Official agent skill

CodeQL Security Scan

by trailofbits in trailofbits/skills

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

OfficialCC-BY-SA-4.0Auto-check: notesSecurity

Install CodeQL Security Scan

skills CLI
$ npx skills add trailofbits/skills --skill codeql -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills codeql --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/static-analysis/skills/codeql .claude/skills/codeql && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
codeql
GitHub stars
7.4k
Token cost
~4.6k tokens
SKILL.md length
1,762 words
Files
35 (incl. scripts, references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

  • Works in 6 steps: Database quality is non-negotiable. A… → Data extensions catch what CodeQL… → Explicit suite references prevent silent… → …
  • Running a CodeQL scan on a repository to find vulnerabilities
  • SKILL.md covers Essential Principles, Each Bash call is a fresh shell, Output Directory and Quick Start, plus 4 more sections
  • Runs Shell and Python scripts from its folder; calls jq; reaches github.com and docs.astral.sh

What it does

Supported languages are Python, JavaScript and TypeScript, Go, Java and Kotlin, C and C++, C#, Ruby and Swift. The skill's principles are that a database which builds is not automatically good, since a cached build can extract nothing while reporting success, that data extensions catch project-specific wrappers around database calls, request parsing and shell execution, and that an explicit `.qls` suite must always be generated instead of passing pack names. Zero findings must be investigated with `check_db_quality.py` and a suite check, and on Apple Silicon an exit code 137 is an arm64e mismatch, not a build failure.

Because every Bash call is a fresh shell, variables, arrays and sourced functions have to be re-established inside each block, or a lost function can silently push the build ladder down to `--build-mode=none`. Two scan modes exist: run all, combining security-and-quality with security-experimental, and important only, a high-precision set. The `semgrep` skill covers fast single-file matching or builds that are unavailable, and `sarif-parsing` handles existing SARIF. Reference files cover build fixes, extension YAML, performance tuning, rulesets, threat models and SARIF processing.

When your agent uses it

  • Running a CodeQL scan on a repository to find vulnerabilities
  • Building a CodeQL database and checking its quality
  • Modeling project-specific sources and sinks with data extensions
  • Choosing between a run-all scan and a high-precision scan

Example prompts

  • “Run a CodeQL scan on this repo in important-only mode and summarize the findings.”
  • “Build a CodeQL database for this Java service and check that extraction actually worked.”
  • “CodeQL found nothing in my Django app. Check the database quality and add data extensions for our wrapper functions.”
  • “My CodeQL build exits with code 137 on an Apple Silicon Mac. What should I try?”

Requirements

  • The CodeQL CLI
  • A buildable project when scanning compiled languages
  • Python 3 for the quality-check scripts
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Edit, Glob, Grep, AskUserQuestion, TaskCreate, TaskList, TaskUpdate, TaskGet

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Database quality is non-negotiable. A database that builds is not automatically good — a cached build extracts nothing while reporting…
  2. Data extensions catch what CodeQL misses. Django, Spring, and Express projects still wrap database calls, request parsing, and shell…
  3. Explicit suite references prevent silent query dropping. Never pass pack names to codeql database analyze — each pack's defaultSuiteFile…
  4. Zero findings needs investigation, not celebration. It can mean poor extraction, missing models, the wrong packs, or suite filtering. Run…
  5. macOS Apple Silicon requires workarounds for compiled languages. Exit code 137 is an arm64e/arm64 mismatch, not a build failure. Try…
  6. Follow workflows step by step. Each phase gates the next; skipping quality assessment or data extensions leaves the gap invisible in the…

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Edit
    • Glob
    • Grep
    • AskUserQuestion
    • TaskCreate
    • TaskList
    • TaskUpdate

    …and 1 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell and Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • docs.astral.sh

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

CodeQL Security Scan loads about 4.6k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 190 tokens; SKILL.md has 1,762 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~190
When it runs · the whole SKILL.md, loaded when a task matches
~4.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~21k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Edit, Glob, Grep, AskUserQuestion, TaskCreate, TaskList, TaskUpdate, TaskGet

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,762 words, ~4,618 tokens.

Download SKILL.mdSave it as .claude/skills/codeql/SKILL.md (or your agent's skills folder). This skill also uses 34 other files; get the full folder from GitHub.
name
codeql
description
Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "build codeql database", "SAST scan", "taint analysis", "dataflow analysis", or "find vulnerabilities in this repo". Covers Python, JavaScript/TypeScript, Go, Java/Kotlin, C/C++, C#, Ruby, and Swift. Supports "run all" (security-and-quality + security-experimental) and "important only" (high-precision) scan modes, and creates data extension models for project-specific sources and sinks. For fast single-file pattern matching, or when no build is available for a compiled language, use the semgrep skill; to parse SARIF that already exists rather than produce it, use the sarif-parsing skill.
allowed-tools
Bash, Read, Write, Edit, Glob, Grep, AskUserQuestion, TaskCreate, TaskList, TaskUpdate, TaskGet

CodeQL Analysis

Supported languages: Python, JavaScript/TypeScript, Go, Java/Kotlin, C/C++, C#, Ruby, Swift.

Skill resources: Reference files and templates are located at {baseDir}/references/ and {baseDir}/workflows/.

Essential Principles

  1. Database quality is non-negotiable. A database that builds is not automatically good — a cached build extracts nothing while reporting success.

  2. Data extensions catch what CodeQL misses. Django, Spring, and Express projects still wrap database calls, request parsing, and shell execution in project-specific APIs that no shipped model covers.

  3. Explicit suite references prevent silent query dropping. Never pass pack names to codeql database analyze — each pack's defaultSuiteFile applies hidden filters that can produce zero results. Always generate a .qls.

  4. Zero findings needs investigation, not celebration. It can mean poor extraction, missing models, the wrong packs, or suite filtering. Run {baseDir}/scripts/check_db_quality.py after the build, confirm {baseDir}/scripts/verify_query_suite.py exited zero for the suite in use — the generation scripts run it, so invoke it by hand only for a reused or hand-edited suite — and say in the report that both passed.

  5. macOS Apple Silicon requires workarounds for compiled languages. Exit code 137 is an arm64e/arm64 mismatch, not a build failure. Try Homebrew arm64 tools or Rosetta before falling back to build-mode=none.

  6. Follow workflows step by step. Each phase gates the next; skipping quality assessment or data extensions leaves the gap invisible in the results.

Each Bash call is a fresh shell

Nothing carries across a Bash call: not variables, not arrays, not functions sourced from build_log.sh. Every block below that uses a value must re-establish it in the same block. The workflows point back here rather than repeating it; what they do state is the specific damage at that site, because each one fails differently and silently:

  • a lost function makes run_logged exit 127, which the build ladder reads as a failed method and walks down to --build-mode=none, never having invoked CodeQL
  • a lost array expands to nothing, so every --threat-model and --model-packs the user chose is dropped while the final report still lists them as used
  • a lost scalar under set -u aborts the block with unbound variable

Output Directory

All generated files (database, build logs, diagnostics, extensions, results) are stored in a single output directory.

  • If the user specifies an output directory in their prompt, use it as OUTPUT_DIR.
  • If not specified, default to ./static_analysis_codeql_1. If that already exists, increment to _2, _3, etc.

In both cases, always create the directory with mkdir -p before writing any files.

Set USER_SPECIFIED_DIR to the literal path from the user's prompt before running this, or leave it unset to auto-increment. Nothing else assigns it.

bash
# Resolve output directory
USER_SPECIFIED_DIR="${USER_SPECIFIED_DIR:-}"   # substitute the user's path here, if any
if [ -n "$USER_SPECIFIED_DIR" ]; then
  OUTPUT_DIR="$USER_SPECIFIED_DIR"
else
  BASE="static_analysis_codeql"
  N=1
  while [ -e "${BASE}_${N}" ]; do
    N=$((N + 1))
  done
  OUTPUT_DIR="${BASE}_${N}"
fi
mkdir -p "$OUTPUT_DIR"

The output directory is resolved once at the start before any workflow executes. All workflows receive $OUTPUT_DIR and store their artifacts there:

$OUTPUT_DIR/
├── rulesets.txt                 # Selected query packs (logged after Step 3)
├── codeql.db/                   # CodeQL database (dir containing codeql-database.yml)
├── build.log                    # Build log
├── codeql-config.yml            # Exclusion config (interpreted languages)
├── diagnostics/                 # Diagnostic queries and CSVs
├── extensions/                  # Data extension YAMLs
├── raw/                         # Unfiltered analysis output
│   ├── results.sarif
│   └── run-all.qls | important-only.qls
└── results/                     # Final results (filtered for important-only, copied for run-all)
    └── results.sarif
Database Discovery

A CodeQL database is identified by the presence of a codeql-database.yml marker file inside its directory. When searching for existing databases, always collect all matches — there may be multiple databases from previous runs or for different languages.

Discovery command. find_databases.sh prints one database path per line, filtering out the marker files a failed build leaves behind. Build the array in the same block that selects from it — each Bash call is a fresh shell, so an array built here is empty by the next call, and the run concludes there is no database:

bash
# Command substitution, not `done < <(...)`: a process substitution discards the script's
# exit status, so "codeql is not on this shell's PATH" (exit 2) would arrive as an empty
# list and route to "build a new database" with three good ones sitting on disk.
if ! DB_LIST=$("{baseDir}/scripts/find_databases.sh" "${OUTPUT_DIR:-.}" .); then
  echo "ERROR: database discovery failed — see the message above" >&2
  exit 1
fi

FOUND_DBS=()
while IFS= read -r db; do
  [ -n "$db" ] || continue
  FOUND_DBS+=("$db")
done <<<"$DB_LIST"

echo "Found ${#FOUND_DBS[@]} existing database(s)"

# The metadata the selection prompt needs, collected here rather than in a block of its
# own: FOUND_DBS is gone by the next Bash call, and a loop over an array that no longer
# exists prints nothing and reports success.
for db in "${FOUND_DBS[@]}"; do
  CODEQL_LANG=$(codeql resolve database --format=json -- "$db" 2>/dev/null | jq -r '.languages[0]')
  CREATED=$(grep '^creationMetadata:' -A5 "$db/codeql-database.yml" 2>/dev/null | grep 'creationTime' | awk '{print $2}')
  echo "$db — language: $CODEQL_LANG, created: $CREATED"
done

Never assume a database is named codeql.db — discover it by its marker file.

When multiple databases are found: use AskUserQuestion to let the user select which database to use, or to build a new one, from the language and creation time printed above. AskUserQuestion takes at most four options, so with more databases than that, offer the three most recent plus "Build a new database" and list the rest in the prompt text. Skip AskUserQuestion if the user explicitly stated which database to use or to build a new one in their prompt.

Quick Start

For the common case ("scan this codebase for vulnerabilities"):

bash
# Verify CodeQL is installed. Stop here if it is not — every later command fails with
# a less informative error, and the run wastes a build cycle before saying why.
if ! command -v codeql >/dev/null 2>&1; then
  echo "ERROR: codeql not found on PATH. Install it with one of:" >&2
  echo "  gh extension install github/gh-codeql   # then: gh codeql install-stub" >&2
  echo "  brew install --cask codeql" >&2
  echo "  https://github.com/github/codeql-action/releases  (codeql-bundle)" >&2
  exit 1
fi

# jq parses `codeql resolve database --format=json` in the very next step. Without it
# CODEQL_LANG comes back empty and the run continues against the wrong language.
if ! command -v jq >/dev/null 2>&1; then
  echo "ERROR: jq not found on PATH (brew install jq / apt install jq)" >&2
  exit 1
fi

# uv runs both guard scripts and both suite generators. Check it here rather than at
# suite generation, which is after the build — otherwise a machine without uv spends
# the whole build before failing.
if ! command -v uv >/dev/null 2>&1; then
  echo "ERROR: uv not found on PATH (https://docs.astral.sh/uv/getting-started/)" >&2
  exit 1
fi

codeql --version

Then resolve OUTPUT_DIR using the block in Output Directory above — it honours a user-specified directory, which a bare auto-increment does not.

Then execute the full pipeline: build database → create data extensions → run analysis using the workflows below.

Rationalizations to Reject

These shortcuts lead to missed findings. Do not accept them:

  • "security-extended is enough" - It is the baseline. Always check if Trail of Bits packs and Community Packs are available for the language. They catch categories security-extended misses entirely.
  • "security-and-quality is the broadest suite" - security-and-quality excludes all experimental/ query paths. For run-all mode, import both security-and-quality and security-experimental. The delta is 1–52 queries depending on the language.
  • "The database built, so it's good" - A database that builds does not mean it extracted well. Always run quality assessment and check file counts against expected source files.
  • "Data extensions aren't needed for standard frameworks" - Even Django/Spring apps have custom wrappers that CodeQL does not model. Skipping extensions means missing vulnerabilities.
  • "build-mode=none is fine for compiled languages" - It produces severely incomplete analysis. Only use as an absolute last resort. On macOS, try the arm64 toolchain workaround or Rosetta first.
  • "The build fails on macOS, just use build-mode=none" - Exit code 137 is caused by arm64e/arm64 mismatch, not a fundamental build failure. See macos-arm64e-workaround.md.
  • "No findings means the code is secure" - Run check_db_quality.py and verify_query_suite.py and report that they passed. Without them, zero findings and a database that extracted nothing are the same output.
  • "I'll just run the default suite" / "I'll just pass the pack names directly" - Each pack's defaultSuiteFile applies hidden filters and can produce zero results. Always use an explicit suite reference.
  • "I'll put files in the current directory" - All generated files must go in $OUTPUT_DIR. Scattering files in the working directory makes cleanup impossible and risks overwriting previous runs.
  • "Just use the first database I find" - Multiple databases may exist for different languages or from previous runs. When more than one is found, present all options to the user. Only skip the prompt when the user already specified which database to use.
  • "The user said 'scan', that means they want me to pick a database" - "Scan" is not database selection. If multiple databases exist and the user didn't name one, ask.

Show full SKILL.md (743 more words)Show less

Workflow Selection

This skill has three workflows. Once a workflow is selected, execute it step by step without skipping phases.

These runs are long. A database build has four fallback methods, so use the task tools to track progress. Decide which steps are worth tracking based on the run.

WorkflowPurpose
build-databaseCreate CodeQL database using build methods in sequence
create-data-extensionsDetect or generate data extension models for project APIs
run-analysisSelect rulesets, execute queries, process results
Building unattended

This plugin ships /static-analysis:codeql-build, which runs the build-database steps end to end: detect the language and toolchain, walk the method ladder applying fixes from build-fixes.md between rungs, and enforce the quality gate.

/static-analysis:codeql-build {"target": "/abs/path", "lang": "cpp"}

It asks nothing. Every method failing, and a database that built but sits below the quality threshold, come back as statuses — no-method-succeeded and built-below-threshold — for you to act on here, because whether the remaining extractor errors are confined to code nobody needs analysed is a judgement call the run cannot make.

Use it when the build is the long, uncertain part and you want it driven to a conclusion. Work build-database.md by hand when you want a say in which method is tried, or when a build failure needs interpreting as it happens.

Auto-Detection Logic

If user explicitly specifies what to do (e.g., "build a database", "run analysis on ./my-db"), execute that workflow directly. Do NOT call AskUserQuestion for database selection if the user's prompt already makes their intent clear — e.g., "build a new database", "analyze the codeql database in static_analysis_codeql_2", "run a full scan from scratch".

Default pipeline for "test", "scan", "analyze", or similar: Discover existing databases using the command in Database Discovery above, then decide.

ConditionAction
No databases foundResolve new $OUTPUT_DIR, execute build → extensions → analysis (full pipeline)
One database foundUse AskUserQuestion: reuse it or build new?
Multiple databases foundUse AskUserQuestion, capped at four options — see Database Discovery
User explicitly stated intentSkip AskUserQuestion, act on their instructions directly
Database Selection Prompt

When existing databases are found and the user did not explicitly specify which to use, present them via AskUserQuestion under the header "Existing CodeQL Databases". Label each option with the path, language, and creation time collected above — ./static_analysis_codeql_1/codeql.db (language: python, created: 2026-02-24) — and make the last option "Build a new database".

After selection:

  • If user picks an existing database: Set $OUTPUT_DIR to its parent directory (or the directory containing it), set $DB_NAME to the selected path, then proceed to extensions → analysis.
  • If user picks "Build new": Resolve a new $OUTPUT_DIR, execute build → extensions → analysis.
General Decision Prompt

If neither the database nor the workflow is clear from the prompt, offer the four workflows via AskUserQuestion — full scan (recommended), build database, create data extensions, run analysis — naming any databases found and the resolved $OUTPUT_DIR.


Reference Index

FileContent
Scripts
scripts/verify_query_suite.pyFails a suite that resolves to zero queries. The generation scripts run it; invoke by hand only for a reused or hand-edited suite
scripts/check_db_quality.pyFails a database with no analysable source. Run after every build
scripts/build_log.shlog_step/run_logged helpers; source before any build step
scripts/find_databases.shPrints every database that codeql resolve database accepts, one per line. Build your array from it in the block that reads it
scripts/generate_suite.shWrites the run-all or important-only .qls and verifies it resolves to a non-zero query count
References — the three workflows are listed under Workflow Selection
references/macos-arm64e-workaround.mdApple Silicon build tracing workarounds
references/build-fixes.mdBuild failure fix catalog
references/quality-assessment.mdDatabase quality metrics and improvements
references/extension-yaml-format.mdData extension YAML column definitions and examples
references/sarif-processing.mdjq commands for SARIF output processing
references/diagnostic-query-templates.mdQL queries for source/sink enumeration
references/important-only-suite.mdImportant-only suite template and generation
references/run-all-suite.mdRun-all suite template
references/ruleset-catalog.mdAvailable query packs by language
references/threat-models.mdThreat model configuration
references/language-details.mdLanguage-specific build and extraction details
references/performance-tuning.mdMemory, threading, and timeout configuration

Success Criteria

A complete CodeQL analysis run should satisfy:

  • Output directory resolved (user-specified or auto-incremented default)
  • All generated files stored inside $OUTPUT_DIR
  • Database built (discovered via codeql-database.yml marker) and {baseDir}/scripts/check_db_quality.py exited zero
  • Data extensions evaluated — either created in $OUTPUT_DIR/extensions/ or explicitly skipped with justification
  • Analysis run with explicit suite reference (not default pack suite), and {baseDir}/scripts/verify_query_suite.py exited zero for it
  • All installed query packs (official + Trail of Bits + Community) used or explicitly excluded
  • Selected query packs logged to $OUTPUT_DIR/rulesets.txt
  • Unfiltered results preserved in $OUTPUT_DIR/raw/results.sarif
  • Final results in $OUTPUT_DIR/results/results.sarif (filtered for important-only, copied for run-all)
  • Zero-finding results investigated (database quality, model coverage, suite selection)
  • Build log preserved at $OUTPUT_DIR/build.log with all commands, fixes, and quality assessments

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 34 other files (scripts, references, assets) in plugins/static-analysis/skills/codeql of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/build-fixes.md
  • references/diagnostic-query-templates.md
  • references/extension-yaml-format.md
  • references/important-only-suite.md
  • references/language-details.md
  • references/macos-arm64e-workaround.md
  • references/performance-tuning.md
  • references/quality-assessment.md
  • references/ruleset-catalog.md
  • references/run-all-suite.md
  • references/sarif-processing.md
  • references/threat-models.md
  • scripts/build_log.sh
  • scripts/check_db_quality.py
  • … and 18 more

Open the folder on GitHubat commit 82fe822

Compare with similar skills

CodeQL Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

CodeQL Security Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
CodeQL Security Scan this skilltrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Taint Instrumentation AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.0
Codeqlgithub/awesome-copilot40k1 repos~3.4kAutomated safety check: PassMIT
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Codeql

    github/awesome-copilot

    Official

    Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.

    40k GitHub starsUsed in 1 repo~3.4k tokens
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Failure Oriented Instrumentation

    ArabelaTso/Skills-4-SE

    Selectively instruments code to capture runtime data for debugging failures and bugs.

    253 GitHub stars~2.1k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub stars~1.7k tokensUpdated 5 days ago
    Auto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 3 repos~4.2k tokens
    Auto-check: notes
  • Code Context Slicing

    trailofbits/skills

    Official

    Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository.

    7.4k GitHub stars~2.1k tokensUpdated 5 days ago
    Auto-check passed

Categories

Questions about CodeQL Security Scan

What does CodeQL Security Scan do?

Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. Supported languages are Python, JavaScript and TypeScript, Go, Java and Kotlin, C and C++, C#, Ruby and Swift.qls` suite must always be generated instead of passing pack names.

When should I use CodeQL Security Scan?

CodeQL Security Scan fits situations like: running a CodeQL scan on a repository to find vulnerabilities; building a CodeQL database and checking its quality; modeling project-specific sources and sinks with data extensions; choosing between a run-all scan and a high-precision scan.

How do I install CodeQL Security Scan in Claude Code?

Run `npx skills add trailofbits/skills --skill codeql -a claude-code`. Or copy the skill folder (plugins/static-analysis/skills/codeql in trailofbits/skills) into .claude/skills/codeql in your project. Claude Code loads it when a task matches its description.

How do I install CodeQL Security Scan in Codex?

Run `npx skills add trailofbits/skills --skill codeql -a codex`. Or copy the skill folder (plugins/static-analysis/skills/codeql in trailofbits/skills) into .agents/skills/codeql in your project. Codex loads it when a task matches its description.

Can I use CodeQL Security Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill codeql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codeql, .gemini/skills/codeql, .github/skills/codeql and .opencode/skills/codeql in your project.

What does CodeQL Security Scan need to run?

Going by SKILL.md and its folder, CodeQL Security Scan needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (jq). Our summary lists: The CodeQL CLI; A buildable project when scanning compiled languages; Python 3 for the quality-check scripts. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, AskUserQuestion, TaskCreate, TaskList, TaskUpdate, TaskGet.

Does CodeQL Security Scan access the network?

SKILL.md names 2 domains. In commands or code: github.com and docs.astral.sh; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is CodeQL Security Scan safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does CodeQL Security Scan use?

CodeQL Security Scan is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does CodeQL Security Scan use?

About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.

What are the alternatives to CodeQL Security Scan?

Skills that share tags, products or a category with CodeQL Security Scan: Code Audit (3stoneBrother/code-audit, 893 stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars), Taint Instrumentation Assistant (ArabelaTso/Skills-4-SE, 253 stars) and Codeql (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains CodeQL Security Scan?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.