Agent skill

Semgrep Skill

by KimYx0207 in KimYx0207/Kim_Service

Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.

MITAuto-check passedSecurity

Install Semgrep Skill

skills CLI
$ npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install KimYx0207/Kim_Service semgrep-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/KimYx0207/Kim_Service.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/semgrep-skill .claude/skills/semgrep-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semgrep-skill
GitHub stars
174
Token cost
~1.2k tokens
SKILL.md length
564 words
Files
22 (incl. scripts)
Skills in repo
8
Repo updated
First seen
Licence
MIT

At a glance

Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.

  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Safety contract, Invoke and interpret, Coverage and trust boundary and Installing this Skill
  • Runs Python, PowerShell, Shell and JavaScript scripts from its folder; calls python and semgrep

What it does

Semgrep Skill is an agent skill from KimYx0207/Kim_Service. Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. Requires an explicit authorized workspaceRoot and target. No remote rules, uploads, installs, source excerpts or automatic fixes.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 26 other files, including scripts (for example `CHANGELOG.md`, `README.md` and `README_EN.md`).

It sits in Security, covering Static analysis and SAST. It works with Semgrep. The repository describes itself as: 面向 Claude Code、Codex 等 AI 编码助手的 Hook 与 Agent Skill 开源合集。 The licence is MIT.

When your agent uses it

  • Tasks that involve Static analysis and SAST

Example prompts

  • “/semgrep-skill”

Requirements

  • Python 3
  • Node.js
  • A Bash shell
  • PowerShell

What it can do on your machine

Read from SKILL.md and the folder at commit 20296f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python, PowerShell, Shell and JavaScript, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • semgrep

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semgrep Skill loads about 1.2k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 564 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from KimYx0207/Kim_Service at commit 20296f7, republished under its MIT licence (© KimYx0207). 564 words, ~1,176 tokens.

Download SKILL.mdSave it as .claude/skills/semgrep-skill/SKILL.md (or your agent's skills folder). This skill also uses 21 other files; get the full folder from GitHub.
name
semgrep-skill
description
Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. Requires an explicit authorized workspaceRoot and target. No remote rules, uploads, installs, source excerpts or automatic fixes.
version
1.1.0
context
fork

Local Semgrep security scan

Use only <skill-dir>/scripts/scan.py, where <skill-dir> contains this file. The package capability.json defines the input, result and optional invocation. Read it after the caller verifies the discovered package hash. The generated index selects the package; it does not contain or grant the invocation.

Safety contract

  • Require the user's explicit authorized absolute local workspaceRoot and a directory target inside it. Never default to the current project or drive.
  • The wrapper accepts only rules/local-security.yml, extracts just python-subprocess-shell-true and javascript-eval into temporary configuration before scanning, and records both hashes. The bundled legacy secret-pattern rule is not executed by this route; credential checks are outside this capability.
  • It executes an already-installed trusted host CLI with an argv array and shell:false. Never execute files from the scan target as programs.
  • Both the version probe and scan use --metrics off, --disable-version-check, isolated settings/log/cache paths, and a minimal subprocess environment. Caller tokens, proxies and custom Semgrep configuration are not inherited. Windows APPDATA and a computed installed Python user base/site may be retained solely to locate the existing host runtime; caller PYTHONPATH is not inherited.
  • Do not use --config auto, registry URLs, Semgrep Cloud, login or uploads.
  • Do not use --autofix, write reports, install Semgrep or fetch rules. The installer installs the Skill projection only and requires separate write approval.
  • stdout contains rule IDs, workspace-relative paths, spans, severity and bundled rule messages. Raw source, metavariables and raw CLI diagnostics are withheld.

Invoke and interpret

From any working directory, pass one UTF-8 JSON object over stdin:

json
{"schemaVersion":1,"workspaceRoot":"<authorized-absolute-local-root>","target":"<directory-within-root>"}
bash
python "<skill-dir>/scripts/scan.py" --input-json -

Equivalent named arguments are --workspace-root <absolute-root> --target <directory>, optionally --rules rules/local-security.yml. There are no extra Semgrep flags, executable overrides or JSON-file paths. Do not separately run a bare semgrep --version: the wrapper performs its own isolated runtime check.

Return the wrapper result, not a promise to scan later. completed means every selected file was confirmed scanned, not that findings were empty or security was certified. completed exits 0 even with findings. partial, invalid_input, unavailable and failed exit 2 and keep completed:false. An unavailable tool must stay unavailable; no installation is attempted. Missing files or errors must never be labeled clean. Remediation remains advisory text.

Show full SKILL.md (210 more words)Show less

Coverage and trust boundary

Only visible .py, .js, .jsx, .ts, .tsx files are selected. Hidden directories/files, node_modules, pycache, venv and vendor are excluded. Links/reparse points are rejected. Narrow targets to at most 512 eligible files, each at most 1 MiB; do not select a target containing the host temporary directory. Each subprocess has a 60-second limit; output is checked while running against an 8 MiB limit per stream. These are safety bounds in scripts/scan.py, not caller-adjustable business parameters.

networkUsed:false describes the enforced local configuration, metrics/version opt-outs and environment isolation; it is not OS network isolation or a packet capture certificate. filesModified:false means no source edits: temporary configuration, settings and logs are outside the target and cleaned afterward. Use a trusted host installation and stable filesystem; this is not a sandbox for malicious binaries or concurrent path replacement. Findings cover two patterns only; omitted file types and excluded directories were not audited.

Installing this Skill

install.ps1, install.sh and scripts/install.py remain dry-run first, require explicit project/user scope, and require --apply to write. They project this file, capability.json, scripts/scan.py and the bundled rules with hash receipts and rollback. They never install Semgrep or overwrite legacy code-security. See README for preview/apply/rollback commands; do not treat scan permission as permission to install or change source.

© KimYx0207, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 21 other files (scripts) in skills/semgrep-skill of KimYx0207/Kim_Service.

  • SKILL.md
  • CHANGELOG.md
  • LICENSE
  • NOTICE
  • README.md
  • README_EN.md
  • capability.json
  • images/二维码基础款.png
  • images/微信.jpg
  • images/支付宝.jpg
  • install.ps1
  • install.sh
  • rules/local-security.yml
  • scripts/install.py
  • scripts/scan.py
  • tests/fixtures/safe.js
  • … and 6 more

Open the folder on GitHubat commit 20296f7

Compare with similar skills

Semgrep Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semgrep Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semgrep Skill this skillKimYx0207/Kim_Service174—~1.2kAutomated safety check: PassMIT
Semgrepvigolium/piolium1401 repos~2.4kAutomated safety check: NotesMIT
Semgrep Security Scantrailofbits/skills7.5k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
Sast SemgrepAgentSecOps/SecOpsAgentKit2202 repos~2.4kAutomated safety check: PassCustom licence
Semgrep Rule Creatortrailofbits/skills7.5k6 repos~1.8kAutomated safety check: NotesCC-BY-SA-4.0
Semgrep Rule Variant Creatortrailofbits/skills7.5k5 repos~3.4kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    140 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.5k GitHub stars~3.7k tokensUpdated today
    SecurityAuto-check: notes
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    220 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed
  • Semgrep Rule Creator

    trailofbits/skills

    Official

    Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns.

    7.5k GitHub starsUsed in 6 repos~1.8k tokens
    SecurityAuto-check: notes
  • Official

    Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.

    7.5k GitHub starsUsed in 5 repos~3.4k tokens
    SecurityAuto-check: notes
  • Semgrep

    waybarrios/opencode-power-pack

    Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.

    534 GitHub stars~2.4k tokensUpdated 4 days ago
    SecurityAuto-check passed

More from KimYx0207/Kim_Service

All 8 skills in this repo
  • Meta Skill Creator

    KimYx0207/Kim_Service

    创建、重构或验收可复用技能包。适用于把重复工作流做成跨宿主能力包,并明确触发规则、第一动作、渐进加载、资产模板、脚本校验、触发评测、基线对比、验收证据、闭环治理、公开交付边界和不可伪造的运行证明;也适用于清理冗余参考、拆分人读模板与机器结构数据、补齐首次公开前的验收记录、记录运行反馈、生成写回或不写回决定。当用户提到"做一个 skill / 改 skill / 优化 skill / 评审…

    174 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Agent Teams Playbook

    KimYx0207/Kim_Service

    Cross-runtime playbook for multi-agent collaboration, agent teams, swarm orchestration, parallel task distribution, capability discovery, and quality gates on Claude Code, Codex, OpenClaw, and Cursor.

    174 GitHub stars~2.7k tokensUpdated 4 days ago
    Auto-check passed
  • Xiaohongshu Skill

    KimYx0207/Kim_Service

    生成完整的小红书/Rednote 图文发布包:先自动研究内容机会,再完成标题、正文、封面、6-8 页内页、逐页视觉导演表、Image2 优先图片路线、封面 MVP 确认、批量出图和发布前自检。适用于课程、服务、产品、个人 IP、本地商家和知识分享;单点标题、封面字或改写不触发。

    174 GitHub stars~1.9k tokensUpdated 4 days ago
    Auto-check passed
  • Memory 3layer

    KimYx0207/Kim_Service

    为长周期、跨会话的 Agent 工作建立平台中立的三层记忆。适用于加载项目记忆、记录可复用事实与每日进展、维护隐性知识、迁移旧版 .claude/memory、检查记忆状态或清理过时条目;Claude Code 与 Codex 可通过各自 Hooks 自动接线,其他 Agent Skills 宿主只使用手动核心。不要用它保存秘密、完整聊天记录、一次性日志或未经确认的推测。

    174 GitHub stars~1.2k tokensUpdated 4 days ago
    Auto-check passed
  • Find Skill

    KimYx0207/Kim_Service

    Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities.

    174 GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Kim Decision

    KimYx0207/Kim_Service

    A skill your agent uses when the user asks for KIM, Kim, laojin, 老金, 问问老金, 老金怎么看, asks for decision analysis, structured reasoning, product/business/content review, PRD, MVP, user path, growth…

    174 GitHub stars~7.1k tokensUpdated 4 days ago
    Auto-check passed

Works with

Categories

Questions about Semgrep Skill

What does Semgrep Skill do?

Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules. Semgrep Skill is an agent skill from KimYx0207/Kim_Service. Runs the installed local Semgrep CLI through a bounded JSON wrapper with two bundled non-secret rules.

When should I use Semgrep Skill?

Semgrep Skill fits situations like: tasks that involve Static analysis and SAST.

How do I install Semgrep Skill in Claude Code?

Run `npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a claude-code`. Or copy the skill folder (skills/semgrep-skill in KimYx0207/Kim_Service) into .claude/skills/semgrep-skill in your project. Claude Code loads it when a task matches its description.

How do I install Semgrep Skill in Codex?

Run `npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a codex`. Or copy the skill folder (skills/semgrep-skill in KimYx0207/Kim_Service) into .agents/skills/semgrep-skill in your project. Codex loads it when a task matches its description.

Can I use Semgrep Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add KimYx0207/Kim_Service --skill semgrep-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semgrep-skill, .gemini/skills/semgrep-skill, .github/skills/semgrep-skill and .opencode/skills/semgrep-skill in your project.

What does Semgrep Skill need to run?

Going by SKILL.md and its folder, Semgrep Skill needs Python, PowerShell, a shell and JavaScript for the scripts in its folder and the command-line tools its instructions call (python and semgrep). Our summary lists: Python 3; Node.js; A Bash shell; PowerShell.

Does Semgrep Skill access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Semgrep Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Semgrep Skill use?

Semgrep Skill is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semgrep Skill use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Semgrep Skill?

Skills that share tags, products or a category with Semgrep Skill: Semgrep (vigolium/piolium, 140 stars), Semgrep Security Scan (trailofbits/skills, 7.5k stars), Sast Semgrep (AgentSecOps/SecOpsAgentKit, 220 stars) and Semgrep Rule Creator (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semgrep Skill?

KimYx0207 (a GitHub user) maintains it in KimYx0207/Kim_Service, which has 174 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 6, 2026.

Source: KimYx0207/Kim_Service on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.