Official agent skill

Codeql

by elastic in elastic/kibana

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

OfficialCustom licenceAuto-check passedSecurity

Install Codeql

skills CLI
$ npx skills add elastic/kibana --skill codeql -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/kibana codeql --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/kibana.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/codeql .claude/skills/codeql && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codeql
GitHub stars
21k
Token cost
~1.7k tokens
SKILL.md length
516 words
Files
3 (incl. scripts)
Skills in repo
40
Repo updated
First seen
Licence
Custom licence

At a glance

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

  • Works in 4 steps: Lists recent CodeQL analyses for the ref → Fetches full SARIF JSON (with rule… → Prints formatted results (rule,… → …
  • Debugging CodeQL queries
  • SKILL.md covers Project Layout, Running Queries Locally (Full…, Running CodeQL Unit Tests and Fetching Remote SARIF / Scan…, plus 4 more sections
  • Runs JavaScript scripts from its folder; calls bash, node and brew; needs GITHUB_TOKEN

What it does

Codeql is an agent skill from elastic/kibana, published by the product's own GitHub organization. Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. Use when writing or debugging CodeQL queries, running CodeQL unit tests, analyzing SARIF results, fetching scan results, or checking codeql suppression justifications.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml`).

It sits in Security, covering Static analysis and SAST and Unit testing. It works with Elasticsearch, GitHub and Docker. The repository describes itself as: Your window into all of your data.

When your agent uses it

  • Debugging CodeQL queries
  • Running CodeQL unit tests
  • Analyzing SARIF results
  • Fetching scan results

Example prompts

  • “/codeql”

Requirements

  • Node.js
  • Docker
  • A credential in GITHUB_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Lists recent CodeQL analyses for the ref
  2. Fetches full SARIF JSON (with rule severity cross-referencing)
  3. Prints formatted results (rule, severity, message, file:line)
  4. Fetches code scanning alerts for the same ref

What it can do on your machine

Read from SKILL.md and the folder at commit ee7c86b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • node
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • codeql.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Codeql loads about 1.7k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 516 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 516 words (~1,741 tokens).

“Uses Docker to create a CodeQL database and run queries against real source code.”

— opening of SKILL.md by elastic, Custom licence
name
codeql
disable-model-invocation
true

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files (scripts) in .agents/skills/codeql of elastic/kibana.

  • SKILL.md
  • agents/openai.yaml
  • scripts/fetch_sarif.mjs

Open the folder on GitHubat commit ee7c86b

Compare with similar skills

Codeql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Codeql compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Codeql this skillelastic/kibana21k—~1.7kAutomated safety check: PassCustom licence
Issue WriterNVIDIA/container-canary309—~1.1kAutomated safety check: PassApache-2.0
Redamon Testingsamugit83/redamon3k—~1.8kAutomated safety check: PassMIT
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
SkepticRaoFoundation/subtensor389—~660Automated safety check: PassApache-2.0

Similar skills

  • Issue Writer

    NVIDIA/container-canary

    Official

    Draft and revise concise, human-focused GitHub issues for pytest-kind-ng.

    309 GitHub stars~1.1k tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Redamon Testing

    samugit83/redamon

    How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie.

    3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated today
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated today
    SecurityAuto-check: notes
  • Skeptic

    RaoFoundation/subtensor

    Run the security-focused Skeptic persona on the local working tree's diff against a base branch.

    389 GitHub stars~660 tokensUpdated today
    SecurityAuto-check passed
  • Kedro Plugins Security Review

    kedro-org/kedro-plugins

    Run a security scan on the kedro-plugins codebase or a pull request.

    119 GitHub stars~3.1k tokensUpdated today
    SecurityAuto-check passed

More from elastic/kibana

All 40 skills in this repo
  • Official

    Migrate Kibana Cypress E2E tests (.cy.ts) to Scout (Playwright).

    21k GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Activate Connector

    elastic/kibana

    Official

    Creates a connector instance in a running Kibana. An agent skill from elastic/kibana.

    21k GitHub stars~1.9k tokensUpdated today
    Auto-check: notes
  • Debug Oas

    elastic/kibana

    Official

    A skill your agent uses when debugging OpenAPI (OAS) issues for a specific API area in Kibana by scoping validation output with one or more --path filters, then separating structural invalid-OAS…

    21k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Evals Write Spec

    elastic/kibana

    Official

    Write LLM evaluation spec files with datasets, tasks, and evaluators using the @kbn/evals Playwright fixture.

    21k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Kbn GitHub

    elastic/kibana

    Official

    GitHub interactions via gh CLI for the Kibana repo. An agent skill from elastic/kibana.

    21k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Official

    Implement and review Kibana feature privilege deprecations. An agent skill from elastic/kibana.

    21k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Codeql

What does Codeql do?

Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments. Codeql is an agent skill from elastic/kibana, published by the product's own GitHub organization. Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

When should I use Codeql?

Codeql fits situations like: debugging CodeQL queries; running CodeQL unit tests; analyzing SARIF results; fetching scan results.

How do I install Codeql in Claude Code?

Run `npx skills add elastic/kibana --skill codeql -a claude-code`. Or copy the skill folder (.agents/skills/codeql in elastic/kibana) into .claude/skills/codeql in your project. Claude Code loads it when a task matches its description.

How do I install Codeql in Codex?

Run `npx skills add elastic/kibana --skill codeql -a codex`. Or copy the skill folder (.agents/skills/codeql in elastic/kibana) into .agents/skills/codeql in your project. Codex loads it when a task matches its description.

Can I use Codeql in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/kibana --skill codeql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codeql, .gemini/skills/codeql, .github/skills/codeql and .opencode/skills/codeql in your project.

What does Codeql need to run?

Going by SKILL.md and its folder, Codeql needs JavaScript for the scripts in its folder, the command-line tools its instructions call (bash, node and brew) and credentials named GITHUB_TOKEN. Our summary lists: Node.js; Docker; A credential in GITHUB_TOKEN.

Does Codeql access the network?

SKILL.md names 1 domain. As links in the text: codeql.github.com. This is read from the text; nothing was executed.

Is Codeql safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Codeql use?

Codeql has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Codeql use?

About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Codeql?

Skills that share tags, products or a category with Codeql: Issue Writer (NVIDIA/container-canary, 309 stars), Redamon Testing (samugit83/redamon, 3k stars), Kedro Security Review (kedro-org/kedro, 11k stars) and Pyspector Security Audit (ParzivalHack/PySpector, 151 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Codeql?

elastic (a GitHub organization, an official publisher) maintains it in elastic/kibana, which has 21,310 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 8, 2026.

Source: elastic/kibana on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.