Developer tool
Semgrep agent skills for Claude Code, Codex and other agents.
- skills
- 51
- official
- 10
- Type
- Developer tool
- Website
- semgrep.dev
- Official GitHub
- semgrep
- Reviews
- See Semgrep on Enlisted
Semgrep skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
Official (10 skills)
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 2 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.4k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 3 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 4 | Run Semgrep static analysis scans and create custom detection rules. | semgrep/ | 322 | — | ~2.3k | Automated safety check: Pass | Unknown | 2 mo ago |
| 5 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.4k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 6 | Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data. | trailofbits/ | 7.4k | — | ~2.3k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 7 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 8 | Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common… | trailofbits/ | 7.4k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 9 | Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. | trailofbits/ | 7.4k | — | ~967 | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 10 | A skill your agent uses when adding a webhook endpoint for a third party that sends to PostHog, adding an inbound webhook consumer for a provider that already has an endpoint, or migrating a… | PostHog/ | 721 | — | ~3.1k | Automated safety check: Pass | MIT | today |
Community
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 11 | Commits changes in the Saleor codebase and works through pre-commit hook failures from ruff, mypy, the GraphQL schema check and the migrations check. | saleor/ | 23k | — | ~575 | Automated safety check: Pass | BSD-3-Clause | yesterday |
| 12 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | yesterday |
| 13 | 13.Semgrep Run Semgrep static analysis scan on a codebase using parallel subagents. | vigolium/ | 138 | 1 repo | ~2.4k | Automated safety check: Notes | MIT | 17 days ago |
| 14 | 14.Sast Semgrep Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. | AgentSecOps/ | 219 | 2 repos | ~2.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 15 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 6 days ago |
| 16 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 219 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 17 | 17.Semgrep Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis. | waybarrios/ | 533 | — | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 18 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 505 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 19 | Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. | skrun-dev/ | 210 | — | ~1.3k | Automated safety check: Pass | MIT | 14 days ago |
| 20 | 20.Code Audit A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification. | zhaoxuya520/ | 40k | 2 repos | ~374 | Automated safety check: Warn | MIT | 15 days ago |
| 21 | Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages. | davila7/ | 32k | 10 repos | ~1.6k | Automated safety check: Pass | MIT | today |
| 22 | Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by… | hardw00t/ | 104 | — | ~2.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 23 | Find similar vulnerabilities and bugs across codebases using pattern-based analysis. | waybarrios/ | 533 | 5 repos | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 24 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 4 days ago |
| 25 | 25.Aster Config Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. | Zfinix/ | 111 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 26 | Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. | KimYx0207/ | 174 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 27 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits. | cyberful/ | 134 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 29 | Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. | Aedelon/ | 120 | — | ~1.6k | Automated safety check: Notes | Unknown | 7 mo ago |
| 30 | Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. | vibeeval/ | 531 | — | ~4.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 33 | 33.Code Audit Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification. | sickn33/ | 47k | 1 repo | ~480 | Automated safety check: Pass | MIT | yesterday |
| 34 | Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | yesterday |
| 35 | Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint… | mtarcure/ | 162 | — | ~1.5k | Automated safety check: Pass | MIT | 16 days ago |
| 37 | Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks | aiskillstore/ | 430 | 6 repos | ~3.7k | Automated safety check: Pass | No licence | today |
| 38 | 38.Semgrep Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape. | alpha-omega-security/ | 231 | — | ~439 | Automated safety check: Pass | MIT | today |
| 39 | A skill your agent uses when setting up CI/CD pipelines for Frappe apps, configuring GitHub Actions test workflows, or adding linting and security scanning. | Impertio-Studio/ | 187 | — | ~3.2k | Automated safety check: Notes | MIT | 20 days ago |
| 40 | Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests… | petrkindlmann/ | 163 | — | ~4.9k | Automated safety check: Pass | MIT | 3 mo ago |
| 41 | Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | BagelHole/ | 1.1k | — | ~2.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 42 | 42.Mitigate Draft operational mitigations for a finding consumers can apply before a fix ships. | alpha-omega-security/ | 231 | — | ~1.3k | Automated safety check: Pass | MIT | today |
| 43 | Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed… | BankrBot/ | 1.2k | — | ~858 | Automated safety check: Pass | No licence | 2 days ago |
| 44 | Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle | deonmenezes/ | 505 | — | ~312 | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 45 | A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 156 | — | ~2.8k | Automated safety check: Notes | MIT | today |
| 46 | Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 47 | Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or… | sundial-org/ | 663 | — | ~875 | Automated safety check: Pass | No licence | 7 mo ago |
| 48 | A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now… | OneWave-AI/ | 322 | — | ~836 | Automated safety check: Pass | MIT | 5 days ago |
Questions, answered from the data.
What is the best Semgrep skill?
Semgrep Security Scan (official) from trailofbits/skills ranks first of the 51 Semgrep skills listed here, with the highest score: its repository has 7.4k GitHub stars, its SKILL.md loads about 3.7k tokens and it has informational notes only in the automated safety check. Next come Semgrep Rule Creator and Semgrep Rule Variant Creator.
Is there an official Semgrep skill?
10 of the 51 Semgrep skills are official, published by the vendor's own GitHub organization: Semgrep Security Scan, Semgrep Rule Creator, Semgrep Rule Variant Creator, Semgrep, Sarif Parsing and 5 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.