Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
$ npx skills add trailofbits/skills --skill codeql -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills codeql --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/static-analysis/skills/codeql .claude/skills/codeql && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "codeql" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/static-analysis/skills/codeql into .claude/skills/codeql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codeql", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/static-analysis/skills/codeqlType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill codeql -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills codeql --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/static-analysis/skills/codeql .agents/skills/codeql && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "codeql" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/static-analysis/skills/codeql into .agents/skills/codeql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codeql", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill codeql -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills codeql --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/static-analysis/skills/codeql .cursor/skills/codeql && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "codeql" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/static-analysis/skills/codeql into .cursor/skills/codeql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codeql", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/static-analysis/skills/codeql--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill codeql -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills codeql --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/static-analysis/skills/codeql .gemini/skills/codeql && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "codeql" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/static-analysis/skills/codeql into .gemini/skills/codeql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codeql", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills codeqlInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill codeql -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/static-analysis/skills/codeql .github/skills/codeql && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "codeql" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/static-analysis/skills/codeql into .github/skills/codeql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codeql", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill codeql -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills codeql --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/static-analysis/skills/codeql .opencode/skills/codeql && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "codeql" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/static-analysis/skills/codeql into .opencode/skills/codeql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "codeql", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
codeqlScans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
Supported languages are Python, JavaScript and TypeScript, Go, Java and Kotlin, C and C++, C#, Ruby and Swift. The skill's principles are that a database which builds is not automatically good, since a cached build can extract nothing while reporting success, that data extensions catch project-specific wrappers around database calls, request parsing and shell execution, and that an explicit `.qls` suite must always be generated instead of passing pack names. Zero findings must be investigated with `check_db_quality.py` and a suite check, and on Apple Silicon an exit code 137 is an arm64e mismatch, not a build failure.
Because every Bash call is a fresh shell, variables, arrays and sourced functions have to be re-established inside each block, or a lost function can silently push the build ladder down to `--build-mode=none`. Two scan modes exist: run all, combining security-and-quality with security-experimental, and important only, a high-precision set. The `semgrep` skill covers fast single-file matching or builds that are unavailable, and `sarif-parsing` handles existing SARIF. Reference files cover build fixes, extension YAML, performance tuning, rulesets, threat models and SARIF processing.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteEditGlobGrepAskUserQuestionTaskCreateTaskListTaskUpdate…and 1 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Shell and Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
jqFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comdocs.astral.shFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
CodeQL Security Scan loads about 4.6k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 190 tokens; SKILL.md has 1,762 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Edit, Glob, Grep, AskUserQuestion, TaskCreate, TaskList, TaskUpdate, TaskGetAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,762 words, ~4,618 tokens.
.claude/skills/codeql/SKILL.md (or your agent's skills folder). This skill also uses 34 other files; get the full folder from GitHub.Supported languages: Python, JavaScript/TypeScript, Go, Java/Kotlin, C/C++, C#, Ruby, Swift.
Skill resources: Reference files and templates are located at {baseDir}/references/ and {baseDir}/workflows/.
Database quality is non-negotiable. A database that builds is not automatically good — a cached build extracts nothing while reporting success.
Data extensions catch what CodeQL misses. Django, Spring, and Express projects still wrap database calls, request parsing, and shell execution in project-specific APIs that no shipped model covers.
Explicit suite references prevent silent query dropping. Never pass pack names to codeql database analyze — each pack's defaultSuiteFile applies hidden filters that can produce zero results. Always generate a .qls.
Zero findings needs investigation, not celebration. It can mean poor extraction, missing models, the wrong packs, or suite filtering. Run {baseDir}/scripts/check_db_quality.py after the build, confirm {baseDir}/scripts/verify_query_suite.py exited zero for the suite in use — the generation scripts run it, so invoke it by hand only for a reused or hand-edited suite — and say in the report that both passed.
macOS Apple Silicon requires workarounds for compiled languages. Exit code 137 is an arm64e/arm64 mismatch, not a build failure. Try Homebrew arm64 tools or Rosetta before falling back to build-mode=none.
Follow workflows step by step. Each phase gates the next; skipping quality assessment or data extensions leaves the gap invisible in the results.
Nothing carries across a Bash call: not variables, not arrays, not functions sourced from
build_log.sh. Every block below that uses a value must re-establish it in the same block.
The workflows point back here rather than repeating it; what they do state is the specific
damage at that site, because each one fails differently and silently:
run_logged exit 127, which the build ladder reads as a failed
method and walks down to --build-mode=none, never having invoked CodeQL--threat-model and --model-packs the user
chose is dropped while the final report still lists them as usedset -u aborts the block with unbound variableAll generated files (database, build logs, diagnostics, extensions, results) are stored in a single output directory.
OUTPUT_DIR../static_analysis_codeql_1. If that already exists, increment to _2, _3, etc.In both cases, always create the directory with mkdir -p before writing any files.
Set USER_SPECIFIED_DIR to the literal path from the user's prompt before running this,
or leave it unset to auto-increment. Nothing else assigns it.
# Resolve output directory
USER_SPECIFIED_DIR="${USER_SPECIFIED_DIR:-}" # substitute the user's path here, if any
if [ -n "$USER_SPECIFIED_DIR" ]; then
OUTPUT_DIR="$USER_SPECIFIED_DIR"
else
BASE="static_analysis_codeql"
N=1
while [ -e "${BASE}_${N}" ]; do
N=$((N + 1))
done
OUTPUT_DIR="${BASE}_${N}"
fi
mkdir -p "$OUTPUT_DIR"The output directory is resolved once at the start before any workflow executes. All workflows receive $OUTPUT_DIR and store their artifacts there:
$OUTPUT_DIR/
├── rulesets.txt # Selected query packs (logged after Step 3)
├── codeql.db/ # CodeQL database (dir containing codeql-database.yml)
├── build.log # Build log
├── codeql-config.yml # Exclusion config (interpreted languages)
├── diagnostics/ # Diagnostic queries and CSVs
├── extensions/ # Data extension YAMLs
├── raw/ # Unfiltered analysis output
│ ├── results.sarif
│ └── run-all.qls | important-only.qls
└── results/ # Final results (filtered for important-only, copied for run-all)
└── results.sarifA CodeQL database is identified by the presence of a codeql-database.yml marker file inside its directory. When searching for existing databases, always collect all matches — there may be multiple databases from previous runs or for different languages.
Discovery command. find_databases.sh prints one database path per line, filtering
out the marker files a failed build leaves behind. Build the array in the same block
that selects from it — each Bash call is a fresh shell, so an array built here is empty
by the next call, and the run concludes there is no database:
# Command substitution, not `done < <(...)`: a process substitution discards the script's
# exit status, so "codeql is not on this shell's PATH" (exit 2) would arrive as an empty
# list and route to "build a new database" with three good ones sitting on disk.
if ! DB_LIST=$("{baseDir}/scripts/find_databases.sh" "${OUTPUT_DIR:-.}" .); then
echo "ERROR: database discovery failed — see the message above" >&2
exit 1
fi
FOUND_DBS=()
while IFS= read -r db; do
[ -n "$db" ] || continue
FOUND_DBS+=("$db")
done <<<"$DB_LIST"
echo "Found ${#FOUND_DBS[@]} existing database(s)"
# The metadata the selection prompt needs, collected here rather than in a block of its
# own: FOUND_DBS is gone by the next Bash call, and a loop over an array that no longer
# exists prints nothing and reports success.
for db in "${FOUND_DBS[@]}"; do
CODEQL_LANG=$(codeql resolve database --format=json -- "$db" 2>/dev/null | jq -r '.languages[0]')
CREATED=$(grep '^creationMetadata:' -A5 "$db/codeql-database.yml" 2>/dev/null | grep 'creationTime' | awk '{print $2}')
echo "$db — language: $CODEQL_LANG, created: $CREATED"
doneNever assume a database is named codeql.db — discover it by its marker file.
When multiple databases are found: use AskUserQuestion to let the user select which database to use, or to build a new one, from the language and creation time printed above. AskUserQuestion takes at most four options, so with more databases than that, offer the three most recent plus "Build a new database" and list the rest in the prompt text. Skip AskUserQuestion if the user explicitly stated which database to use or to build a new one in their prompt.
For the common case ("scan this codebase for vulnerabilities"):
# Verify CodeQL is installed. Stop here if it is not — every later command fails with
# a less informative error, and the run wastes a build cycle before saying why.
if ! command -v codeql >/dev/null 2>&1; then
echo "ERROR: codeql not found on PATH. Install it with one of:" >&2
echo " gh extension install github/gh-codeql # then: gh codeql install-stub" >&2
echo " brew install --cask codeql" >&2
echo " https://github.com/github/codeql-action/releases (codeql-bundle)" >&2
exit 1
fi
# jq parses `codeql resolve database --format=json` in the very next step. Without it
# CODEQL_LANG comes back empty and the run continues against the wrong language.
if ! command -v jq >/dev/null 2>&1; then
echo "ERROR: jq not found on PATH (brew install jq / apt install jq)" >&2
exit 1
fi
# uv runs both guard scripts and both suite generators. Check it here rather than at
# suite generation, which is after the build — otherwise a machine without uv spends
# the whole build before failing.
if ! command -v uv >/dev/null 2>&1; then
echo "ERROR: uv not found on PATH (https://docs.astral.sh/uv/getting-started/)" >&2
exit 1
fi
codeql --versionThen resolve OUTPUT_DIR using the block in Output Directory above —
it honours a user-specified directory, which a bare auto-increment does not.
Then execute the full pipeline: build database → create data extensions → run analysis using the workflows below.
These shortcuts lead to missed findings. Do not accept them:
security-extended misses entirely.security-and-quality excludes all experimental/ query paths. For run-all mode, import both security-and-quality and security-experimental. The delta is 1–52 queries depending on the language.arm64e/arm64 mismatch, not a fundamental build failure. See macos-arm64e-workaround.md.check_db_quality.py and verify_query_suite.py and report that they passed. Without them, zero findings and a database that extracted nothing are the same output.defaultSuiteFile applies hidden filters and can produce zero results. Always use an explicit suite reference.$OUTPUT_DIR. Scattering files in the working directory makes cleanup impossible and risks overwriting previous runs.This skill has three workflows. Once a workflow is selected, execute it step by step without skipping phases.
These runs are long. A database build has four fallback methods, so use the task tools to track progress. Decide which steps are worth tracking based on the run.
| Workflow | Purpose |
|---|---|
| build-database | Create CodeQL database using build methods in sequence |
| create-data-extensions | Detect or generate data extension models for project APIs |
| run-analysis | Select rulesets, execute queries, process results |
This plugin ships /static-analysis:codeql-build, which runs the build-database steps
end to end: detect the language and toolchain, walk the method ladder applying fixes from
build-fixes.md between rungs, and enforce the quality gate.
/static-analysis:codeql-build {"target": "/abs/path", "lang": "cpp"}It asks nothing. Every method failing, and a database that built but sits below the quality
threshold, come back as statuses — no-method-succeeded and built-below-threshold — for you
to act on here, because whether the remaining extractor errors are confined to code nobody
needs analysed is a judgement call the run cannot make.
Use it when the build is the long, uncertain part and you want it driven to a conclusion. Work build-database.md by hand when you want a say in which method is tried, or when a build failure needs interpreting as it happens.
If user explicitly specifies what to do (e.g., "build a database", "run analysis on ./my-db"), execute that workflow directly. Do NOT call AskUserQuestion for database selection if the user's prompt already makes their intent clear — e.g., "build a new database", "analyze the codeql database in static_analysis_codeql_2", "run a full scan from scratch".
Default pipeline for "test", "scan", "analyze", or similar: Discover existing databases using the command in Database Discovery above, then decide.
| Condition | Action |
|---|---|
| No databases found | Resolve new $OUTPUT_DIR, execute build → extensions → analysis (full pipeline) |
| One database found | Use AskUserQuestion: reuse it or build new? |
| Multiple databases found | Use AskUserQuestion, capped at four options — see Database Discovery |
| User explicitly stated intent | Skip AskUserQuestion, act on their instructions directly |
When existing databases are found and the user did not explicitly specify which to use,
present them via AskUserQuestion under the header "Existing CodeQL Databases". Label each
option with the path, language, and creation time collected above — ./static_analysis_codeql_1/codeql.db (language: python, created: 2026-02-24) — and make the last option "Build a new database".
After selection:
$OUTPUT_DIR to its parent directory (or the directory containing it), set $DB_NAME to the selected path, then proceed to extensions → analysis.$OUTPUT_DIR, execute build → extensions → analysis.If neither the database nor the workflow is clear from the prompt, offer the four
workflows via AskUserQuestion — full scan (recommended), build database, create data
extensions, run analysis — naming any databases found and the resolved $OUTPUT_DIR.
| File | Content |
|---|---|
| Scripts | |
| scripts/verify_query_suite.py | Fails a suite that resolves to zero queries. The generation scripts run it; invoke by hand only for a reused or hand-edited suite |
| scripts/check_db_quality.py | Fails a database with no analysable source. Run after every build |
| scripts/build_log.sh | log_step/run_logged helpers; source before any build step |
| scripts/find_databases.sh | Prints every database that codeql resolve database accepts, one per line. Build your array from it in the block that reads it |
| scripts/generate_suite.sh | Writes the run-all or important-only .qls and verifies it resolves to a non-zero query count |
| References — the three workflows are listed under Workflow Selection | |
| references/macos-arm64e-workaround.md | Apple Silicon build tracing workarounds |
| references/build-fixes.md | Build failure fix catalog |
| references/quality-assessment.md | Database quality metrics and improvements |
| references/extension-yaml-format.md | Data extension YAML column definitions and examples |
| references/sarif-processing.md | jq commands for SARIF output processing |
| references/diagnostic-query-templates.md | QL queries for source/sink enumeration |
| references/important-only-suite.md | Important-only suite template and generation |
| references/run-all-suite.md | Run-all suite template |
| references/ruleset-catalog.md | Available query packs by language |
| references/threat-models.md | Threat model configuration |
| references/language-details.md | Language-specific build and extraction details |
| references/performance-tuning.md | Memory, threading, and timeout configuration |
A complete CodeQL analysis run should satisfy:
$OUTPUT_DIRcodeql-database.yml marker) and {baseDir}/scripts/check_db_quality.py exited zero$OUTPUT_DIR/extensions/ or explicitly skipped with justification{baseDir}/scripts/verify_query_suite.py exited zero for it$OUTPUT_DIR/rulesets.txt$OUTPUT_DIR/raw/results.sarif$OUTPUT_DIR/results/results.sarif (filtered for important-only, copied for run-all)$OUTPUT_DIR/build.log with all commands, fixes, and quality assessments© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 34 other files (scripts, references, assets) in plugins/static-analysis/skills/codeql of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
CodeQL Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| CodeQL Security Scan this skilltrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Security Verification Gatefengshao1227/ccg-workflow | 5.9k | — | ~621 | Automated safety check: Notes | MIT | |
| Taint Instrumentation AssistantArabelaTso/Skills-4-SE | 253 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Codeqlgithub/awesome-copilot | 40k | 1 repos | ~3.4k | Automated safety check: Pass | MIT | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
fengshao1227/ccg-workflow
Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.
ArabelaTso/Skills-4-SE
Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.
github/awesome-copilot
Comprehensive guide for setting up and configuring CodeQL code scanning via GitHub Actions workflows and the CodeQL CLI.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
ArabelaTso/Skills-4-SE
Selectively instruments code to capture runtime data for debugging failures and bugs.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Picks a small, graph-based slice of source with Trailmark and hands a focused code task to a smaller or local model without exposing the whole repository.
Works with
Categories
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks. Supported languages are Python, JavaScript and TypeScript, Go, Java and Kotlin, C and C++, C#, Ruby and Swift.qls` suite must always be generated instead of passing pack names.
CodeQL Security Scan fits situations like: running a CodeQL scan on a repository to find vulnerabilities; building a CodeQL database and checking its quality; modeling project-specific sources and sinks with data extensions; choosing between a run-all scan and a high-precision scan.
Run `npx skills add trailofbits/skills --skill codeql -a claude-code`. Or copy the skill folder (plugins/static-analysis/skills/codeql in trailofbits/skills) into .claude/skills/codeql in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill codeql -a codex`. Or copy the skill folder (plugins/static-analysis/skills/codeql in trailofbits/skills) into .agents/skills/codeql in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill codeql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/codeql, .gemini/skills/codeql, .github/skills/codeql and .opencode/skills/codeql in your project.
Going by SKILL.md and its folder, CodeQL Security Scan needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (jq). Our summary lists: The CodeQL CLI; A buildable project when scanning compiled languages; Python 3 for the quality-check scripts. Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, AskUserQuestion, TaskCreate, TaskList, TaskUpdate, TaskGet.
SKILL.md names 2 domains. In commands or code: github.com and docs.astral.sh; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
CodeQL Security Scan is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.6k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 16k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with CodeQL Security Scan: Code Audit (3stoneBrother/code-audit, 893 stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars), Taint Instrumentation Assistant (ArabelaTso/Skills-4-SE, 253 stars) and Codeql (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,400 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 2, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.