Agent skill

Triage Codeql

by netdata in netdata/netdata

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

GPL-3.0Auto-check: notesSecurity

Install Triage Codeql

skills CLI
$ npx skills add netdata/netdata --skill triage-codeql -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install netdata/netdata triage-codeql --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/netdata/netdata.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/triage-codeql .claude/skills/triage-codeql && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
triage-codeql
GitHub stars
81k
Token cost
~1.8k tokens
SKILL.md length
785 words
Files
5 (incl. scripts)
Skills in repo
27
Repo updated
First seen
Licence
GPL-3.0

At a glance

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Pick The Task, Owners, Setup and Inspect, plus 3 more sections
  • Runs Shell and Python scripts from its folder; calls bash, gh and jq
  • Tasks that involve Secrets management

What it does

Triage Codeql is an agent skill from netdata/netdata. Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. Not for CodeQL query authoring, CI configuration, Dependabot, or secret scanning.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `scripts/_lib.sh`, `scripts/codeql-dismiss.sh` and `scripts/codeql-list.sh`).

It sits in Security, covering Static analysis and SAST, Secrets management and Dependency management. It works with GitHub. The repository describes itself as: The fastest path to AI-powered full stack observability, even for lean teams. The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Secrets management
  • Tasks that involve Dependency management

Example prompts

  • “/triage-codeql”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 9fe30d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • gh
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.github.com
    • cli.github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Triage Codeql loads about 1.8k tokens when it runs. Until then it costs about 55 tokens; SKILL.md has 785 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:39
    The helpers do not source `.env`. Use `gh auth status` to diagnose missing authentication; use `gh auth login`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from netdata/netdata at commit 9fe30d9, republished under its GPL-3.0 licence (© netdata). 785 words, ~1,767 tokens.

Download SKILL.mdSave it as .claude/skills/triage-codeql/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
triage-codeql
description
Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. Not for CodeQL query authoring, CI configuration, Dependabot, or secret scanning.

GitHub Code Scanning Triage

Use the shipped helpers for GitHub REST alert operations. Run commands below from the repository root. Owner references starting with ./ are relative to this skill directory.

Pick The Task

TaskRead
List, inspect or review findingsSetup, Inspect, Triage Decisions
Apply an authorized dismissal or batchSetup, Inspect, Triage Decisions, Apply Verified Decisions
Diagnose a failed requestTroubleshooting and the linked API/CLI reference
Change queries, suites or CIThe workflow and config owners below; this is not an operational triage task

Authorization and read-only scope follow AGENTS.md#when-a-sow-is-required; findings and evidence follow AGENTS.md#review. Inspection stops at the verified report. Applying remote state changes requires authorization covering those actions; preserve permission already granted for the current scope.

Owners

  • Helpers: ./scripts/codeql-list.sh, ./scripts/codeql-dismiss.sh, and ./scripts/_lib.sh own their arguments, output and repository resolution. Use list-helper --help for its flags.
  • CI suites and upload filters: .github/workflows/codeql.yml and its referenced .github/codeql/ configs. Do not infer every language uses the C/C++ security-extended configuration.
  • API permissions, alert states and operations: GitHub REST code scanning.
  • Authentication: gh environment.
  • Discovery capture: AGENTS.md#knowledge-capture.

Setup

  • The helpers need Bash, Git, gh and jq; summary output also uses awk, sort, head and column.
  • Authentication belongs to gh, through its configured credentials or supported exported environment variables. The helpers do not source .env. Use gh auth status to diagnose missing authentication; use gh auth login only when setup is needed. Do not request credential values in conversation.
  • Check the endpoint's token permissions and the account's repository access separately. A successful listing does not establish permission to dismiss.
  • Confirm the target: the helpers prefer upstream, falling back to origin when that remote lookup is absent. They are intended for github.com remotes; a fork checkout can therefore operate on upstream alerts.

Resolve the same target used by both helpers; this reads Git configuration without displaying the remote URL. Keep Setup and subsequent examples in the same shell session so they share codeql_repo:

bash
source .agents/skills/triage-codeql/scripts/_lib.sh
codeql_repo="$(gh_require_slug)"
printf '%s\n' "$codeql_repo"

Inspect

The default is open alerts across tools. The compact summary shows only the most frequent rule/severity groups; use --raw for the complete array merged across pages. For a CodeQL-only investigation:

bash
bash .agents/skills/triage-codeql/scripts/codeql-list.sh --tool=CodeQL
bash .agents/skills/triage-codeql/scripts/codeql-list.sh --tool=CodeQL --raw \
  | jq -r '.[] | [.number, .rule.id, .most_recent_instance.location.path, .html_url] | @tsv'

The list helper also supports --state= and --severity=; choose filters from the requested investigation. A candidate list is not a dismissal list.

Set codeql_alert to a listed alert number, then inspect the alert with the target resolved in Setup:

bash
gh api "/repos/${codeql_repo:?resolve the repository in Setup}/code-scanning/alerts/${codeql_alert:?set the alert number}"

Open the returned html_url for available traces. Verify the rule, affected code, reachability and relevant instances before deciding; a matching rule ID, directory or filename alone does not establish a false positive.

Show full SKILL.md (364 more words)Show less

Triage Decisions

The dismissal helper supports the following reasons; this is its supported subset, not the complete GitHub API enum.

Helper reasonEvidence needed
false positiveThe reported defect is incorrect: establish the relevant guard, type or unreachable path.
won't fixThe defect is real and the user accepts leaving the risk unresolved.
used in testsThe flagged path is confined to test code or fixtures, rather than reachable production behavior.

Fixing code and having analysis report fixed is different from dismissing a finding. Reopening a dismissed alert is also possible through GitHub or the update endpoint with state=open; the dismissal helper does not implement it. Consult GitHub's alert history when investigating a reopened finding.

Apply Verified Decisions

Use ./scripts/codeql-dismiss.sh only for the verified alert number, reason and comment covered by authorization. Set codeql_reason and codeql_comment from that decision. Comments SHOULD be short, factual and ASCII; the helper passes the quoted comment as one API string argument.

bash
bash .agents/skills/triage-codeql/scripts/codeql-dismiss.sh \
  "${codeql_alert:?set the verified alert number}" \
  "${codeql_reason:?set the verified reason}" \
  "${codeql_comment:?set the supporting explanation}"

For a batch, you MUST record the exact verified alert numbers with their reasons and supporting evidence before applying the single-alert helper to each. You MUST NOT pipe a rule-only search directly into dismissal commands. Re-check the target and decision if the code or alert has changed since inspection; inspect the returned state after each request.

Apply writes sequentially and stop on errors. Handle throttling according to the response and GitHub's rate-limit guidance; there is no fixed safe request rate, and the helpers do not implement retries.

Troubleshooting

SymptomCheck
Missing executableInstall the missing Setup dependency through the environment's normal setup.
Authentication or access errorCheck gh authentication, endpoint token permissions and repository access.
Alert endpoint returns 404Confirm resolved repository, alert number, visibility/access and Code Scanning availability.
Empty successful outputInspect --raw, the selected tool/state/severity and the command's exit status.
Suspected missing pagesThe list helper already uses --paginate; inspect raw output rather than the bounded summary.
Missing C/C++ findings under build/Inspect the workflow's SARIF upload filter; config paths-ignore alone does not explain built analysis.

For direct calls beyond the helpers, use the linked REST reference and gh api manual. Dependabot's GraphQL vulnerabilityAlerts is a different data source; it does not retrieve CodeQL findings.

© netdata, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in .agents/skills/triage-codeql of netdata/netdata.

  • SKILL.md
  • scripts/_lib.sh
  • scripts/codeql-dismiss.sh
  • scripts/codeql-list.sh
  • tests/test_remote.py

Open the folder on GitHubat commit 9fe30d9

Compare with similar skills

Triage Codeql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Triage Codeql compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Triage Codeql this skillnetdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0
Implementing GitHub Advanced Security For Code Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
Triaging Security Findingsbitwarden/ai-plugins154—~2.2kAutomated safety check: PassCustom licence
Sicurezza GitHubccplugins/awesome-claude-code-plugins967—~486Automated safety check: NotesApache-2.0
Security Vulnerabilities Patcheraxelixlabs/axelix147—~4.2kAutomated safety check: PassLGPL-3.0
Security Remediatecloudposse/atmos1.4k—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing GitHub Advanced Security For Code Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Triaging Security Findings

    bitwarden/ai-plugins

    Official

    This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work…

    154 GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check passed
  • Sicurezza GitHub

    ccplugins/awesome-claude-code-plugins

    Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.

    967 GitHub stars~486 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    147 GitHub stars~4.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Remediate

    cloudposse/atmos

    Fix open Dependabot and CodeQL/code-scanning alerts directly on the current branch.

    1.4k GitHub stars~1.3k tokensUpdated today
    SecurityAuto-check passed
  • GitHub Project Automation

    secondsky/claude-skills

    GitHub repository automation (CI/CD, issue templates, Dependabot, CodeQL).

    227 GitHub stars~4k tokensUpdated 9 days ago
    DevOps & CloudAuto-check: notes

More from netdata/netdata

All 27 skills in this repo
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Repo Mirror Sources

    netdata/netdata

    Inspect Netdata-org source checkouts under NETDATAREPOSDIR, or set up and synchronize that mirror when requested.

    81k GitHub stars~1.2k tokensUpdated today
    Auto-check: notes
  • Triage Agent Events

    netdata/netdata

    Investigate Netdata crashes, panics and fatals from agent-events captures or authorized fleet queries.

    81k GitHub stars~2.4k tokensUpdated today
    Auto-check: notes
  • Triage Codacy

    netdata/netdata

    Inspect, analyze, troubleshoot, or review Codacy findings and local analyzer/API helpers.

    81k GitHub stars~2.2k tokensUpdated today
    Auto-check: notes
  • Triage Coverity

    netdata/netdata

    Inspect or review Coverity Scan defects and saved CID bundles; fetch live findings or apply verified triage decisions when requested.

    81k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Triage Sonarqube

    netdata/netdata

    Inspect, review, or apply authorized triage decisions to SonarCloud issues and security hotspots; also review the Sonar helpers.

    81k GitHub stars~2.8k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Triage Codeql

What does Triage Codeql do?

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. Triage Codeql is an agent skill from netdata/netdata. Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

When should I use Triage Codeql?

Triage Codeql fits situations like: tasks that involve Static analysis and SAST; tasks that involve Secrets management; tasks that involve Dependency management.

How do I install Triage Codeql in Claude Code?

Run `npx skills add netdata/netdata --skill triage-codeql -a claude-code`. Or copy the skill folder (.agents/skills/triage-codeql in netdata/netdata) into .claude/skills/triage-codeql in your project. Claude Code loads it when a task matches its description.

How do I install Triage Codeql in Codex?

Run `npx skills add netdata/netdata --skill triage-codeql -a codex`. Or copy the skill folder (.agents/skills/triage-codeql in netdata/netdata) into .agents/skills/triage-codeql in your project. Codex loads it when a task matches its description.

Can I use Triage Codeql in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add netdata/netdata --skill triage-codeql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/triage-codeql, .gemini/skills/triage-codeql, .github/skills/triage-codeql and .opencode/skills/triage-codeql in your project.

What does Triage Codeql need to run?

Going by SKILL.md and its folder, Triage Codeql needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (bash, gh and jq). Our summary lists: Python 3; A Bash shell.

Does Triage Codeql access the network?

SKILL.md names 2 domains. As links in the text: docs.github.com and cli.github.com. This is read from the text; nothing was executed.

Is Triage Codeql safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Triage Codeql use?

Triage Codeql is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Triage Codeql use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Triage Codeql?

Skills that share tags, products or a category with Triage Codeql: Implementing GitHub Advanced Security For Code Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Triaging Security Findings (bitwarden/ai-plugins, 154 stars), Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 967 stars) and Security Vulnerabilities Patcher (axelixlabs/axelix, 147 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Triage Codeql?

netdata (a GitHub organization) maintains it in netdata/netdata, which has 80,820 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 7, 2026.

Source: netdata/netdata on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.