Semgrep Security Scan
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.
$ npx skills add vigolium/piolium --skill audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vigolium/piolium audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vigolium/piolium.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit .claude/skills/audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit" agent skill from https://github.com/vigolium/piolium/tree/main/skills/audit into .claude/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vigolium/piolium/tree/main/skills/auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vigolium/piolium --skill audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vigolium/piolium audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vigolium/piolium.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/audit .agents/skills/audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit" agent skill from https://github.com/vigolium/piolium/tree/main/skills/audit into .agents/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vigolium/piolium --skill audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vigolium/piolium audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vigolium/piolium.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/audit .cursor/skills/audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit" agent skill from https://github.com/vigolium/piolium/tree/main/skills/audit into .cursor/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vigolium/piolium.git --path skills/audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vigolium/piolium --skill audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vigolium/piolium audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vigolium/piolium.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/audit .gemini/skills/audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit" agent skill from https://github.com/vigolium/piolium/tree/main/skills/audit into .gemini/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vigolium/piolium auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vigolium/piolium --skill audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vigolium/piolium.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/audit .github/skills/audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit" agent skill from https://github.com/vigolium/piolium/tree/main/skills/audit into .github/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vigolium/piolium --skill audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vigolium/piolium audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vigolium/piolium.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/audit .opencode/skills/audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit" agent skill from https://github.com/vigolium/piolium/tree/main/skills/audit into .opencode/skills/audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
auditA skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.
Audit is an agent skill from vigolium/piolium. Use when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. Defines a 10-phase security audit methodology combining advisory intelligence, patch bypass analysis, knowledge base construction, baseline and custom SAST, spec gap analysis, deep bug hunting, false positive elimination, variant analysis, and final reporting with realistic PoC construction. Triggers on "audit this repo", "run a full security…
Its SKILL.md is about 8.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts, reference files and assets (for example `hooks/scripts/validate_phase_output.py`, `references/adversarial-review.md` and `references/architecture-aware-sast.md`).
It sits in Security, covering Security review, Static analysis and SAST and Knowledge bases. The repository describes itself as: A Pi-native extension for thorough, agentic security audits. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9ffdcac. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python and Shell), which the agent can run.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Audit loads about 8.7k tokens when it runs, and up to ~60k if it reads all its reference files. Until then it costs about 178 tokens; SKILL.md has 3,829 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from vigolium/piolium at commit 9ffdcac, republished under its MIT licence (© vigolium). 3,829 words, ~8,743 tokens.
.claude/skills/audit/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.10-phase security audit methodology for arbitrary source code repositories. Each phase defines what to analyze and what to produce. Orchestration (branching, state management, agent dispatch) is handled by the plugin commands.
Before executing any phase, apply these rules to avoid redundant work:
piolium/attack-surface/knowledge-base-report.md from the previous
run is the starting knowledge base. Do not regenerate it from scratch. Load it, diff the codebase
against the commit field of the last completed entry in piolium/audit-state.json, and update
only the sections whose source inputs changed. Mark unchanged sections with
[reused from <short-sha>]. Documentation-only changes require no re-audit; changes to auth,
core business logic, or attack-surface components invalidate the Static Analysis Summary and
Phase 10 Addendum (## Phase 10 Addendum, written by the Review Chambers) sections at minimum.piolium/findings-draft/ already contains draft files,
resume from the existing drafts rather than starting fresh.piolium/audit-state.json is append-only. Before starting a new audit,
append a new entry to the audits array with status: "in_progress". After each phase
completes or fails, update that entry's phases map in-place. Never overwrite or remove
earlier entries — they are the permanent audit history. See references/report-templates.md
for the full schema.Before executing Phase 1, perform the following environment checks:
Security folder dirtiness check: Run git status piolium/ to determine if piolium/ has
uncommitted changes or untracked files.
Concurrent agent detection: Check whether another agent is actively writing to the source
code tree. Indicators include uncommitted modifications outside piolium/ in the working tree
(e.g., staged edits, new untracked source files) or the presence of .claude/ task state that
suggests a live session.
Worktree isolation: If BOTH conditions hold — piolium/ is dirty AND another agent is
actively modifying source code — create an isolated git worktree pinned to the current HEAD so
the audit analyses a stable snapshot and writes to a conflict-free path:
AUDIT_WT="../audit-$(basename "$PWD")-$(date +%s)"
git worktree add --detach "$AUDIT_WT" HEADRun the entire audit from inside $AUDIT_WT. All piolium/ output is written to the
worktree copy. At the end of Phase 15, merge the retained artifacts back and tear down the
worktree:
cp -r "$AUDIT_WT/piolium/attack-surface/" piolium/
cp -r "$AUDIT_WT/piolium/final-audit-report.md" piolium/
cp -r "$AUDIT_WT/piolium/findings/" piolium/
git worktree remove --force "$AUDIT_WT"If only one condition holds (security is dirty but no concurrent agent, or a concurrent agent exists but security is clean), proceed without a worktree — no isolation needed.
flowchart TD
Start["Audit Request"] --> Setup["Setup + reuse check"]
Setup --> P1["1. Intelligence Gathering"]
P1 --> P2["2. Patch Bypass Analysis (per-patch parallel)"]
P2 --> P3["3. Knowledge Base"]
P3 --> P4["4. Static Analysis (incl. inline Enrichment)"]
P3 --> P6["6. Spec Gap Analysis"]
P4 --> P7["7. Deep Bug Hunting"]
P6 --> P7
P7 --> P8["8. P11-LITE: FP Check + Cold Verification (CRITICAL/HIGH only)"]
P8 --> P9["9. Variant Analysis"]
P9 --> P10["10. Exploitation & Final Reporting"]Use the advisory-hunter workflow to collect:
piolium/attack-surface/sbom.jsonsecurity_relevant subset of that inventory, with runtime context noted for each one. Use the supply-chain-risk-auditor skill to systematically assess the flagged components' risks.Treat dependency findings as hypotheses until the audit proves the affected runtime path is reachable.
Write all findings to the ## Advisory Intelligence and ## Component Inventory sections of piolium/attack-surface/knowledge-base-report.md, and the full inventory to piolium/attack-surface/sbom.json.
For each advisory patch:
Write all findings to the ## Bypass Analysis section of piolium/attack-surface/knowledge-base-report.md.
Build the project model from source:
security-threat-model skill to formally document the threat model.last30days, wooyun-legacy, MCP tools, and web search. See
references/domain-attack-playbooks.md for the research action sequence and per-domain templates.Before completing Phase 3, add a ## Phase 4 CodeQL Extraction Targets section to the KB draft.
For each high-risk DFD slice, record the expected CodeQL source type (RemoteFlowSource,
LocalUserInput, EnvironmentVariable) and the expected sink kind (sql-execution, command-execution,
file-access, http-request, code-execution, deserialization). This is the data contract that tells
Phase 4's structural extractor which per-slice call graph queries to run. Leave the section blank
if no DFD slices were identified — structural extraction will run generic enumeration only.
Produce piolium/attack-surface/knowledge-base-report.md with all Phase 3 sections populated. This is the
single knowledge base file for the entire audit. The threat model and attack surface content
live inside it as sections — no separate files.
The Phase 3 threat model is mandatory input for all later phases.
CRITICAL ENFORCEMENT: You MUST physically execute the SAST tools. Do not hallucinate results or skip execution. You must ensure codeql successfully runs and that semgrep uses the Pro engine (--pro) exclusively. Standard Semgrep is only permitted as a fallback when Pro is unavailable due to an authentication or licensing failure; document the fallback and its reason in the report.
Before running any security suite, build the CodeQL database and store it at
piolium/codeql-artifacts/db/ (not a transient path). Do not delete it after this sub-step.
Follow the ## Structural Extraction Workflow in references/architecture-aware-sast.md to produce:
piolium/codeql-artifacts/entry-points.jsonpiolium/codeql-artifacts/sinks.jsonpiolium/codeql-artifacts/call-graph-slices.jsonpiolium/codeql-artifacts/flow-paths-raw.sarif (git-ignored, retained until Phase 12)piolium/codeql-artifacts/flow-paths-all-severities.mdpiolium/attack-surface/knowledge-base-report.mdPopulate the ## CodeQL Structural Analysis section of piolium/attack-surface/knowledge-base-report.md
after extraction completes.
Baseline requirements:
codeql skill to run built-in security suites against the database built in 4.1.semgrep skill with --pro enforced for all passes (baseline, language, framework, and custom). Fall back to standard Semgrep only if the Pro engine fails with an authentication or licensing error; document the fallback reason in the ## Static Analysis Summary section of piolium/attack-surface/knowledge-base-report.md.agentic-actions-auditor when .github/workflows/ exists; write results to the ## GitHub Actions Audit section of piolium/attack-surface/knowledge-base-report.md.Custom Architecture Generalization (Dynamic Rules):
piolium/codeql-queries/ and piolium/semgrep-rules/.## Static Analysis Summary section of piolium/attack-surface/knowledge-base-report.md.Operational rules:
sarif-parsing if needed.After SAST runs complete and before deep bug hunting, classify each candidate finding as one of:
For every candidate, answer:
piolium/codeql-artifacts/call-graph-slices.json for the finding's source-to-sink slice.
If reachable: true, that strengthens the finding. If reachable: false and both source and
sink appear in the enumeration files, that is evidence to downgrade — document the discrepancy.
For findings without a pre-computed slice, run an on-demand query against
piolium/codeql-artifacts/db/.Downgrade or exclude by default when the issue is only:
Write enrichment verdicts to the ## SAST Enrichment section of piolium/attack-surface/knowledge-base-report.md. In the
## CodeQL Structural Analysis section, note any entry points from entry-points.json not
present in the Phase 3 DFD slices, and any sinks from sinks.json mapping to unmodeled
high-risk flows.
Delete Semgrep cache, semgrep-res/, and codeql-res/. Do not delete
piolium/codeql-artifacts/db/ — it is retained for Phases 7 and 9. Full database deletion
happens at the end of Phase 12.
If the repo implements specs or RFCs:
## Domain Attack Research section of piolium/attack-surface/knowledge-base-report.md first —
it contains pre-computed domain attack patterns from Phase 3 that directly inform which spec
gaps to prioritize.spec-to-code-compliance.Write all findings to the ## Spec Gap Analysis section of piolium/attack-surface/knowledge-base-report.md.
If no specs or RFCs were identified in Phase 3, mark the section "None identified" and skip.
Phase 10 uses a Review Chamber multi-agent debate system. Instead of a single deep-auditor agent, four specialized roles collaborate through structured argumentation to produce findings with higher creativity and lower false-positive rates.
After Phase 4 (SAST + inline enrichment) and Phase 9 (spec gap) complete:
## High-Risk DFD Slices and ## High-Risk CFD Slices from piolium/attack-surface/knowledge-base-report.mdCreate piolium/chamber-workspace/ and piolium/attack-pattern-registry.json. The orchestrator
seeds the registry as {"patterns": []} before this phase — append to it, and do not delete it
even when no chamber confirms a new pattern. Phase 12 reads it.
Each chamber spawns four agents that communicate through an append-only debate transcript at
piolium/chamber-workspace/<chamber-id>/debate.md:
Attack Ideator (Red Team Creative): generates 3-7 attack hypotheses per cluster by cycling
through 8 creative modes — vulnerability chaining, business logic abuse, race conditions/TOCTOU,
second-order/stored attacks, trust boundary confusion, parser/protocol differentials, state
machine attacks, and supply chain interaction. See references/creative-attack-modes.md.
Does NOT trace code or issue verdicts.
Code Tracer (Technical Analyst): takes each hypothesis and traces it through actual code.
Uses Method 2.6 from references/deep-analysis.md (call-graph slices, entry-points.json,
sinks.json, flow-paths-all-severities.md, on-demand QL queries). Produces reachability verdicts
(REACHABLE / UNREACHABLE / PARTIAL) with file:line evidence chains.
Does NOT generate hypotheses or issue final verdicts.
Devil's Advocate (Challenger): challenges EVERY finding. Searches 5 protection layers
(language, framework, middleware, application, documentation). Checks all 8 Claude-Specific FP
patterns from references/triage-and-prereqs.md. Must argue against even obvious vulnerabilities —
inability to construct credible defense is itself strong evidence.
Does NOT generate hypotheses or issue verdicts.
Chamber Synthesizer (Coordinator + Judge): orchestrates debate rounds, reads all arguments,
resolves disputes, assigns calibrated severity per references/triage-and-prereqs.md, and writes
finding drafts. Only role that writes to piolium/findings-draft/. Manages the attack pattern
registry. May request up to 2 follow-up investigation rounds per hypothesis.
Optional 5th role — Variant Scout: monitors debate for confirmed patterns and concurrently searches for structural variants in sibling components, front-loading Phase 12 work.
Each chamber proceeds through structured rounds:
Round 1 (Ideation): Ideator generates 3-7 hypotheses
Round 2 (Tracing): Tracer traces each hypothesis through code
Round 3 (Challenge): Advocate writes defense brief per hypothesis
Round 4 (Synthesis): Synthesizer evaluates arguments, issues verdicts
Round 5-6 (Optional): Focused re-investigation on unresolved hypothesesConvergence criteria — debate ends for a hypothesis when:
Limits: max 7 hypotheses per batch, max 3 rounds per hypothesis, max 3 concurrent chambers.
See references/chamber-protocol.md for complete debate format, transcript template, and
convergence rules.
Before writing any finding draft, the Synthesizer applies this 5-point check:
If any check fails, drop the finding. If ambiguous, add Pre-FP-Flag: check-N-ambiguous to the
draft for Phase 11 priority.
Chambers share a pattern registry at piolium/attack-pattern-registry.json. When a
Synthesizer confirms a finding, it adds the root cause pattern with detection signatures
(CodeQL, grep, Semgrep). Other chambers read the registry before new ideation rounds,
enabling cross-domain pattern discovery.
piolium/findings-draft/p7-<NNN>-<slug>.md (Medium+ only, Low dropped)piolium/chamber-workspace/<chamber-id>/debate.md (audit artifact)piolium/chamber-workspace/<chamber-id>/variant-candidates/ (for Phase 12)piolium/attack-pattern-registry.json (for Phases 8, 9)After all chambers close, append a ## Phase 10 Addendum section to
piolium/attack-surface/knowledge-base-report.md containing: newly discovered attack surfaces, revised trust
boundary assumptions, and additional DFD/CFD paths found during chamber debates. Forward-append
only — Phase 3 content preserved for auditability.
Chambers may delegate to specialized skills for scope NOT already covered by Phase 3 domain attack research:
insecure-defaults — fail-open configurations, weak auth defaultssharp-edges — API design issues, dangerous configurationswooyun-legacy — web vulnerability techniqueszeroize-audit — C/C++/Rust secret handlingContext: Read references/chamber-protocol.md, references/creative-attack-modes.md,
references/deep-analysis.md, and references/triage-and-prereqs.md.
Phase 11 is reduced from full adversarial review to P11-LITE because the Devil's Advocate already challenged every finding during the Phase 10 chamber debate.
Apply fp-check to all candidate findings with Verdict: VALID from Phase 10.
Retain only findings exploitable within the project's actual threat model.
SECURITY.md to understand what maintainers consider a vulnerability vs. accepted risk.references/triage-and-prereqs.md.Pre-FP-Flag annotations from the chamber debate.CRITICAL: Verify intended behavior vs. bug. Cross-reference framework documentation, user guides, and inline comments to prove a finding is an unintended flaw, not a documented feature.
CRITICAL: Drop theoretical/unexploitable bugs — static IVs without key access, timing side-channels without practical exploit, by-design behavior, informational findings, defense-in-depth-only changes, correctness issues without trust boundary crossing, dependency alerts without reachable runtime path.
CRITICAL: "Best practice" is not a valid FP verdict. A missing security control IS a vulnerability if the threat model shows attacker-controlled input reaches a sensitive sink without adequate protection.
Use verdicts: VALID, FALSE POSITIVE, BY DESIGN, OUT OF SCOPE,
DROP (low severity).
Write each verdict back into the corresponding piolium/findings-draft/ file immediately.
Medium findings skip Stage 2 — already challenged by the Devil's Advocate during the chamber debate. This reduces Phase 11 cost by ~60%.
For each CRITICAL and HIGH finding with Verdict: VALID after Stage 1, spawn a fresh agent
per finding. The task description contains only the finding draft file path — no debate transcript,
no context, no Phase 10 reasoning.
Each cold verifier independently:
references/real-env-validation.mdCold verifiers write verdicts back into finding drafts and produce
piolium/adversarial-reviews/<slug>-review.md. DISPROVED findings have their Verdict:
updated to FALSE POSITIVE (adversarial). Lower severity wins when challenged.
See references/adversarial-review.md for the cold verification protocol (scoped to
CRITICAL/HIGH only).
For each confirmed finding rated Medium or higher, search for variants using the same flow shape, not just the same syntax.
Primary input: piolium/attack-pattern-registry.json — the structured registry of confirmed
patterns from Phase 10 Review Chambers. Each pattern includes detection_signature fields with
ready-made CodeQL, grep, and Semgrep queries for automated variant hunting, plus
untested_candidates identifying specific code locations to investigate.
An empty patterns array is a normal Phase 10 outcome — chambers that confirm no new root-cause
pattern write nothing. Fall back to hunting variants from the finding drafts alone. Never search
outside the audit directory for the registry.
Also read:
## Phase 10 Addendum in piolium/attack-surface/knowledge-base-report.md for attack surfaces discovered
during chamber debatespiolium/chamber-workspace/*/variant-candidates/ for pre-identified candidates from Variant
Scoutspiolium/codeql-artifacts/entry-points.json and sinks.json for structurally similar
entry/sink combinationsUse:
variant-analysis skillpiolium/codeql-artifacts/db/ for AST-level structural matchesIncremental persistence: Write each confirmed variant immediately to piolium/findings-draft/p9-<NNN>-<slug>.md using the finding draft template. Only create drafts for variants rated Medium or higher.
Database cleanup: After all variant queries complete, delete the CodeQL database:
rm -rf piolium/codeql-artifacts/db/The extracted JSON and markdown summaries in piolium/codeql-artifacts/ are retained as
permanent audit record.
Draft promotion: Before generating individual reports, collect all files in piolium/findings-draft/ with verdict VALID. Assign new severity-prefixed IDs (C1, H1, M1) now — discard any F-NNN or other ad-hoc IDs used during drafting. For each Critical/High/Medium finding, create the corresponding piolium/findings/<ID>-<slug>/ directory and copy the draft as the basis for the final vuln-report output. Low severity findings are dropped entirely — they do not appear in individual reports, the summary table, or any other output. Never carry forward F-NNN draft IDs into final reports.
For each critical, high, and medium bug confirmed:
references/real-env-validation.md for provisioning procedures.vuln-report skill for each Critical, High, and Medium finding. Follow its naming convention: number bugs with severity prefixes C1, H1, M1, incrementing the counter per severity tier. Prefix both the report title and the folder name with this ID.piolium/findings/<Cn|Hn|Mn>-<bug-name>/.piolium/findings/<ID>-<slug>/evidence/. Annotate PoC-Status: executed | theoretical | blocked in the finding. A theoretical or blocked status requires a PoC-Block-Reason: line.Consolidated Pentest-Style Report:
7. Generate a final piolium/final-audit-report.md that synthesizes the entire audit:
After the consolidated report is written, delete all working artifacts:
rm -rf piolium/findings-draft/
rm -rf piolium/adversarial-reviews/
rm -rf piolium/real-env-evidence/
rm -rf piolium/codeql-artifacts/
rm -rf piolium/codeql-queries/
rm -rf piolium/semgrep-rules/
rm -f piolium/audit-state.json
rm -f piolium/merged-results.sarif
rm -f piolium/bounty-scope.mdOnly four paths are retained: piolium/attack-surface/knowledge-base-report.md, piolium/attack-surface/sbom.json, piolium/final-audit-report.md, and piolium/findings/.
All audit output lives in <repo-root>/piolium/. Four paths are retained after the audit completes. Everything else is cleaned up at the end of Phase 15.
Retained after audit:
| Path | Phases that write to it |
|---|---|
piolium/attack-surface/knowledge-base-report.md | 1 (advisory), 2 (bypass), 3 (arch/threat model/attack surface/domain attack research), 4 (SAST summary + CodeQL structural), 5 (enrichment), 6 (spec gaps), 7 (addendum) |
piolium/attack-surface/sbom.json | 1 (general component inventory / SBOM) |
piolium/final-audit-report.md | 10 |
piolium/findings/<Cn|Hn|Mn>-<bug-name>/ | 10 (promoted from draft) |
Working artifacts (deleted at end of Phase 15):
| Path | Phase |
|---|---|
piolium/codeql-artifacts/ | 4-9 |
piolium/codeql-queries/ | 4, 9 |
piolium/semgrep-rules/ | 4, 9 |
piolium/chamber-workspace/<chamber-id>/debate.md | 7 (debate) |
piolium/chamber-workspace/<chamber-id>/variant-candidates/ | 7 (scout) |
piolium/attack-pattern-registry.json | 7, 9 (intel) |
piolium/findings-draft/<phase>-<NNN>-<slug>.md | 7-9 (incremental) |
piolium/adversarial-reviews/<slug>-review.md | 8 Stage 2 (C/H) |
piolium/real-env-evidence/<finding-slug>/ | 8 Stage 2 |
piolium/audit-state.json | all phases |
piolium/bounty-scope.md | pre-audit (input) |
semgrep-res/, and codeql-res/ after Phase 4. Retain
piolium/codeql-artifacts/db/ through Phase 12 for on-demand reachability and variant queries.
Delete the database at the end of Phase 12. Delete all remaining working artifacts at the end of
Phase 15 — only piolium/attack-surface/knowledge-base-report.md, piolium/attack-surface/sbom.json,
piolium/final-audit-report.md, and piolium/findings/ are retained.Run consistency checks after Phase 15 completes, or on demand, to detect state drift and report inconsistencies:
piolium/final-audit-report.md must correspond to a directory in piolium/findings/.piolium/attack-surface/knowledge-base-report.md must contain all phase-labelled sections. Sections labelled Phase 1-6 must be non-empty. Phase 10 Addendum must exist after Phase 10.piolium/ but not referenced by the KB or final-audit-report.md are flagged as orphans.<sha>]".piolium/findings-draft/ should contain no files with verdict VALID that are missing a corresponding directory in piolium/findings/.piolium/codeql-artifacts/entry-points.json, sinks.json, call-graph-slices.json, and flow-paths-all-severities.md must all exist.piolium/findings/ must contain no directory with an L-prefixed ID, and piolium/final-audit-report.md must contain no LOW entry in the findings table.piolium/ must not contain advisory-hunter-report.md, bypass-analysis-report.md, threat-model-report.md, attack-surface-report.md, static-analysis-report.md, actions-audit-report.md, spec-gaps-report.md, or final-findings-report.md. These have been consolidated into knowledge-base-report.md.After the audit, use:
prompt-optimizer to tighten weak promptsprompt-builder to refine targeted audit promptsskill-creator to update recurring audit workflows when new patterns emerge© vigolium, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 15 other files (scripts, references, assets) in skills/audit of vigolium/piolium.
Open the folder on GitHubat commit 9ffdcac
Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Audit this skillvigolium/piolium | 140 | — | ~8.7k | Automated safety check: Pass | MIT | |
| Semgrep Security Scantrailofbits/skills | 7.4k | — | ~3.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| CodeCrucible Security Scansblock/codecrucible | 117 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Codeqlwaybarrios/opencode-power-pack | 533 | 2 repos | ~3.7k | Automated safety check: Pass | MIT | |
| Agentic GitHub Actions Auditortrailofbits/skills | 7.4k | 6 repos | ~5.4k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Sast Analysisutkusen/sast-skills | 1.3k | — | ~1k | Automated safety check: Pass | MIT |
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
block/codecrucible
Runs the codecrucible CLI for LLM-backed security scans of a repository, checks scope and cost first with a dry run, and reads the SARIF results.
waybarrios/opencode-power-pack
Run CodeQL database creation and security queries, add data-extension models, or process CodeQL SARIF.
trailofbits/skills
Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.
utkusen/sast-skills
Perform codebase analysis and architecture mapping as the first phase of a security assessment.
PlamenTSV/plamen
Prepare Solidity projects for a security audit — test coverage, test quality, NatSpec docs, code hygiene, dependency health, best-practice enforcement, deployment readiness, and project…
vigolium/piolium
Run Semgrep static analysis scan on a codebase using parallel subagents.
vigolium/piolium
Verifies code implements exactly what documentation specifies for blockchain audits.
vigolium/piolium
A skill your agent uses to review code. An agent skill from vigolium/piolium.
Categories
A skill your agent uses when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures. Audit is an agent skill from vigolium/piolium. Use when running a full security audit of an arbitrary source code repository, especially large, complex, multi-component, distributed, or non-standard architectures.
Audit fits situations like: running a full security audit of an arbitrary source code repository; especially large; multi-component; non-standard architectures.
Run `npx skills add vigolium/piolium --skill audit -a claude-code`. Or copy the skill folder (skills/audit in vigolium/piolium) into .claude/skills/audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vigolium/piolium --skill audit -a codex`. Or copy the skill folder (skills/audit in vigolium/piolium) into .agents/skills/audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vigolium/piolium --skill audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit, .gemini/skills/audit, .github/skills/audit and .opencode/skills/audit in your project.
Going by SKILL.md and its folder, Audit needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: Python 3; A Bash shell.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.7k tokens (SKILL.md is roughly 35k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 52k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Audit: Semgrep Security Scan (trailofbits/skills, 7.4k stars), CodeCrucible Security Scans (block/codecrucible, 117 stars), Codeql (waybarrios/opencode-power-pack, 533 stars) and Agentic GitHub Actions Auditor (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vigolium (a GitHub organization) maintains it in vigolium/piolium, which has 140 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 20, 2026.
Source: vigolium/piolium on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.