Security Verification Gate
fengshao1227/ccg-workflow
Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.
Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.
$ npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install skrun-dev/skrun semgrep-rule-creator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/skrun-dev/skrun.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/semgrep-rule-creator .claude/skills/semgrep-rule-creator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "semgrep-rule-creator" agent skill from https://github.com/skrun-dev/skrun/tree/main/agents/semgrep-rule-creator into .claude/skills/semgrep-rule-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-creator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/skrun-dev/skrun/tree/main/agents/semgrep-rule-creatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install skrun-dev/skrun semgrep-rule-creator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/skrun-dev/skrun.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/semgrep-rule-creator .agents/skills/semgrep-rule-creator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "semgrep-rule-creator" agent skill from https://github.com/skrun-dev/skrun/tree/main/agents/semgrep-rule-creator into .agents/skills/semgrep-rule-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-creator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install skrun-dev/skrun semgrep-rule-creator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/skrun-dev/skrun.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/semgrep-rule-creator .cursor/skills/semgrep-rule-creator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "semgrep-rule-creator" agent skill from https://github.com/skrun-dev/skrun/tree/main/agents/semgrep-rule-creator into .cursor/skills/semgrep-rule-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-creator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/skrun-dev/skrun.git --path agents/semgrep-rule-creator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install skrun-dev/skrun semgrep-rule-creator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/skrun-dev/skrun.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/semgrep-rule-creator .gemini/skills/semgrep-rule-creator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "semgrep-rule-creator" agent skill from https://github.com/skrun-dev/skrun/tree/main/agents/semgrep-rule-creator into .gemini/skills/semgrep-rule-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-creator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install skrun-dev/skrun semgrep-rule-creatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/skrun-dev/skrun.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/semgrep-rule-creator .github/skills/semgrep-rule-creator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "semgrep-rule-creator" agent skill from https://github.com/skrun-dev/skrun/tree/main/agents/semgrep-rule-creator into .github/skills/semgrep-rule-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-creator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install skrun-dev/skrun semgrep-rule-creator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/skrun-dev/skrun.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/semgrep-rule-creator .opencode/skills/semgrep-rule-creator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "semgrep-rule-creator" agent skill from https://github.com/skrun-dev/skrun/tree/main/agents/semgrep-rule-creator into .opencode/skills/semgrep-rule-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-creator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
semgrep-rule-creatorGenerate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.
Semgrep Rule Creator is an agent skill from skrun-dev/skrun. Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. Picks an appropriate severity, infers the right CWE/OWASP mapping, and produces a ready-to-commit rule with documentation. Use when asked to draft a Semgrep rule, encode a security pattern, or productize a security finding for the codebase.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `README.md`, `agent.yaml` and `fixtures/sample-cve.md`).
It sits in Security, covering Static analysis and SAST, Web application vulnerabilities and Vulnerability scanning. It works with Semgrep. The repository describes itself as: Deploy any Agent Skill as an API via POST /run. The open-source multi-model alternative to Claude Managed Agents, Microsoft Foundry & Mistral/Koyeb — works with any LLM. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b1d963b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (TypeScript), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
cwe.mitre.orgowasp.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Semgrep Rule Creator loads about 1.3k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 382 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from skrun-dev/skrun at commit b1d963b, republished under its MIT licence (© skrun-dev). 382 words, ~1,252 tokens.
.claude/skills/semgrep-rule-creator/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.You are a security engineer who writes Semgrep rules for a living. Given a vulnerability description and a concrete bad-code example, you produce three artifacts:
rule.yml — the actual Semgrep rule (drop into the repo's .semgrep/ directory).tests.md — good/bad code examples that document expected behavior.README.md — rationale, severity reasoning, references (CWE/OWASP links).Analyze the input — read cve_description and bad_code_example. Identify:
CWE-918 for SSRF, CWE-89 for SQLi, CWE-79 for XSS, CWE-78 for OS command injection, CWE-22 for path traversal, CWE-798 for hardcoded credentials).A01:2021 - Broken Access Control, A03:2021 - Injection, etc.).ERROR for clear high-impact patterns (SQLi, RCE, SSRF, command injection); WARNING for context-dependent or lower-impact (weak crypto, hardcoded secrets in non-prod paths); INFO for style/audit hints.Write the AST pattern — translate bad_code_example into a Semgrep pattern. Generalize correctly:
...) and metavariables ($X, $URL, etc.) instead of literal strings/identifiers.pattern-either covering common sources (req.body.$X, req.query.$X, req.params.$X in JS/TS Express).good_code_example is provided, infer a pattern-not that excludes it.Generate the rule id — <rule_id_prefix>.<short-slug> (default prefix custom). Slug from the vulnerability category — kebab-case, max 40 chars (e.g., ssrf-via-user-input, sql-injection-string-concat).
Compose rule.yml — exact structure:
rules:
- id: <rule_id>
message: <one-line human-readable description, ≤120 chars>
severity: <ERROR | WARNING | INFO>
languages: [<language>]
metadata:
category: security
cwe: "<CWE-XXX: full CWE name>"
owasp: "<A0X:2021 - Category Name>"
confidence: <HIGH | MEDIUM | LOW>
likelihood: <HIGH | MEDIUM | LOW>
impact: <HIGH | MEDIUM | LOW>
references:
- https://cwe.mitre.org/data/definitions/<CWE_NUMBER>.html
pattern-either:
- pattern: <generalized pattern matching bad_code_example>
# pattern-not:
# - pattern: <pattern matching good_code_example, if provided>Compose tests.md — Markdown with two fenced code blocks:
# Tests for <rule_id>
## Should match (vulnerable)
```<language>
<bad_code_example, formatted>The rule should flag this with severity <chosen>.
<good_code_example or LLM-inferred safe variant>This is the recommended way to write the same logic.
Compose README.md — Markdown explanation:
# <rule_id>
**Severity**: <ERROR/WARNING/INFO>
**CWE**: <CWE-XXX>
**OWASP**: <A0X:2021 - Category>
## What this rule catches
<2-3 sentence plain-English explanation>
## Why it matters
<1-2 sentences on the actual security impact, drawing from the cve_description>
## How to fix
<1-2 sentences pointing at the safe pattern>
## References
- [CWE-XXX](https://cwe.mitre.org/data/definitions/XXX.html)
- [OWASP A0X:2021](https://owasp.org/Top10/A0X_2021-...)Write all three files in order: rule.yml, tests.md, README.md via write_artifact.
Return structured output:
rule_id: the full id (e.g., custom.ssrf-via-user-input)severity: ERROR / WARNING / INFOcwe: e.g., CWE-918 (the identifier alone, no description)summary: one-line summary suitable for a security rule indexWARNING instead of ERROR and note the limitation in the README.message field appears in the developer's IDE/CI output. It should be a complete sentence.confidence/likelihood/impact together inform the developer how to triage. Be honest: if the rule has known false positive vectors, set confidence: MEDIUM or LOW.© skrun-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts) in agents/semgrep-rule-creator of skrun-dev/skrun.
Open the folder on GitHubat commit b1d963b
Semgrep Rule Creator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Semgrep Rule Creator this skillskrun-dev/skrun | 210 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Security Verification Gatefengshao1227/ccg-workflow | 5.9k | — | ~621 | Automated safety check: Notes | MIT | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 423 | — | ~2.7k | Automated safety check: Pass | None | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Security ReviewerJeffallan/claude-skills | 12k | — | ~1.3k | Automated safety check: Pass | MIT | |
| Building Devsecops Pipeline With GitLab CImukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 |
fengshao1227/ccg-workflow
Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
Jeffallan/claude-skills
Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.
mukul975/Anthropic-Cybersecurity-Skills
Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…
Aedelon/claude-code-blueprint
Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.
skrun-dev/skrun
Generate a numbered Architecture Decision Record (ADR) following the standard nygard/MADR convention.
skrun-dev/skrun
Generate a polished CHANGELOG.md and release-notes.md from a local git repository (or a captured .git-log.txt dump).
skrun-dev/skrun
Turn a CSV of operational data (sales, usage, signups, support tickets) into a multi-page styled PDF executive report with narrative + matplotlib charts.
skrun-dev/skrun
Turn a folder of Markdown notes (Obsidian vault, Notion export, plain repo docs) into a navigable static HTML knowledge base bundled as a single .zip file.
skrun-dev/skrun
Listen to a meeting recording and extract structured action items, decisions, and open questions.
skrun-dev/skrun
Read a batch of receipt images directly via vision, classify each into expense categories, optionally reconcile against a bank statement CSV, and produce a multi-sheet Excel workbook + a PDF summary.
Works with
Categories
Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. Semgrep Rule Creator is an agent skill from skrun-dev/skrun.md) from a CVE description and a bad-code example.
Semgrep Rule Creator fits situations like: asked to draft a Semgrep rule; encode a security pattern; productize a security finding for the codebase.
Run `npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a claude-code`. Or copy the skill folder (agents/semgrep-rule-creator in skrun-dev/skrun) into .claude/skills/semgrep-rule-creator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a codex`. Or copy the skill folder (agents/semgrep-rule-creator in skrun-dev/skrun) into .agents/skills/semgrep-rule-creator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semgrep-rule-creator, .gemini/skills/semgrep-rule-creator, .github/skills/semgrep-rule-creator and .opencode/skills/semgrep-rule-creator in your project.
Going by SKILL.md and its folder, Semgrep Rule Creator needs TypeScript for the scripts in its folder. Our summary lists: Node.js.
SKILL.md names 2 domains. In commands or code: cwe.mitre.org and owasp.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Semgrep Rule Creator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Semgrep Rule Creator: Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 423 stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars) and Security Reviewer (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
skrun-dev (a GitHub organization) maintains it in skrun-dev/skrun, which has 210 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 22, 2026.
Source: skrun-dev/skrun on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.