IN PLAIN ENGLISH
What it does—and when it fits
CodeQL is Trail of Bits' interprocedural security-analysis workflow for eight language families. It treats database extraction quality, project-specific data-flow models, explicit query suites, and zero-result investigation as required gates rather than optional cleanup.
This is aimed at Application-security engineers scanning substantial repositories. Compare the examples below with your task, then review the limitations, permissions, and risks before installing.
- Build a trustworthy databaseTry supported build strategies and reject databases that extracted too little code.
- Model project data flowAdd custom sources, sinks, and summaries for framework wrappers.
- Run explicit suitesPreserve raw SARIF and verify the selected query set is non-empty.
- Quality gates reduce false clean results caused by empty extraction or silently filtered queries.
- Supports deep data-flow analysis across major compiled and interpreted languages.
No verified review text is in the current dataset. Use the linked source for the latest discussion.
Read the source note ↗INSTALL BY AGENT
Choose your Agent
Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.
npx skills add trailofbits/skills --skill codeql --agent claude-codenpx skills add trailofbits/skills --skill codeql --agent claude-code -gProject install stays with this repository for team sharing. Personal install adds -g and works across repositories.
View install paths
.claude/skills/codeql/~/.claude/skills/codeql/Claude Code discovers custom Skill folders automatically at project or personal scope.
View path evidence ↗TYPICAL WORKFLOW
A practical workflow
Build a trustworthy database
Try supported build strategies and reject databases that extracted too little code.
Model project data flow
Add custom sources, sinks, and summaries for framework wrappers.
Run explicit suites
Preserve raw SARIF and verify the selected query set is non-empty.
THE TRADEOFFS
Advantages and tradeoffs
Notable strengths
- Quality gates reduce false clean results caused by empty extraction or silently filtered queries.
- Supports deep data-flow analysis across major compiled and interpreted languages.
Limitations
- Requires CodeQL, jq, uv, a buildable target, and potentially long database construction.
- Static analysis findings still require manual exploitability review and can miss runtime-only behavior.
BEST FIT
Who it is for
Application-security engineers scanning substantial repositories
Teams that need reproducible SARIF evidence rather than a quick pattern scan
BEFORE YOU USE IT
Risks to review before use
Build and scan side effects
Database creation executes project build commands and may download query packs. Use an isolated checkout, review build scripts, and keep credentials out of the scan environment.
SECURITY
What the permission profile means
- Run untrusted builds in a disposable sandbox with no production credentials.
- Treat zero findings as inconclusive until extraction and suite checks pass.
Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.
COMMON QUESTIONS
codeql Skill FAQ
What is the codeql Skill?
Interprocedural security analysis with explicit database-quality and query-suite gates. CodeQL is Trail of Bits' interprocedural security-analysis workflow for eight language families. It treats database extraction quality, project-specific data-flow models, explicit query suites, and zero-result investigation as required gates rather than optional cleanup.
How do I install the codeql Skill?
Open and review the listed source, choose the project or personal path for your Agent, then verify the first run in a controlled project. Open the pinned commit and read the current SKILL.md.
Is the codeql Skill safe to use?
SkillSignal checked the source on 2026-09-23, but that is not a runtime test or security certification. Review the “Build and scan side effects” risk first and begin with the least access required.
INSIDE THE PACKAGE
Indexed files
TAGS
Original SkillSignal editorial profile grounded in Trail of Bits commit 32e34f81, checked 2026-09-23; not independently executed or security-certified.