Search

Semgrep

51 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Commits changes in the Saleor codebase and works through pre-commit hook failures from ruff, mypy, the GraphQL schema check and the migrations check.

saleor/saleor23k—~575Automated safety check: PassBSD-3-Clausetoday
2

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknownyesterday
3

Run Semgrep static analysis scan on a codebase using parallel subagents.

vigolium/piolium1401 repo~2.4kAutomated safety check: NotesMIT19 days ago
4

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.02 days ago
5

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

openqodex/openqodex470—~2.4kAutomated safety check: PassApache-2.0yesterday
6

Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

AgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassUnknown5 mo ago
7

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.0yesterday
8

Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines.

AgentSecOps/SecOpsAgentKit220—~2.3kAutomated safety check: PassUnknown5 mo ago
9

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

trailofbits/skills7.4k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.02 days ago
10

Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

trailofbits/skills7.4k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
11

Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

waybarrios/opencode-power-pack533—~2.4kAutomated safety check: PassMIT3 days ago
12
12.SemgrepOfficial

Run Semgrep static analysis scans and create custom detection rules.

semgrep/skills322—~2.3kAutomated safety check: PassUnknown2 mo ago
13
13.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.4k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.02 days ago
14

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack504—~510Automated safety check: PassApache-2.06 days ago
15

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

skrun-dev/skrun210—~1.3kAutomated safety check: PassMIT17 days ago
16

A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

zhaoxuya520/reverse-skill40k2 repos~374Automated safety check: WarnMIT17 days ago
17

Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.

davila7/claude-code-templates32k11 repos~1.6kAutomated safety check: PassMITtoday
18

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by…

hardw00t/ai-security-arsenal104—~2.7kAutomated safety check: PassNo licence5 mo ago
19

Find similar vulnerabilities and bugs across codebases using pattern-based analysis.

waybarrios/opencode-power-pack5335 repos~1.4kAutomated safety check: PassMIT3 days ago
20

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT6 days ago
21

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

Zfinix/aster113—~1.2kAutomated safety check: PassApache-2.0today
22

Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.

KimYx0207/Kim_Service174—~1.2kAutomated safety check: PassMIT3 days ago
23

Overlays SARIF results, weAudit annotations and binary-analysis exports onto a Trailmark code graph so each finding can be read next to blast radius and taint data.

trailofbits/skills7.4k—~2.3kAutomated safety check: PassCC-BY-SA-4.02 days ago
24

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
25

Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

cyberful/cyberful135—~1.3kAutomated safety check: PassAGPL-3.01 mo ago
26

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

Aedelon/claude-code-blueprint120—~1.6kAutomated safety check: NotesUnknown7 mo ago
27

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

trailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.02 days ago
28

Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common…

trailofbits/skills7.4k—~1.1kAutomated safety check: NotesCC-BY-SA-4.02 days ago
29
29.Variant AnalysisOfficial

Hunts for the other instances of a bug already found — the variants of one root cause across a codebase.

trailofbits/skills7.4k—~967Automated safety check: PassCC-BY-SA-4.02 days ago
30

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
31

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
32

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

vibeeval/vibecosystem531—~4.6kAutomated safety check: PassMIT2 mo ago
33

Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification.

sickn33/agentic-awesome-skills47k1 repo~480Automated safety check: PassMITtoday
34

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

sickn33/agentic-awesome-skills47k1 repo~2.4kAutomated safety check: PassMITtoday
35

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

aiskillstore/marketplace4307 repos~3.7kAutomated safety check: PassNo licencetoday
36

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
37

A skill your agent uses when adding a webhook endpoint for a third party that sends to PostHog, adding an inbound webhook consumer for a provider that already has an endpoint, or migrating a…

PostHog/posthog40k—~3.1kAutomated safety check: PassUnknowntoday
38

A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint…

mtarcure/claude-vibe-squad164—~1.5kAutomated safety check: PassMIT19 days ago
39

Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape.

alpha-omega-security/scrutineer239—~439Automated safety check: PassMITtoday
40

A skill your agent uses when setting up CI/CD pipelines for Frappe apps, configuring GitHub Actions test workflows, or adding linting and security scanning.

Impertio-Studio/Frappe_Claude_Skill_Package188—~3.2kAutomated safety check: NotesMIT22 days ago
41

Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

petrkindlmann/qa-skills168—~4.9kAutomated safety check: PassMIT4 mo ago
42

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

BagelHole/DevOps-Security-Agent-Skills1.1k—~2.2kAutomated safety check: PassMIT4 mo ago
43

Draft operational mitigations for a finding consumers can apply before a fix ships.

alpha-omega-security/scrutineer239—~1.3kAutomated safety check: PassMITtoday
44

Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed…

BankrBot/skills1.2k—~858Automated safety check: PassNo licence4 days ago
45

Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle

deonmenezes/mantishack504—~312Automated safety check: PassApache-2.06 days ago
46

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

ericrisco/rsc-harness174—~2.8kAutomated safety check: NotesMIT2 days ago
47

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT2 mo ago
48

Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace.

jeremylongshore/tons-of-skills-marketplace2.8k—~750Automated safety check: NotesMITyesterday