Code Review & Testing · IN-DEPTH PROFILE

codeql Skill

Interprocedural security analysis with explicit database-quality and query-suite gates.

Best for

Application-security engineers scanning substantial repositories

What you get

Build a trustworthy database + Model project data flow

Main limitation

Requires CodeQL, jq, uv, a buildable target, and potentially long database construction.

First risk

Build and scan side effects. Database creation executes project build commands and may download query packs. Use an isolated checkout, review build scripts, and keep credentials out of the scan environment.

EVIDENCE FRESHNESS

Three checks, kept separate

A recent source check is not a runtime test or security audit.

Upstream sourceChecked 2026-09-23

Pinned revision · 32e34f81

Open pinned commit ↗
SkillSignal profileEditorial metadata

Updated 2026-09-23

Runtime & securityNot independently verified

Source review does not certify behavior or safety.

IN PLAIN ENGLISH

What it does—and when it fits

CodeQL is Trail of Bits' interprocedural security-analysis workflow for eight language families. It treats database extraction quality, project-specific data-flow models, explicit query suites, and zero-result investigation as required gates rather than optional cleanup.

This is aimed at Application-security engineers scanning substantial repositories. Compare the examples below with your task, then review the limitations, permissions, and risks before installing.

What you get
  • Build a trustworthy databaseTry supported build strategies and reject databases that extracted too little code.
  • Model project data flowAdd custom sources, sinks, and summaries for framework wrappers.
  • Run explicit suitesPreserve raw SARIF and verify the selected query set is non-empty.
What makes it different
  • Quality gates reduce false clean results caused by empty extraction or silently filtered queries.
  • Supports deep data-flow analysis across major compiled and interpreted languages.
Community signalNo attributed third-party rating yet

No verified review text is in the current dataset. Use the linked source for the latest discussion.

Read the source note ↗

INSTALL BY AGENT

Choose your Agent

Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.

Native

This Skill's current record explicitly names this Agent. Still inspect scripts, permissions, and external dependencies first.

Project install (recommended)
npx skills add trailofbits/skills --skill codeql --agent claude-code
Personal install
npx skills add trailofbits/skills --skill codeql --agent claude-code -g

Project install stays with this repository for team sharing. Personal install adds -g and works across repositories.

View install paths
Project path.claude/skills/codeql/
Personal path~/.claude/skills/codeql/
Official agent docs

Claude Code discovers custom Skill folders automatically at project or personal scope.

View path evidence ↗

TYPICAL WORKFLOW

A practical workflow

01

Build a trustworthy database

Try supported build strategies and reject databases that extracted too little code.

02

Model project data flow

Add custom sources, sinks, and summaries for framework wrappers.

03

Run explicit suites

Preserve raw SARIF and verify the selected query set is non-empty.

THE TRADEOFFS

Advantages and tradeoffs

Notable strengths

  1. Quality gates reduce false clean results caused by empty extraction or silently filtered queries.
  2. Supports deep data-flow analysis across major compiled and interpreted languages.

Limitations

  1. Requires CodeQL, jq, uv, a buildable target, and potentially long database construction.
  2. Static analysis findings still require manual exploitability review and can miss runtime-only behavior.

BEST FIT

Who it is for

→

Application-security engineers scanning substantial repositories

→

Teams that need reproducible SARIF evidence rather than a quick pattern scan

BEFORE YOU USE IT

Risks to review before use

High

Build and scan side effects

Database creation executes project build commands and may download query packs. Use an isolated checkout, review build scripts, and keep credentials out of the scan environment.

SECURITY

What the permission profile means

  • Run untrusted builds in a disposable sandbox with no production credentials.
  • Treat zero findings as inconclusive until extraction and suite checks pass.

Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.

COMMON QUESTIONS

codeql Skill FAQ

What is the codeql Skill?

Interprocedural security analysis with explicit database-quality and query-suite gates. CodeQL is Trail of Bits' interprocedural security-analysis workflow for eight language families. It treats database extraction quality, project-specific data-flow models, explicit query suites, and zero-result investigation as required gates rather than optional cleanup.

How do I install the codeql Skill?

Open and review the listed source, choose the project or personal path for your Agent, then verify the first run in a controlled project. Open the pinned commit and read the current SKILL.md.

Is the codeql Skill safe to use?

SkillSignal checked the source on 2026-09-23, but that is not a runtime test or security certification. Review the “Build and scan side effects” risk first and begin with the least access required.

INSIDE THE PACKAGE

Indexed files

SKILL.mdUpstream package contentSource-linked
workflows/Upstream package contentSource-linked
references/Upstream package contentSource-linked
scripts/Upstream package contentSource-linked

TAGS

codeqlsastdata-flow

Original SkillSignal editorial profile grounded in Trail of Bits commit 32e34f81, checked 2026-09-23; not independently executed or security-certified.