claude Code, Codex and other agents.

Fast static analysis tool for finding bugs and security issues with custom rules.
skills
51
official
10
Type
Developer tool
Website
semgrep.dev
Official GitHub
semgrep
Reviews
See Semgrep on Enlisted

Semgrep skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Official (10 skills)

Official Semgrep skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.05 days ago
2

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.05 days ago
3

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.4k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.05 days ago
4
4.SemgrepOfficial

Run Semgrep static analysis scans and create custom detection rules.

semgrep/skills322—~2.3kAutomated safety check: PassUnknown2 mo ago
5
5.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.05 days ago
6

Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data.

trailofbits/skills7.4k—~2.3kAutomated safety check: PassCC-BY-SA-4.05 days ago
7

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

trailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.05 days ago
8

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common…

trailofbits/skills7.4k—~1.1kAutomated safety check: NotesCC-BY-SA-4.05 days ago
9

Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.

trailofbits/skills7.4k—~967Automated safety check: PassCC-BY-SA-4.05 days ago
10

A skill your agent uses when adding a webhook endpoint for a third party that sends to PostHog, adding an inbound webhook consumer for a provider that already has an endpoint, or migrating a…

PostHog/posthog-foss721—~3.1kAutomated safety check: PassMITtoday

Community

Community Semgrep skills
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
11

Commits changes in the Saleor codebase and works through pre-commit hook failures from ruff, mypy, the GraphQL schema check and the migrations check.

saleor/saleor23k—~575Automated safety check: PassBSD-3-Clauseyesterday
12

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknownyesterday
13

Run Semgrep static analysis scan on a codebase using parallel subagents.

vigolium/piolium1381 repo~2.4kAutomated safety check: NotesMIT17 days ago
14

Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

AgentSecOps/SecOpsAgentKit2192 repos~2.4kAutomated safety check: PassUnknown5 mo ago
15

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.06 days ago
16

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit219—~2.3kAutomated safety check: PassUnknown5 mo ago
17

Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

waybarrios/opencode-power-pack533—~2.4kAutomated safety check: PassMITyesterday
18

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack505—~510Automated safety check: PassApache-2.04 days ago
19

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

skrun-dev/skrun210—~1.3kAutomated safety check: PassMIT14 days ago
20

A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

zhaoxuya520/reverse-skill40k2 repos~374Automated safety check: WarnMIT15 days ago
21

Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

davila7/claude-code-templates32k10 repos~1.6kAutomated safety check: PassMITtoday
22

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by…

hardw00t/ai-security-arsenal104—~2.7kAutomated safety check: PassNo licence5 mo ago
23

Find similar vulnerabilities and bugs across codebases using pattern-based analysis.

waybarrios/opencode-power-pack5335 repos~1.4kAutomated safety check: PassMITyesterday
24

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT4 days ago
25

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

Zfinix/aster111—~1.2kAutomated safety check: PassApache-2.0yesterday
26

Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.

KimYx0207/Kim_Service174—~1.2kAutomated safety check: PassMITyesterday
27

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
28

Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

cyberful/cyberful134—~1.3kAutomated safety check: PassAGPL-3.01 mo ago
29

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

Aedelon/claude-code-blueprint120—~1.6kAutomated safety check: NotesUnknown7 mo ago
30

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
31

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
32

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

vibeeval/vibecosystem531—~4.6kAutomated safety check: PassMIT1 mo ago
33

Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification.

sickn33/agentic-awesome-skills47k1 repo~480Automated safety check: PassMITyesterday
34

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

sickn33/agentic-awesome-skills47k1 repo~2.4kAutomated safety check: PassMITyesterday
35

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
36

A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint…

mtarcure/claude-vibe-squad162—~1.5kAutomated safety check: PassMIT16 days ago
37

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

aiskillstore/marketplace4306 repos~3.7kAutomated safety check: PassNo licencetoday
38

Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape.

alpha-omega-security/scrutineer231—~439Automated safety check: PassMITtoday
39

A skill your agent uses when setting up CI/CD pipelines for Frappe apps, configuring GitHub Actions test workflows, or adding linting and security scanning.

Impertio-Studio/Frappe_Claude_Skill_Package187—~3.2kAutomated safety check: NotesMIT20 days ago
40

Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

petrkindlmann/qa-skills163—~4.9kAutomated safety check: PassMIT3 mo ago
41

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

BagelHole/DevOps-Security-Agent-Skills1.1k—~2.2kAutomated safety check: PassMIT4 mo ago
42

Draft operational mitigations for a finding consumers can apply before a fix ships.

alpha-omega-security/scrutineer231—~1.3kAutomated safety check: PassMITtoday
43

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

BankrBot/skills1.2k—~858Automated safety check: PassNo licence2 days ago
44

Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle

deonmenezes/mantishack505—~312Automated safety check: PassApache-2.04 days ago
45

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

ericrisco/rsc-harness156—~2.8kAutomated safety check: NotesMITtoday
46

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT2 mo ago
47

Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…

sundial-org/awesome-openclaw-skills663—~875Automated safety check: PassNo licence7 mo ago
48

A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now…

OneWave-AI/claude-skills322—~836Automated safety check: PassMIT5 days ago

Questions, answered from the data.

What is the best Semgrep skill?

Semgrep Security Scan (official) from trailofbits/skills ranks first of the 51 Semgrep skills listed here, with the highest score: its repository has 7.4k GitHub stars, its SKILL.md loads about 3.7k tokens and it has informational notes only in the automated safety check. Next come Semgrep Rule Creator and Semgrep Rule Variant Creator.

Is there an official Semgrep skill?

10 of the 51 Semgrep skills are official, published by the vendor's own GitHub organization: Semgrep Security Scan, Semgrep Rule Creator, Semgrep Rule Variant Creator, Semgrep, Sarif Parsing and 5 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.