Semgrep
Running Semgrep properly and writing rules that catch a pattern without drowning the repo in findings.
Installation
$ npx skills add trailofbits/skillsThe CLI's unit is the repository, so this installs everything in trailofbits/skills, not semgrep alone. It writes into whichever agent directories it finds — Claude Code, Codex, Cursor, Copilot, Windsurf, Zed.
Summary
Running Semgrep properly and writing rules that catch a pattern without drowning the repo in findings.
- Reach for it when you want a class of bug caught deterministically in CI instead of hopefully by a model.
- Sits in Secure — threat modelling, scanning, supply chain, and finding the other five copies of the bug you just found.
- Stack-agnostic — nothing in it assumes a particular language or framework.
- Published by Trail of Bits. Well regarded, but not the vendor of the thing it covers.
- Installing pulls the whole trailofbits/skills repository: this catalogue lists 12 other entries from it, and the repo may hold more.
Where it sits in delivery
SecureThreat modelling, scanning, supply chain, and finding the other five copies of the bug you just found.Everything in Secure →
The skill itself
The full text lives with its publisher and changes when they change it. Read it there rather than here — a mirrored copy of somebody else's procedure goes stale silently, and this page would have no way of telling you.
Related
More in Secure
- Security best practicesOpenAI's secure-coding guidance for agent-written code.
openai/skills - Supabase Postgres best practicesSchema, indexing and row-level security as Supabase recommends them.
supabase/agent-skills - Security & hardeningInput validation, authn/authz, secrets, dependency risk and logging — the everyday floor rather than a formal audit.
addyosmani/agent-skills - CodeQLWriting and running CodeQL queries for dataflow problems a pattern matcher cannot see.
trailofbits/skills - Secure workflow guideHardening CI: pinned actions, scoped tokens, and the injection paths in a pull_request_target trigger.
trailofbits/skills - Security threat modelProduces a threat model for a feature or system — assets, entry points, trust boundaries, mitigations.Agent
openai/skills