Semgrep
vigolium/piolium
Run Semgrep static analysis scan on a codebase using parallel subagents.
Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.
$ npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install KimYx0207/Kim_Service semgrep-skill --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/KimYx0207/Kim_Service.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/semgrep-skill .claude/skills/semgrep-skill && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "semgrep-skill" agent skill from https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill into .claude/skills/semgrep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-skill", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install KimYx0207/Kim_Service semgrep-skill --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KimYx0207/Kim_Service.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/semgrep-skill .agents/skills/semgrep-skill && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "semgrep-skill" agent skill from https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill into .agents/skills/semgrep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-skill", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install KimYx0207/Kim_Service semgrep-skill --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KimYx0207/Kim_Service.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/semgrep-skill .cursor/skills/semgrep-skill && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "semgrep-skill" agent skill from https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill into .cursor/skills/semgrep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-skill", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/KimYx0207/Kim_Service.git --path skills/semgrep-skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install KimYx0207/Kim_Service semgrep-skill --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KimYx0207/Kim_Service.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/semgrep-skill .gemini/skills/semgrep-skill && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "semgrep-skill" agent skill from https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill into .gemini/skills/semgrep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-skill", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install KimYx0207/Kim_Service semgrep-skillInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/KimYx0207/Kim_Service.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/semgrep-skill .github/skills/semgrep-skill && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "semgrep-skill" agent skill from https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill into .github/skills/semgrep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-skill", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install KimYx0207/Kim_Service semgrep-skill --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/KimYx0207/Kim_Service.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/semgrep-skill .opencode/skills/semgrep-skill && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "semgrep-skill" agent skill from https://github.com/KimYx0207/Kim_Service/tree/main/skills/semgrep-skill into .opencode/skills/semgrep-skill/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-skill", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
semgrep-skillRuns the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.
Semgrep Skill is an agent skill from KimYx0207/Kim_Service. Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. Requires an explicit authorized workspaceRoot and target. No remote rules, uploads, installs, source excerpts or automatic fixes.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including scripts (for example `CHANGELOG.md`, `README.md` and `README_EN.md`).
It sits in Security, covering Static analysis and SAST. It works with Semgrep. The repository describes itself as: 面向 Claude Code、Codex 等 AI 编码助手的 Hook 与 Agent Skill 开源合集。 The licence is MIT.
Read from SKILL.md and the folder at commit 20296f7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python, PowerShell, Shell and JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
pythonsemgrepFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Semgrep Skill loads about 1.2k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 564 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from KimYx0207/Kim_Service at commit 20296f7, republished under its MIT licence (© KimYx0207). 564 words, ~1,176 tokens.
.claude/skills/semgrep-skill/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.Use only <skill-dir>/scripts/scan.py, where <skill-dir> contains this file.
The package capability.json defines the input, result and optional invocation.
Read it after the caller verifies the discovered package hash. The generated
index selects the package; it does not contain or grant the invocation.
workspaceRoot and a
directory target inside it. Never default to the current project or drive.rules/local-security.yml, extracts just
python-subprocess-shell-true and javascript-eval into temporary configuration
before scanning, and records both hashes. The bundled legacy secret-pattern
rule is not executed by this route; credential checks are outside this capability.shell:false. Never execute files from the scan target as programs.--metrics off, --disable-version-check,
isolated settings/log/cache paths, and a minimal subprocess environment.
Caller tokens, proxies and custom Semgrep configuration are not inherited.
Windows APPDATA and a computed installed Python user base/site may be retained
solely to locate the existing host runtime; caller PYTHONPATH is not inherited.--config auto, registry URLs, Semgrep Cloud, login or uploads.--autofix, write reports, install Semgrep or fetch rules. The
installer installs the Skill projection only and requires separate write approval.From any working directory, pass one UTF-8 JSON object over stdin:
{"schemaVersion":1,"workspaceRoot":"<authorized-absolute-local-root>","target":"<directory-within-root>"}python "<skill-dir>/scripts/scan.py" --input-json -Equivalent named arguments are --workspace-root <absolute-root> --target <directory>, optionally --rules rules/local-security.yml. There are no extra
Semgrep flags, executable overrides or JSON-file paths. Do not separately run a
bare semgrep --version: the wrapper performs its own isolated runtime check.
Return the wrapper result, not a promise to scan later. completed means every
selected file was confirmed scanned, not that findings were empty or security
was certified. completed exits 0 even with findings. partial, invalid_input,
unavailable and failed exit 2 and keep completed:false. An unavailable tool
must stay unavailable; no installation is attempted. Missing files or errors
must never be labeled clean. Remediation remains advisory text.
Only visible .py, .js, .jsx, .ts, .tsx files are selected. Hidden
directories/files, node_modules, pycache, venv and vendor are excluded.
Links/reparse points are rejected. Narrow targets to at most 512 eligible files,
each at most 1 MiB; do not select a target containing the host temporary directory.
Each subprocess has a 60-second limit; output is checked
while running against an 8 MiB limit per stream. These are safety bounds in
scripts/scan.py, not caller-adjustable business parameters.
networkUsed:false describes the enforced local configuration, metrics/version
opt-outs and environment isolation; it is not OS network isolation or a packet
capture certificate. filesModified:false means no source edits: temporary
configuration, settings and logs are outside the target and cleaned afterward.
Use a trusted host installation and stable filesystem; this is not a sandbox for
malicious binaries or concurrent path replacement. Findings cover two patterns
only; omitted file types and excluded directories were not audited.
install.ps1, install.sh and scripts/install.py remain dry-run first, require
explicit project/user scope, and require --apply to write. They project this
file, capability.json, scripts/scan.py and the bundled rules with hash receipts
and rollback. They never install Semgrep or overwrite legacy code-security.
See README for preview/apply/rollback commands; do not treat scan permission as
permission to install or change source.
© KimYx0207, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 21 other files (scripts) in skills/semgrep-skill of KimYx0207/Kim_Service.
Open the folder on GitHubat commit 20296f7
Semgrep Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Semgrep Skill this skillKimYx0207/Kim_Service | 174 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Semgrepvigolium/piolium | 140 | 1 repos | ~2.4k | Automated safety check: Notes | MIT | |
| Semgrep Security Scantrailofbits/skills | 7.5k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Sast SemgrepAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~2.4k | Automated safety check: Pass | Custom licence | |
| Semgrep Rule Creatortrailofbits/skills | 7.5k | 6 repos | ~1.8k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Semgrep Rule Variant Creatortrailofbits/skills | 7.5k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 |
vigolium/piolium
Run Semgrep static analysis scan on a codebase using parallel subagents.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
AgentSecOps/SecOpsAgentKit
Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.
trailofbits/skills
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.
trailofbits/skills
Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.
waybarrios/opencode-power-pack
Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.
KimYx0207/Kim_Service
创建、重构或验收可复用技能包。适用于把重复工作流做成跨宿主能力包,并明确触发规则、第一动作、渐进加载、资产模板、脚本校验、触发评测、基线对比、验收证据、闭环治理、公开交付边界和不可伪造的运行证明;也适用于清理冗余参考、拆分人读模板与机器结构数据、补齐首次公开前的验收记录、记录运行反馈、生成写回或不写回决定。当用户提到"做一个 skill / 改 skill / 优化 skill / 评审…
KimYx0207/Kim_Service
Cross-runtime playbook for multi-agent collaboration, agent teams, swarm orchestration, parallel task distribution, capability discovery, and quality gates on Claude Code, Codex, OpenClaw, and Cursor.
KimYx0207/Kim_Service
生成完整的小红书/Rednote 图文发布包:先自动研究内容机会,再完成标题、正文、封面、6-8 页内页、逐页视觉导演表、Image2 优先图片路线、封面 MVP 确认、批量出图和发布前自检。适用于课程、服务、产品、个人 IP、本地商家和知识分享;单点标题、封面字或改写不触发。
KimYx0207/Kim_Service
为长周期、跨会话的 Agent 工作建立平台中立的三层记忆。适用于加载项目记忆、记录可复用事实与每日进展、维护隐性知识、迁移旧版 .claude/memory、检查记忆状态或清理过时条目;Claude Code 与 Codex 可通过各自 Hooks 自动接线,其他 Agent Skills 宿主只使用手动核心。不要用它保存秘密、完整聊天记录、一次性日志或未经确认的推测。
KimYx0207/Kim_Service
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities.
KimYx0207/Kim_Service
A skill your agent uses when the user asks for KIM, Kim, laojin, 老金, 问问老金, 老金怎么看, asks for decision analysis, structured reasoning, product/business/content review, PRD, MVP, user path, growth…
Works with
Categories
Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. Semgrep Skill is an agent skill from KimYx0207/Kim_Service. Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.
Semgrep Skill fits situations like: tasks that involve Static analysis and SAST.
Run `npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a claude-code`. Or copy the skill folder (skills/semgrep-skill in KimYx0207/Kim_Service) into .claude/skills/semgrep-skill in your project. Claude Code loads it when a task matches its description.
Run `npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a codex`. Or copy the skill folder (skills/semgrep-skill in KimYx0207/Kim_Service) into .agents/skills/semgrep-skill in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semgrep-skill, .gemini/skills/semgrep-skill, .github/skills/semgrep-skill and .opencode/skills/semgrep-skill in your project.
Going by SKILL.md and its folder, Semgrep Skill needs Python, PowerShell, a shell and JavaScript for the scripts in its folder and the command-line tools its instructions call (python and semgrep). Our summary lists: Python 3; Node.js; A Bash shell; PowerShell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Semgrep Skill is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Semgrep Skill: Semgrep (vigolium/piolium, 140 stars), Semgrep Security Scan (trailofbits/skills, 7.5k stars), Sast Semgrep (AgentSecOps/SecOpsAgentKit, 220 stars) and Semgrep Rule Creator (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
KimYx0207 (a GitHub user) maintains it in KimYx0207/Kim_Service, which has 174 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.
Source: KimYx0207/Kim_Service on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.