Agent skill

Semgrep Rule Creator

by skrun-dev in skrun-dev/skrun

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

MITAuto-check passedSecurity

Install Semgrep Rule Creator

skills CLI
$ npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install skrun-dev/skrun semgrep-rule-creator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/skrun-dev/skrun.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/semgrep-rule-creator .claude/skills/semgrep-rule-creator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
semgrep-rule-creator
GitHub stars
210
Token cost
~1.3k tokens
SKILL.md length
382 words
Files
5 (incl. scripts)
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

  • Works in 3 steps: rule.yml — the actual Semgrep rule (drop… → tests.md — good/bad code examples that… → README.md — rationale, severity…
  • Asked to draft a Semgrep rule
  • SKILL.md covers Workflow, Should NOT match (safe) and Style
  • Runs TypeScript scripts from its folder; reaches cwe.mitre.org and owasp.org

What it does

Semgrep Rule Creator is an agent skill from skrun-dev/skrun. Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. Picks an appropriate severity, infers the right CWE/OWASP mapping, and produces a ready-to-commit rule with documentation. Use when asked to draft a Semgrep rule, encode a security pattern, or productize a security finding for the codebase.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts (for example `README.md`, `agent.yaml` and `fixtures/sample-cve.md`).

It sits in Security, covering Static analysis and SAST, Web application vulnerabilities and Vulnerability scanning. It works with Semgrep. The repository describes itself as: Deploy any Agent Skill as an API via POST /run. The open-source multi-model alternative to Claude Managed Agents, Microsoft Foundry & Mistral/Koyeb — works with any LLM. The licence is MIT.

When your agent uses it

  • Asked to draft a Semgrep rule
  • Encode a security pattern
  • Productize a security finding for the codebase

Example prompts

  • “/semgrep-rule-creator”

Requirements

  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. rule.yml — the actual Semgrep rule (drop into the repo's .semgrep/ directory).
  2. tests.md — good/bad code examples that document expected behavior.
  3. README.md — rationale, severity reasoning, references (CWE/OWASP links).

What it can do on your machine

Read from SKILL.md and the folder at commit b1d963b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (TypeScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cwe.mitre.org
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Semgrep Rule Creator loads about 1.3k tokens when it runs. Until then it costs about 96 tokens; SKILL.md has 382 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from skrun-dev/skrun at commit b1d963b, republished under its MIT licence (© skrun-dev). 382 words, ~1,252 tokens.

Download SKILL.mdSave it as .claude/skills/semgrep-rule-creator/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
semgrep-rule-creator
description
Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. Picks an appropriate severity, infers the right CWE/OWASP mapping, and produces a ready-to-commit rule with documentation. Use when asked to draft a Semgrep rule, encode a security pattern, or productize a security finding for the codebase.

Semgrep Rule Creator

You are a security engineer who writes Semgrep rules for a living. Given a vulnerability description and a concrete bad-code example, you produce three artifacts:

  1. rule.yml — the actual Semgrep rule (drop into the repo's .semgrep/ directory).
  2. tests.md — good/bad code examples that document expected behavior.
  3. README.md — rationale, severity reasoning, references (CWE/OWASP links).

Workflow

  1. Analyze the input — read cve_description and bad_code_example. Identify:

    • The vulnerability category (SSRF, SQLi, XSS, command injection, path traversal, hardcoded secret, weak crypto, deserialization, etc.)
    • The most appropriate CWE (e.g., CWE-918 for SSRF, CWE-89 for SQLi, CWE-79 for XSS, CWE-78 for OS command injection, CWE-22 for path traversal, CWE-798 for hardcoded credentials).
    • The most appropriate OWASP Top 10 (2021) category (A01:2021 - Broken Access Control, A03:2021 - Injection, etc.).
    • Severity: ERROR for clear high-impact patterns (SQLi, RCE, SSRF, command injection); WARNING for context-dependent or lower-impact (weak crypto, hardcoded secrets in non-prod paths); INFO for style/audit hints.
  2. Write the AST pattern — translate bad_code_example into a Semgrep pattern. Generalize correctly:

    • Use ellipsis (...) and metavariables ($X, $URL, etc.) instead of literal strings/identifiers.
    • For tainted-input flow patterns, prefer pattern-either covering common sources (req.body.$X, req.query.$X, req.params.$X in JS/TS Express).
    • If a good_code_example is provided, infer a pattern-not that excludes it.
  3. Generate the rule id — <rule_id_prefix>.<short-slug> (default prefix custom). Slug from the vulnerability category — kebab-case, max 40 chars (e.g., ssrf-via-user-input, sql-injection-string-concat).

  4. Compose rule.yml — exact structure:

    yaml
    rules:
      - id: <rule_id>
        message: <one-line human-readable description, ≤120 chars>
        severity: <ERROR | WARNING | INFO>
        languages: [<language>]
        metadata:
          category: security
          cwe: "<CWE-XXX: full CWE name>"
          owasp: "<A0X:2021 - Category Name>"
          confidence: <HIGH | MEDIUM | LOW>
          likelihood: <HIGH | MEDIUM | LOW>
          impact: <HIGH | MEDIUM | LOW>
          references:
            - https://cwe.mitre.org/data/definitions/<CWE_NUMBER>.html
        pattern-either:
          - pattern: <generalized pattern matching bad_code_example>
        # pattern-not:
        #   - pattern: <pattern matching good_code_example, if provided>
  5. Compose tests.md — Markdown with two fenced code blocks:

    markdown
    # Tests for <rule_id>
    
    ## Should match (vulnerable)
    
    ```<language>
    <bad_code_example, formatted>

    The rule should flag this with severity <chosen>.

    Should NOT match (safe)

    language
    <good_code_example or LLM-inferred safe variant>

    This is the recommended way to write the same logic.

  6. Compose README.md — Markdown explanation:

    markdown
    # <rule_id>
    
    **Severity**: <ERROR/WARNING/INFO>
    **CWE**: <CWE-XXX>
    **OWASP**: <A0X:2021 - Category>
    
    ## What this rule catches
    
    <2-3 sentence plain-English explanation>
    
    ## Why it matters
    
    <1-2 sentences on the actual security impact, drawing from the cve_description>
    
    ## How to fix
    
    <1-2 sentences pointing at the safe pattern>
    
    ## References
    
    - [CWE-XXX](https://cwe.mitre.org/data/definitions/XXX.html)
    - [OWASP A0X:2021](https://owasp.org/Top10/A0X_2021-...)
  7. Write all three files in order: rule.yml, tests.md, README.md via write_artifact.

  8. Return structured output:

    • rule_id: the full id (e.g., custom.ssrf-via-user-input)
    • severity: ERROR / WARNING / INFO
    • cwe: e.g., CWE-918 (the identifier alone, no description)
    • summary: one-line summary suitable for a security rule index
Show full SKILL.md (80 more words)Show less

Style

  • Patterns must be sound — false positives erode trust in security tooling. If you're unsure whether a pattern would over-match, use WARNING instead of ERROR and note the limitation in the README.
  • The message field appears in the developer's IDE/CI output. It should be a complete sentence.
  • Avoid copy-pasting the user's bad_code_example verbatim into the pattern — generalize.
  • confidence/likelihood/impact together inform the developer how to triage. Be honest: if the rule has known false positive vectors, set confidence: MEDIUM or LOW.

© skrun-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts) in agents/semgrep-rule-creator of skrun-dev/skrun.

  • SKILL.md
  • README.md
  • agent.yaml
  • fixtures/sample-cve.md
  • scripts/write_artifact.ts

Open the folder on GitHubat commit b1d963b

Compare with similar skills

Semgrep Rule Creator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Semgrep Rule Creator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Semgrep Rule Creator this skillskrun-dev/skrun210—~1.3kAutomated safety check: PassMIT
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Secknowledge SkillPa55w0rd/secknowledge-skill423—~2.7kAutomated safety check: PassNone
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Building Devsecops Pipeline With GitLab CImukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    423 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Building Devsecops Pipeline With GitLab CI

    mukul975/Anthropic-Cybersecurity-Skills

    Configure a GitLab CI/CD pipeline that embeds SAST (Semgrep, SpotBugs, Gosec, Bandit, NodeJsScan), DAST, container scanning, dependency scanning, and secret detection via GitLab's managed security…

    34k GitHub stars~2.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Audit

    Aedelon/claude-code-blueprint

    Proactive security audit: OWASP top 10, dependency vulnerabilities, secrets detection, input validation, auth patterns, and secure defaults.

    120 GitHub stars~1.6k tokensUpdated 7 mo ago
    SecurityAuto-check: notes

More from skrun-dev/skrun

All 14 skills in this repo
  • Adr Writer

    skrun-dev/skrun

    Generate a numbered Architecture Decision Record (ADR) following the standard nygard/MADR convention.

    210 GitHub stars~861 tokensUpdated 15 days ago
    Auto-check passed
  • Changelog Generator

    skrun-dev/skrun

    Generate a polished CHANGELOG.md and release-notes.md from a local git repository (or a captured .git-log.txt dump).

    210 GitHub stars~770 tokensUpdated 15 days ago
    Auto-check passed
  • Turn a CSV of operational data (sales, usage, signups, support tickets) into a multi-page styled PDF executive report with narrative + matplotlib charts.

    210 GitHub stars~1.1k tokensUpdated 15 days ago
    Auto-check passed
  • Turn a folder of Markdown notes (Obsidian vault, Notion export, plain repo docs) into a navigable static HTML knowledge base bundled as a single .zip file.

    210 GitHub stars~1.4k tokensUpdated 15 days ago
    Auto-check passed
  • Listen to a meeting recording and extract structured action items, decisions, and open questions.

    210 GitHub stars~1.3k tokensUpdated 15 days ago
    Auto-check passed
  • Receipts To Expenses

    skrun-dev/skrun

    Read a batch of receipt images directly via vision, classify each into expense categories, optionally reconcile against a bank statement CSV, and produce a multi-sheet Excel workbook + a PDF summary.

    210 GitHub stars~1.1k tokensUpdated 15 days ago
    Auto-check passed

Works with

Categories

Questions about Semgrep Rule Creator

What does Semgrep Rule Creator do?

Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example. Semgrep Rule Creator is an agent skill from skrun-dev/skrun.md) from a CVE description and a bad-code example.

When should I use Semgrep Rule Creator?

Semgrep Rule Creator fits situations like: asked to draft a Semgrep rule; encode a security pattern; productize a security finding for the codebase.

How do I install Semgrep Rule Creator in Claude Code?

Run `npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a claude-code`. Or copy the skill folder (agents/semgrep-rule-creator in skrun-dev/skrun) into .claude/skills/semgrep-rule-creator in your project. Claude Code loads it when a task matches its description.

How do I install Semgrep Rule Creator in Codex?

Run `npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a codex`. Or copy the skill folder (agents/semgrep-rule-creator in skrun-dev/skrun) into .agents/skills/semgrep-rule-creator in your project. Codex loads it when a task matches its description.

Can I use Semgrep Rule Creator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add skrun-dev/skrun --skill semgrep-rule-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semgrep-rule-creator, .gemini/skills/semgrep-rule-creator, .github/skills/semgrep-rule-creator and .opencode/skills/semgrep-rule-creator in your project.

What does Semgrep Rule Creator need to run?

Going by SKILL.md and its folder, Semgrep Rule Creator needs TypeScript for the scripts in its folder. Our summary lists: Node.js.

Does Semgrep Rule Creator access the network?

SKILL.md names 2 domains. In commands or code: cwe.mitre.org and owasp.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Semgrep Rule Creator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Semgrep Rule Creator use?

Semgrep Rule Creator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Semgrep Rule Creator use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Semgrep Rule Creator?

Skills that share tags, products or a category with Semgrep Rule Creator: Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 423 stars), Cyber Neo (Hainrixz/cyber-neo, 281 stars) and Security Reviewer (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Semgrep Rule Creator?

skrun-dev (a GitHub organization) maintains it in skrun-dev/skrun, which has 210 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 22, 2026.

Source: skrun-dev/skrun on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.