Search
Security · Semgrep · For developers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Run a Kedro security scan on the full codebase or just a pull request. | kedro-org/ | 11k | — | ~3.3k | Automated safety check: Pass | Unknown | 2 days ago |
| 2 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.5k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 3 | Run a security scan on the kedro-plugins codebase or a pull request. | kedro-org/ | 119 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 4 | Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. | trailofbits/ | 7.5k | 3 repos | ~4.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 5 | When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain | deonmenezes/ | 503 | — | ~510 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 6 | Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. | skrun-dev/ | 210 | — | ~1.3k | Automated safety check: Pass | MIT | 18 days ago |
| 7 | Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by… | hardw00t/ | 105 | — | ~2.7k | Automated safety check: Pass | No licence | 5 mo ago |
| 8 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 8 days ago |
| 9 | Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits. | Zfinix/ | 118 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 10 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults. | Aedelon/ | 120 | — | ~1.6k | Automated safety check: Notes | Unknown | 7 mo ago |
| 12 | Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation. | trailofbits/ | 7.5k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 13 | Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration. | vibeeval/ | 532 | — | ~4.6k | Automated safety check: Pass | MIT | 2 mo ago |
| 16 | Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 17 | Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks | aiskillstore/ | 433 | 7 repos | ~3.7k | Automated safety check: Pass | No licence | yesterday |
| 18 | A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint… | mtarcure/ | 165 | — | ~1.5k | Automated safety check: Pass | MIT | 20 days ago |
| 19 | Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests… | petrkindlmann/ | 170 | — | ~4.9k | Automated safety check: Pass | MIT | 4 mo ago |
| 20 | Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube. | BagelHole/ | 1.2k | — | ~2.2k | Automated safety check: Pass | MIT | 4 mo ago |
| 21 | Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle | deonmenezes/ | 503 | — | ~312 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 22 | A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has… | ericrisco/ | 180 | — | ~2.8k | Automated safety check: Notes | MIT | 2 days ago |
| 23 | Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills. | LeoYeAI/ | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 24 | Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or… | sundial-org/ | 663 | — | ~875 | Automated safety check: Pass | No licence | 7 mo ago |
| 25 | Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines. | seb1n/ | 206 | — | ~2.6k | Automated safety check: Pass | MIT | 2 mo ago |