Code Review & Testing · IN-DEPTH PROFILE

semgrep Skill

Approval-gated Semgrep security scans with telemetry disabled and auditable SARIF output.

Best for

Security teams needing a controlled first-pass code scan

What you get

Plan the scan + Approve exact rulesets

Main limitation

Requires Semgrep and network access for registry or third-party rules; Pro-only cross-file analysis may be unavailable.

First risk

Third-party rules and source exposure. The workflow may clone external rules and optional engines can communicate with services. Review the plan, keep metrics off, and do not scan sensitive code with unapproved network access.

EVIDENCE FRESHNESS

Three checks, kept separate

A recent source check is not a runtime test or security audit.

Upstream sourceChecked 2026-09-23

Pinned revision · 32e34f81

Open pinned commit ↗
SkillSignal profileEditorial metadata

Updated 2026-09-23

Runtime & securityNot independently verified

Source review does not certify behavior or safety.

IN PLAIN ENGLISH

What it does—and when it fits

Semgrep is Trail of Bits' approval-gated security scan workflow. It detects languages, proposes exact official and third-party rulesets, disables telemetry, runs approved scans in batches, and merges auditable results into SARIF while recording failures and skipped coverage.

This is aimed at Security teams needing a controlled first-pass code scan. Compare the examples below with your task, then review the limitations, permissions, and risks before installing.

What you get
  • Plan the scanDetect languages and choose full or important-only coverage.
  • Approve exact rulesetsShow target, engine, mode, and every ruleset before execution.
  • Merge auditable outputPreserve raw scans and report failed, skipped, or empty coverage.
What makes it different
  • Telemetry-off commands and an explicit plan reduce accidental source disclosure.
  • Combines fast multi-language rules with optional cross-file Pro analysis.
Community signalNo attributed third-party rating yet

No verified review text is in the current dataset. Use the linked source for the latest discussion.

Read the source note ↗

INSTALL BY AGENT

Choose your Agent

Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.

Native

This Skill's current record explicitly names this Agent. Still inspect scripts, permissions, and external dependencies first.

Project install (recommended)
npx skills add trailofbits/skills --skill semgrep --agent claude-code
Personal install
npx skills add trailofbits/skills --skill semgrep --agent claude-code -g

Project install stays with this repository for team sharing. Personal install adds -g and works across repositories.

View install paths
Project path.claude/skills/semgrep/
Personal path~/.claude/skills/semgrep/
Official agent docs

Claude Code discovers custom Skill folders automatically at project or personal scope.

View path evidence ↗

TYPICAL WORKFLOW

A practical workflow

01

Plan the scan

Detect languages and choose full or important-only coverage.

02

Approve exact rulesets

Show target, engine, mode, and every ruleset before execution.

03

Merge auditable output

Preserve raw scans and report failed, skipped, or empty coverage.

THE TRADEOFFS

Advantages and tradeoffs

Notable strengths

  1. Telemetry-off commands and an explicit plan reduce accidental source disclosure.
  2. Combines fast multi-language rules with optional cross-file Pro analysis.

Limitations

  1. Requires Semgrep and network access for registry or third-party rules; Pro-only cross-file analysis may be unavailable.
  2. Ruleset coverage is not proof of application security and partial failures can create blind spots.

BEST FIT

Who it is for

→

Security teams needing a controlled first-pass code scan

→

Developers producing reviewable SARIF before code review

BEFORE YOU USE IT

Risks to review before use

High

Third-party rules and source exposure

The workflow may clone external rules and optional engines can communicate with services. Review the plan, keep metrics off, and do not scan sensitive code with unapproved network access.

SECURITY

What the permission profile means

  • Verify every command retains --metrics=off and the approved target scope.
  • Report failed and skipped rulesets instead of presenting a partial scan as clean.

Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.

COMMON QUESTIONS

semgrep Skill FAQ

What is the semgrep Skill?

Approval-gated Semgrep security scans with telemetry disabled and auditable SARIF output. Semgrep is Trail of Bits' approval-gated security scan workflow. It detects languages, proposes exact official and third-party rulesets, disables telemetry, runs approved scans in batches, and merges auditable results into SARIF while recording failures and skipped coverage.

How do I install the semgrep Skill?

Open and review the listed source, choose the project or personal path for your Agent, then verify the first run in a controlled project. Open the pinned commit and read the current SKILL.md.

Is the semgrep Skill safe to use?

SkillSignal checked the source on 2026-09-23, but that is not a runtime test or security certification. Review the “Third-party rules and source exposure” risk first and begin with the least access required.

INSIDE THE PACKAGE

Indexed files

SKILL.mdUpstream package contentSource-linked
workflows/Upstream package contentSource-linked
references/Upstream package contentSource-linked
scripts/Upstream package contentSource-linked

TAGS

semgrepsecurity-scansarif

Original SkillSignal editorial profile grounded in Trail of Bits commit 32e34f81, checked 2026-09-23; not independently executed or security-certified.