Search

Semgrep · For developers

29 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Commits changes in the Saleor codebase and works through pre-commit hook failures from ruff, mypy, the GraphQL schema check and the migrations check.

saleor/saleor23k—~575Automated safety check: PassBSD-3-Clause2 days ago
2

Run a Kedro security scan on the full codebase or just a pull request.

kedro-org/kedro11k—~3.3kAutomated safety check: PassUnknown2 days ago
3

Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

trailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0yesterday
4

Code review for the current change, before it is pushed. An agent skill from openqodex/openqodex.

openqodex/openqodex573—~2.5kAutomated safety check: PassApache-2.0today
5

Run a security scan on the kedro-plugins codebase or a pull request.

kedro-org/kedro-plugins119—~3.1kAutomated safety check: PassApache-2.03 days ago
6
6.Sarif ParsingOfficial

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners.

trailofbits/skills7.5k3 repos~4.4kAutomated safety check: NotesCC-BY-SA-4.0yesterday
7

When and how to reach for the companion detectors -- bandit (Python SAST) and trivy (deps + secrets + IaC misconfig) -- alongside the core semgrep/CodeQL/osv/trufflehog toolchain

deonmenezes/mantishack503—~510Automated safety check: PassApache-2.08 days ago
8

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

skrun-dev/skrun210—~1.3kAutomated safety check: PassMIT19 days ago
9

Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by…

hardw00t/ai-security-arsenal105—~2.7kAutomated safety check: PassNo licence5 mo ago
10

Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

Jeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT8 days ago
11

Reference for aster.yaml, covering review models, analyzers, focus areas, include/exclude globs, minconfidence, and the permissions block that gates edits.

Zfinix/aster118—~1.2kAutomated safety check: PassApache-2.02 days ago
12

Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
13

Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

Aedelon/claude-code-blueprint120—~1.6kAutomated safety check: NotesUnknown7 mo ago
14

Gets your own codebase ready for an external security review: sets review goals, runs static analysis, raises test coverage, removes dead code and writes documentation.

trailofbits/skills7.5k—~2.5kAutomated safety check: PassCC-BY-SA-4.0yesterday
15

Integrates CodeQL and Semgrep SAST scanning into GitHub Actions, covering scans on pull requests/pushes, rule tuning to cut false positives, SARIF upload to GitHub Advanced Security, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
16

Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.01 mo ago
17

Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.

vibeeval/vibecosystem532—~4.6kAutomated safety check: PassMIT2 mo ago
18

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

sickn33/agentic-awesome-skills47k1 repo~2.4kAutomated safety check: PassMIT2 days ago
19

Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks

aiskillstore/marketplace4337 repos~3.7kAutomated safety check: PassNo licenceyesterday
20

A skill your agent uses when adding a webhook endpoint for a third party that sends to PostHog, adding an inbound webhook consumer for a provider that already has an endpoint, or migrating a…

PostHog/posthog40k—~3.1kAutomated safety check: PassUnknownyesterday
21

A skill your agent uses when you have a Foundry or Hardhat repository of Solidity or Vyper contracts and want the end-to-end EVM review workflow on native CLIs — a slither static pass, semgrep taint…

mtarcure/claude-vibe-squad165—~1.5kAutomated safety check: PassMIT20 days ago
22

A skill your agent uses when setting up CI/CD pipelines for Frappe apps, configuring GitHub Actions test workflows, or adding linting and security scanning.

Impertio-Studio/Frappe_Claude_Skill_Package189—~3.2kAutomated safety check: NotesMIT24 days ago
23

Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…

petrkindlmann/qa-skills170—~4.9kAutomated safety check: PassMIT4 mo ago
24

Perform static application security testing with tools like Semgrep, CodeQL, and SonarQube.

BagelHole/DevOps-Security-Agent-Skills1.2k—~2.2kAutomated safety check: PassMIT4 mo ago
25

Run semgrep via the mantissemgrep MCP server and triage results into the candidate/confirmed/rejected lifecycle

deonmenezes/mantishack503—~312Automated safety check: PassApache-2.08 days ago
26

A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

ericrisco/rsc-harness180—~2.8kAutomated safety check: NotesMIT2 days ago
27

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

LeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT2 mo ago
28

Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…

sundial-org/awesome-openclaw-skills663—~875Automated safety check: PassNo licence7 mo ago
29

Analyze source code for security vulnerabilities using static analysis tools, custom rules, and CI-integrated scanning pipelines.

seb1n/awesome-ai-agent-skills206—~2.6kAutomated safety check: PassMIT2 mo ago