code-security
Security guidelines for writing secure code. Use when writing code, reviewing code for…
Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code
$ npx -y skills add semgrep/skills --skill semgrep --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/semgrepContext preview
The summary Claude sees to decide when to auto-load this skill.
Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code
name: semgrep description: "Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code quality', 'find vulnerabilities', 'static analysis', 'lint for security', 'audit this code', or want to enforce coding standards — even if they don't mention Semgrep by name. Semgrep is the right tool for pattern-based code scanning across 30+ languages."
Fast, pattern-based static analysis for security scanning and custom rule creation.
If Semgrep MCP tools are available in your environment, prefer them for scanning:
When MCP tools aren't available, fall back to the CLI commands below.
**Ideal scenarios:**
# pip (recommended)
python3 -m pip install semgrep
# Homebrew
brew install semgrep
# Docker
docker run --rm -v "${PWD}:/src" semgrep/semgrep semgrep --config auto /src---
semgrep --config auto . # Auto-detect rules
semgrep --config p/<RULESET> . # Single ruleset semgrep --config p/security-audit --config p/trailofbits . # Multiple
| Ruleset | Description | |---------|-------------| | `p/default` | General security and code quality | | `p/security-audit` | Comprehensive security rules | | `p/owasp-top-ten` | OWASP Top 10 vulnerabilities | | `p/cwe-top-25` | CWE Top 25 vulnerabilities | | `p/trailofbits` | Trail of Bits security rules | | `p/python` | Python-specific | | `p/javascript` | JavaScript-specific | | `p/golang` | Go-specific |
semgrep --config p/security-audit --sarif -o results.sarif . # SARIF semgrep --config p/security-audit --json -o results.json . # JSON
semgrep --config p/python app.py # Single file semgrep --config p/javascript src/ # Directory semgrep --config auto --include='**/test/**' . # Include tests
tests/fixtures/ **/testdata/ generated/ vendor/ node_modules/
password = get_from_vault() # nosemgrep: hardcoded-password dangerous_but_safe() # nosemgrep
---
| Approach | Use When | |----------|----------| | **Taint mode** | Data flows from untrusted source to dangerous sink (injection vulnerabilities) | | **Pattern matching** | Syntactic patterns without data flow requirements (deprecated APIs, hardcoded values) |
**Prioritize taint mode** for injection vulnerabilities. Pattern matching alone can't distinguish between `eval(user_input)` (vulnerable) and `eval("safe_literal")` (safe).
rules:
- id: hardcoded-password
languages: [python]
message: "Hardcoded password detected: $PASSWORD"
severity: ERROR
pattern: password = "$PASSWORD"rules:
- id: command-injection
languages: [python]
message: User input flows to command execution
severity: ERROR
mode: taint
pattern-sources:
- pattern: request.args.get(...)
- pattern: request.form[...]
pattern-sinks:
- pattern: os.system(...)
- pattern: subprocess.call($CMD, shell=True, ...)
pattern-sanitizers:
- pattern: shlex.quote(...)| Syntax | Description | Example | |--------|-------------|---------| | `...` | Match anything | `func(...)` | | `$VAR` | Capture metavariable | `$FUNC($INPUT)` | | `<... ...>` | Deep expression match | `<... user_input ...>` |
| Operator | Description | |----------|-------------| | `pattern` | Match exact pattern | | `patterns` | All must match (AND) | | `pattern-either` | Any matches (OR) | | `pattern-not` | Exclude matches | | `pattern-inside` | Match only inside context | | `pattern-not-inside` | Match only outside context | | `metavariable-regex` | Regex on captured value |
**Test-first is mandatory.** Create test files with annotations:
# test_rule.py
def test_vulnerable():
user_input = request.args.get("id")
# ruleid: my-rule-id
cursor.execute("SELECT * FROM users WHERE id = " + user_input)
def test_safe():
user_input = request.args.get("id")
# ok: my-rule-id
cursor.execute("SELECT * FROM users WHERE id = ?", (user_input,))Run tests:
semgrep --test --config rule.yaml test-file
| Task | Command | |------|---------| | Run tests | `semgrep --test --config rule.yaml test-file` | | Validate YAML | `semgrep --validate --config rule.yaml` | | Dump AST | `semgrep --dump-ast -l <l
A collection of skills for AI coding agents. Skills are packaged instructions and scripts that extend agent capabilities. This should be considered beta-level software; it's primarily generated by transforming open-source Semgrep rules into skill format.
Repo: semgrep/skills
Security guidelines for writing secure code. Use when writing code, reviewing code for…
Security guidelines for LLM applications based on OWASP Top 10 for LLM 2025. Use when…