Search
Semgrep · For devops and sre engineers
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Semgrep Run Semgrep static analysis scan on a codebase using parallel subagents. | vigolium/ | 140 | 1 repo | ~2.4k | Automated safety check: Notes | MIT | 21 days ago |
| 2 | Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file. | trailofbits/ | 7.5k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 3 | Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping. | AgentSecOps/ | 220 | 2 repos | ~2.4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 4 | Aggregates scanner results into DefectDojo, deduplicates findings, tracks remediation SLAs and prepares compliance reports across products and pipelines. | AgentSecOps/ | 220 | — | ~2.3k | Automated safety check: Pass | Unknown | 5 mo ago |
| 5 | Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. | trailofbits/ | 7.5k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 6 | Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. | trailofbits/ | 7.5k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 7 | 7.Semgrep Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis. | waybarrios/ | 534 | — | ~2.4k | Automated safety check: Pass | MIT | 5 days ago |
| 8 | Run Semgrep static analysis scans and create custom detection rules. | semgrep/ | 324 | — | ~2.3k | Automated safety check: Pass | Unknown | 2 mo ago |
| 9 | A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification. | zhaoxuya520/ | 41k | 2 repos | ~374 | Automated safety check: Warn | MIT | 19 days ago |
| 10 | Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages. | davila7/ | 33k | 11 repos | ~1.6k | Automated safety check: Pass | MIT | today |
| 11 | Find similar vulnerabilities and bugs across codebases using pattern-based analysis. | waybarrios/ | 534 | 5 repos | ~1.4k | Automated safety check: Pass | MIT | 5 days ago |
| 12 | Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. | KimYx0207/ | 174 | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 13 | Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits. | cyberful/ | 135 | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 15 | Expands one confirmed or suspected vulnerability into a Trailmark graph neighborhood of variant candidates by finding sibling functions, shared callers and callees, common sensitive sinks, common… | trailofbits/ | 7.5k | — | ~1.1k | Automated safety check: Notes | CC-BY-SA-4.0 | yesterday |
| 16 | Hunts for the other instances of a bug already found — the variants of one root cause across a codebase. | trailofbits/ | 7.5k | — | ~967 | Automated safety check: Pass | CC-BY-SA-4.0 | yesterday |
| 17 | 17.Code Audit Authorized source-code security review and SAST workflows: Semgrep and CodeQL pattern hunting, dangerous API identification, and fix verification. | sickn33/ | 47k | 1 repo | ~480 | Automated safety check: Pass | MIT | 2 days ago |
| 18 | Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | 19.Semgrep Run semgrep's p/security-audit and p/secrets rulesets and map hits into the findings shape. | alpha-omega-security/ | 242 | — | ~439 | Automated safety check: Pass | MIT | yesterday |
| 20 | A skill your agent uses when setting up CI/CD pipelines for Frappe apps, configuring GitHub Actions test workflows, or adding linting and security scanning. | Impertio-Studio/ | 189 | — | ~3.2k | Automated safety check: Notes | MIT | 24 days ago |
| 21 | 21.Mitigate Draft operational mitigations for a finding consumers can apply before a fix ships. | alpha-omega-security/ | 242 | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 22 | Audit trending repos for real exploitable vulnerabilities and disclose responsibly — Private Vulnerability Reporting for code flaws and verified secrets, public PRs only for already-disclosed… | BankrBot/ | 1.2k | — | ~858 | Automated safety check: Pass | No licence | yesterday |
| 23 | 23.Warden Scan Automated SAST + dependency vulnerability scan. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~750 | Automated safety check: Notes | MIT | yesterday |
| 24 | A skill your agent uses to run real static analysis over a diff or repo before shipping — Semgrep, CodeQL, secret scanning, dependency CVEs — and triage the findings into what must be fixed now… | OneWave-AI/ | 336 | — | ~836 | Automated safety check: Pass | MIT | 9 days ago |