Official agent skill

Code Security

by semgrep in semgrep/skills

Security guidelines for writing secure code. An agent skill from semgrep/skills.

OfficialCustom licenceAuto-check passedSecurity

Install Code Security

skills CLI
$ npx skills add semgrep/skills --skill code-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install semgrep/skills code-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/semgrep/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/code-security .claude/skills/code-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-security
GitHub stars
322
Token cost
~1.2k tokens
SKILL.md length
467 words
Files
34
Skills in repo
2
Repo updated
First seen
Licence
Custom licence

At a glance

Security guidelines for writing secure code. An agent skill from semgrep/skills.

  • Works in 4 steps: Identify the language and what the code… → Check the relevant rules below — focus… → Read the specific rule file from rules/… → …
  • Reviewing code for vulnerabilities
  • SKILL.md covers How to Use This Skill, Language-Specific Priority Rules, Categories and Quick Reference
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Security is an agent skill from semgrep/skills, published by the product's own GitHub organization. Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also…

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 34 other files (for example `AGENTS.md`, `README.md` and `metadata.json`).

It sits in Security, covering Web application vulnerabilities, Security review and Infrastructure as code. It works with Docker, GitHub Actions, Kubernetes and Terraform. The repository describes itself as: A collection of skills for AI coding agents from Semgrep.

When your agent uses it

  • Reviewing code for vulnerabilities
  • Asking about secure coding practices like check for SQL injection
  • Review security
  • Users ask to review my code

Example prompts

  • “check for SQL injection”
  • “review security”
  • “t explicitly mention security. Also use when users ask to”
  • “/code-security”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the language and what the code does (handles input? queries a DB? reads files?)
  2. Check the relevant rules below — focus on Critical and High impact first
  3. Read the specific rule file from rules/ for detailed code examples in that language
  4. Apply the secure patterns, or flag the vulnerable patterns if reviewing

What it can do on your machine

Read from SKILL.md and the folder at commit 68177b8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Security loads about 1.2k tokens when it runs. Until then it costs about 153 tokens; SKILL.md has 467 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~153
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 467 words (~1,249 tokens).

“Comprehensive security rules for writing secure code across 15+ languages. Covers OWASP Top 10, infrastructure security, and coding best practices with 28 rule categories.”

— opening of SKILL.md by semgrep, Custom licence
name
code-security

Read the full SKILL.md on GitHub

Files

SKILL.md and 33 other files in skills/code-security of semgrep/skills.

  • SKILL.md
  • AGENTS.md
  • README.md
  • metadata.json
  • rules/_sections.md
  • rules/_template.md
  • rules/authentication-jwt.md
  • rules/best-practice.md
  • rules/code-injection.md
  • rules/command-injection.md
  • rules/correctness.md
  • rules/csrf.md
  • rules/docker.md
  • rules/github-actions.md
  • rules/insecure-crypto.md
  • rules/insecure-deserialization.md
  • rules/insecure-transport.md
  • rules/kubernetes.md
  • rules/maintainability.md
  • rules/memory-safety.md
  • … and 14 more

Open the folder on GitHubat commit 68177b8

Compare with similar skills

Code Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Security this skillsemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone
Devops Excellencemajiayu000/spellbook286—~2.4kAutomated safety check: NotesMIT
Devops Deploymentyonatangross/orchestkit288—~2.7kAutomated safety check: PassMIT
Devops EngineerYikai-Liao/symusic1891 repos~1.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence

Similar skills

  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated today
    SecurityAuto-check: notes
  • Devops Excellence

    majiayu000/spellbook

    DevOps and CI/CD expert. An agent skill from majiayu000/spellbook.

    286 GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Devops Deployment

    yonatangross/orchestkit

    A skill your agent uses when setting up CI/CD pipelines, containerizing applications, deploying to Kubernetes, or writing infrastructure as code.

    288 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Devops Engineer

    Yikai-Liao/symusic

    Creates Dockerfiles, configures CI/CD pipelines, writes Kubernetes manifests, and generates Terraform/Pulumi infrastructure templates.

    189 GitHub starsUsed in 1 repo~1.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    219 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed

More from semgrep/skills

  • Semgrep

    semgrep/skills

    Official

    Run Semgrep static analysis scans and create custom detection rules.

    322 GitHub stars~2.3k tokensUpdated 2 mo ago
    Auto-check passed

Questions about Code Security

What does Code Security do?

Security guidelines for writing secure code. An agent skill from semgrep/skills. Code Security is an agent skill from semgrep/skills, published by the product's own GitHub organization. Security guidelines for writing secure code.

When should I use Code Security?

Code Security fits situations like: reviewing code for vulnerabilities; asking about secure coding practices like check for SQL injection; review security; users ask to review my code.

How do I install Code Security in Claude Code?

Run `npx skills add semgrep/skills --skill code-security -a claude-code`. Or copy the skill folder (skills/code-security in semgrep/skills) into .claude/skills/code-security in your project. Claude Code loads it when a task matches its description.

How do I install Code Security in Codex?

Run `npx skills add semgrep/skills --skill code-security -a codex`. Or copy the skill folder (skills/code-security in semgrep/skills) into .agents/skills/code-security in your project. Codex loads it when a task matches its description.

Can I use Code Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add semgrep/skills --skill code-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-security, .gemini/skills/code-security, .github/skills/code-security and .opencode/skills/code-security in your project.

What does Code Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Security is instructions for the agent only. Our summary lists: Docker.

Does Code Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Security use?

Code Security has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Code Security use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Security?

Skills that share tags, products or a category with Code Security: Security Analyzer (aiskillstore/marketplace, 430 stars), Devops Excellence (majiayu000/spellbook, 286 stars), Devops Deployment (yonatangross/orchestkit, 288 stars) and Devops Engineer (Yikai-Liao/symusic, 189 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Security?

semgrep (a GitHub organization, an official publisher) maintains it in semgrep/skills, which has 322 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on July 28, 2026.

Source: semgrep/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.