Semgrep
vigolium/piolium
Run Semgrep static analysis scan on a codebase using parallel subagents.
Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.
$ npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills semgrep-rule-variant-creator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator .claude/skills/semgrep-rule-variant-creator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "semgrep-rule-variant-creator" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator into .claude/skills/semgrep-rule-variant-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-variant-creator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills semgrep-rule-variant-creator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator .agents/skills/semgrep-rule-variant-creator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "semgrep-rule-variant-creator" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator into .agents/skills/semgrep-rule-variant-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-variant-creator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills semgrep-rule-variant-creator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator .cursor/skills/semgrep-rule-variant-creator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "semgrep-rule-variant-creator" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator into .cursor/skills/semgrep-rule-variant-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-variant-creator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills semgrep-rule-variant-creator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator .gemini/skills/semgrep-rule-variant-creator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "semgrep-rule-variant-creator" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator into .gemini/skills/semgrep-rule-variant-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-variant-creator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills semgrep-rule-variant-creatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator .github/skills/semgrep-rule-variant-creator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "semgrep-rule-variant-creator" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator into .github/skills/semgrep-rule-variant-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-variant-creator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills semgrep-rule-variant-creator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator .opencode/skills/semgrep-rule-variant-creator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "semgrep-rule-variant-creator" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator into .opencode/skills/semgrep-rule-variant-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "semgrep-rule-variant-creator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
semgrep-rule-variant-creatorCreates language variants of existing Semgrep rules. An agent skill from trailofbits/skills.
Semgrep Rule Variant Creator is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Creates language variants of existing Semgrep rules. Use when porting a Semgrep rule to specified target languages. Takes an existing rule and target languages as input, produces independent rule+test directories for each language.
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files and assets (for example `agents/openai.yaml`, `references/applicability-analysis.md` and `references/language-syntax-guide.md`).
It sits in Security, covering Static analysis and SAST. It works with Semgrep. The repository describes itself as: Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows. The licence is CC-BY-SA-4.0.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteEditGlobGrepWebFetchWorkflowFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
semgrepFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
semgrep.devappsec.guideFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Semgrep Rule Variant Creator loads about 3.4k tokens when it runs, and up to ~8.9k if it reads all its reference files. Until then it costs about 65 tokens; SKILL.md has 1,983 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, Write, Edit, Glob, Grep, WebFetch, WorkflowAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 1,983 words, ~3,420 tokens.
.claude/skills/semgrep-rule-variant-creator/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Port an existing Semgrep rule to other languages, one independent test-driven cycle per language.
For a new rule rather than a port, use semgrep-rule-creator — it takes a bug pattern
description where this skill takes a finished rule. That skill is also the reference for
rule-writing fundamentals: taint mode versus pattern matching, why tests come first, and
how to narrow a rule once it passes. Porting applies those same judgments in a new
language, so start there when the rule structure itself is the open question.
Porting is the same four phases repeated per language, so the orchestration ships as a dynamic workflow rather than as instructions to re-follow each run:
/semgrep-rule-variant-creator:port-rule-to-languagesPass the three required arguments, and outputDir unless the working directory is where you
want the variants. One language per entry: "Go and Java" ports a single language named after
the phrase, and the script rejects it.
referencesDir has to be a resolved absolute path. Resolve it here, because no workflow script
can expand a variable. Try in order, first hit wins — the -d is the point, since a bare ls
prints the names of the files inside the directory rather than the directory itself and leaves
nothing to copy:
ls -d -- "${CLAUDE_PLUGIN_ROOT}/skills/semgrep-rule-variant-creator/references"${CODEX_PLUGIN_ROOT}, if that variable is set insteadfind ~/.claude ~/.codex . -type d -path '*/semgrep-rule-variant-creator/skills/*/references' -print -quit 2>/dev/nullThen confirm the directory that printed holds both reference files, with ls -1 -- "<that path>".
Pass the path exactly as printed. If all three come back empty, stop and say so rather than assembling a path by hand: the script rejects a relative path and an unexpanded token, but a hand-built absolute path that happens not to exist clears every guard it has, and the run then reports every language as passed having read no guidance at all.
{
"rulePath": "<path to the rule being ported>",
"languages": ["Go", "Java"],
"referencesDir": "<the absolute path the ls above printed>",
"outputDir": "<where the variant directories should land>"
}A workflow script cannot expand {baseDir} or ${CLAUDE_PLUGIN_ROOT}, and has no filesystem
access to notice that it did not; an installed plugin does not sit in the user's project
either, so referencesDir is the only route by which the references below reach the phase
agents. The script rejects a run that omits it and one that passes a token instead of a path,
rather than porting without them, since a port made without this guidance still reports every
language as passed. outputDir is the one optional argument, defaulting to the working
directory, which is rarely what you want inside a repository.
It reads the rule once, then runs each language through the full cycle independently, and
reports which languages passed, which failed validation, which it judged not applicable, which
Semgrep cannot analyze at all, and which it stopped on — a language key it does not recognize,
two entries resolving to one directory, or a refuter that never reported back. A stop names
what to change and will happen again on a re-run, which is what separates it from an agent that
died. The rule travels as a path, not as text: every phase
reads the file, because an agent asked to repeat a rule back verbatim does not — one
HTML-escaped < and > and broke the <... ...> operator for every phase downstream.
If a run is interrupted while the session is still alive — you stopped it, or an agent hit a
terminal error — relaunch it with
Workflow({scriptPath: "…", resumeFromRunId: "<runId>", args: {…}}), passing the same
arguments again. Arguments are not saved with a run, so a resume that omits them fails the
pre-flight check above before replaying anything; with them, languages that finished replay
from cache and only the unfinished ones re-run.
Resume is same-session only, which rules it out for the interruption a long port is most likely to hit: a session limit ends the session, and runs are stored under that session's own directory, so the next session cannot reach them. A run id it cannot resolve is not an error either — the workflow starts from scratch under that id and re-runs every language at full cost, with nothing saying so. Check the id is still there before counting on a resume:
ls -d ~/.claude/projects/*/*/subagents/workflows/*/That is where runs land today rather than a documented interface, so an empty result may mean the
layout moved rather than that the run is gone. The safe reading is the same either way: if you
cannot confirm the id, or the session ended, re-invoke with the same arguments and point
outputDir somewhere fresh. The script never deletes a directory, so a language that flipped to
NOT_APPLICABLE on the second run leaves the first run's variant behind.
The script is workflows/port-rule-to-languages.js at the plugin root. It pins a
reasoning effort per phase — cheap to read the rule, highest for translation and for the
fix-until-green loop — and encodes the phase order, so a rule cannot be written before
the tests that specify it. It also keeps the two decisions that have no oracle out of any
single agent's hands: a NOT_APPLICABLE verdict goes to an independent refuter before the
language is dropped, and failed validation is retried up to three times rather than
trusting one agent to iterate until green.
Run the phases by hand when you are porting to a single language and want to stay in the loop, or when a port is already half-finished and you only need one phase. The workflow is the only delegation a port needs: one agent to read the rule, and four per language when the port goes green first try — a refuted verdict adds one, and so does each validation retry. Nothing else here is large or independent enough to be worth its own agent, so running a phase by hand means doing it yourself rather than handing it to a subagent.
Each language runs all four before its variant is finished. A language that fails validation is unfinished; a language judged not applicable produces no directory.
1. Applicability analysis — decide whether the pattern belongs in the target language
at all: does the vulnerability class exist there, does an equivalent construct exist for
each source, sink, and sanitizer, and would the ported rule detect real risk rather than
a surface syntax match. Verdict is APPLICABLE, APPLICABLE_WITH_ADAPTATION, or
NOT_APPLICABLE. NOT_APPLICABLE is the one verdict nothing downstream can contradict —
it produces no tests, no rule, and no directory — so it earns a second opinion before you
act on it. Answered separately, by running Semgrep: can Semgrep read this language at all?
Perl has no frontend and Elixir's parser is Pro-only, and in both cases the bug class is
present while the rule is ungradeable — a different finding from NOT_APPLICABLE, which
claims the bug class is absent. See
applicability-analysis.md
for worked examples of each verdict.
2. Test creation — write the test file first, in idiomatic target-language code. At
least two ruleid: cases and two ok: cases, each annotation on the line immediately
above the code it grades. Include the safe form that is the language's own idiom for
doing the thing correctly, since that is the false positive a port most often invents.
3. Rule translation — dump the AST for the target language and translate against what
it shows, because pattern shape follows AST shape rather than source resemblance. Keep the
original's detection intent and mode; change the id to <original-id>-<language>, the
languages key, and add original-rule and ported-from metadata. See
language-syntax-guide.md.
4. Validation — semgrep --test is the acceptance criterion, and it must report that
all tests passed. Missed lines mean the pattern is narrower than the vulnerability;
incorrect lines mean it is broader. The test file is the specification, so fix the rule to
satisfy it. Stopping while tests still fail leaves the language unfinished, not done. See
workflow.md for reading a test failure and for
troubleshooting when a pattern will not match or taint will not propagate.
The acceptance criterion is one specific Semgrep: the version recorded when the rule was read. Switching binaries to get a green is the failure this guards against — an agent that could not pass its Elixir tests installed the last OSS build shipping the Elixir parser and reported its genuine "All tests passed" for a port that is red here. Two other greens mean nothing: a rule Semgrep skipped still ends its run in "All tests passed", and so does a test file whose extension Semgrep does not associate with the rule's language, since it graded zero tests either way.
One directory per applicable language, holding the ported rule and its test file:
python-command-injection-go/
├── python-command-injection-go.yaml
└── python-command-injection-go.goAll tests passed means the rule and its test file agree with each other; it is not
evidence that the vulnerability class is exploitable in the target language, since the same
cycle wrote both, so treat a finished variant as a candidate for review rather than a
validated rule.
Port the rule you were handed to the languages you were asked for. Do not repair the original, widen it to catch a nearby bug class, or add a language nobody named; if the original looks wrong or an obvious target is missing, say so in one sentence and carry on with the port as asked. Every language you were given gets finished — a port is done when its tests pass, not when its files exist.
Keep prose short and spend it on the result. Before the first tool call, say in one
sentence what you are about to do. While a port runs, speak up when a verdict changes,
when the target needs a pattern shape the original does not have, or when the tests will
not go green — not on every semgrep --test iteration. Then lead with the outcome: the
first sentence says which languages passed, which failed validation, which were not
applicable, and which Semgrep cannot analyze, with the detail after it. Correct an earlier statement when the error changes
the rule, the verdict, or what to do next, then keep going; a slip that changes nothing
needs no note.
Rule and test files are the size of the problem. A test file earns its length from distinct constructs and distinct safe forms rather than from restatements of the same case, and neither file needs comments repeating what the code already says.
| Rationalization | Why It Fails | Correct Approach |
|---|---|---|
| "Pattern structure is identical" | Different ASTs across languages | Always dump AST for target language |
| "Same vulnerability, same detection" | Data flow differs between languages | Analyze target language idioms |
| "Rule doesn't need tests since original worked" | Language edge cases differ | Write NEW test cases for target |
| "Skip applicability - it obviously applies" | Some patterns are language-specific | Complete applicability analysis first |
| "I'll create all variants then test" | Errors compound, hard to debug | Finish each language before the next |
| "Library equivalent is close enough" | Surface similarity hides differences | Verify API semantics match |
| "Just translate the syntax 1:1" | Languages have different idioms | Research target language patterns |
| "Most tests pass" | A partial rule reports partial truth | All tests passed, or the port is unfinished |
| "An older semgrep still parses this language" | A green nobody can reproduce on the semgrep the rule must run under | Report the failing output and say the parser is Pro-only |
| "The class exists there, so the rule ports" | Semgrep has no Perl frontend and Elixir's is Pro-only; taint no-ops silently | Confirm semgrep can read the language before porting |
| "Semgrep said all tests passed" | It says that over zero graded tests, for a rule it skipped or a file it never matched | Check the rule ran and the test file's extension matches |
| Task | Command |
|---|---|
| Run tests | semgrep --test --config rule.yaml test-file |
| Validate YAML | semgrep --validate --config rule.yaml |
| Dump AST | semgrep --dump-ast -l <lang> <file> |
| Debug taint flow | semgrep --dataflow-traces -f rule.yaml file |
© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references, assets) in plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in trailofbits/skills, which our catalogue first saw on October 7, 2026.
Semgrep Rule Variant Creator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Semgrep Rule Variant Creator this skilltrailofbits/skills | 7.4k | 5 repos | ~3.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Semgrepvigolium/piolium | 140 | 1 repos | ~2.4k | Automated safety check: Notes | MIT | |
| Sast SemgrepAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~2.4k | Automated safety check: Pass | Custom licence | |
| Semgrepwaybarrios/opencode-power-pack | 533 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Semgrepsemgrep/skills | 322 | — | ~2.3k | Automated safety check: Pass | Custom licence | |
| Code Auditzhaoxuya520/reverse-skill | 40k | 2 repos | ~374 | Automated safety check: Warn | MIT |
vigolium/piolium
Run Semgrep static analysis scan on a codebase using parallel subagents.
AgentSecOps/SecOpsAgentKit
Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.
waybarrios/opencode-power-pack
Run Semgrep static analysis across a codebase, optionally using Semgrep Pro for cross-file taint analysis.
semgrep/skills
Run Semgrep static analysis scans and create custom detection rules.
zhaoxuya520/reverse-skill
A skill your agent uses for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
davila7/claude-code-templates
Static Application Security Testing (SAST) tool setup, configuration, and custom rule creation for comprehensive security scanning across multiple programming languages.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
Works with
Categories
Creates language variants of existing Semgrep rules. An agent skill from trailofbits/skills. Semgrep Rule Variant Creator is an agent skill from trailofbits/skills, published by the product's own GitHub organization. Creates language variants of existing Semgrep rules.
Semgrep Rule Variant Creator fits situations like: porting a Semgrep rule to specified target languages; tasks that involve Static analysis and SAST.
Run `npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a claude-code`. Or copy the skill folder (plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator in trailofbits/skills) into .claude/skills/semgrep-rule-variant-creator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a codex`. Or copy the skill folder (plugins/semgrep-rule-variant-creator/skills/semgrep-rule-variant-creator in trailofbits/skills) into .agents/skills/semgrep-rule-variant-creator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill semgrep-rule-variant-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/semgrep-rule-variant-creator, .gemini/skills/semgrep-rule-variant-creator, .github/skills/semgrep-rule-variant-creator and .opencode/skills/semgrep-rule-variant-creator in your project.
Going by SKILL.md and its folder, Semgrep Rule Variant Creator needs the command-line tools its instructions call (semgrep). Its frontmatter pre-approves these tools: Bash, Read, Write, Edit, Glob, Grep, WebFetch, Workflow.
SKILL.md names 2 domains. As links in the text: semgrep.dev and appsec.guide. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Semgrep Rule Variant Creator is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Semgrep Rule Variant Creator: Semgrep (vigolium/piolium, 140 stars), Sast Semgrep (AgentSecOps/SecOpsAgentKit, 220 stars), Semgrep (waybarrios/opencode-power-pack, 533 stars) and Semgrep (semgrep/skills, 322 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,440 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.