IN PLAIN ENGLISH
What it does—and when it fits
Semgrep is Trail of Bits' approval-gated security scan workflow. It detects languages, proposes exact official and third-party rulesets, disables telemetry, runs approved scans in batches, and merges auditable results into SARIF while recording failures and skipped coverage.
This is aimed at Security teams needing a controlled first-pass code scan. Compare the examples below with your task, then review the limitations, permissions, and risks before installing.
- Plan the scanDetect languages and choose full or important-only coverage.
- Approve exact rulesetsShow target, engine, mode, and every ruleset before execution.
- Merge auditable outputPreserve raw scans and report failed, skipped, or empty coverage.
- Telemetry-off commands and an explicit plan reduce accidental source disclosure.
- Combines fast multi-language rules with optional cross-file Pro analysis.
No verified review text is in the current dataset. Use the linked source for the latest discussion.
Read the source note ↗INSTALL BY AGENT
Choose your Agent
Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.
npx skills add trailofbits/skills --skill semgrep --agent claude-codenpx skills add trailofbits/skills --skill semgrep --agent claude-code -gProject install stays with this repository for team sharing. Personal install adds -g and works across repositories.
View install paths
.claude/skills/semgrep/~/.claude/skills/semgrep/Claude Code discovers custom Skill folders automatically at project or personal scope.
View path evidence ↗TYPICAL WORKFLOW
A practical workflow
Plan the scan
Detect languages and choose full or important-only coverage.
Approve exact rulesets
Show target, engine, mode, and every ruleset before execution.
Merge auditable output
Preserve raw scans and report failed, skipped, or empty coverage.
THE TRADEOFFS
Advantages and tradeoffs
Notable strengths
- Telemetry-off commands and an explicit plan reduce accidental source disclosure.
- Combines fast multi-language rules with optional cross-file Pro analysis.
Limitations
- Requires Semgrep and network access for registry or third-party rules; Pro-only cross-file analysis may be unavailable.
- Ruleset coverage is not proof of application security and partial failures can create blind spots.
BEST FIT
Who it is for
Security teams needing a controlled first-pass code scan
Developers producing reviewable SARIF before code review
BEFORE YOU USE IT
Risks to review before use
Third-party rules and source exposure
The workflow may clone external rules and optional engines can communicate with services. Review the plan, keep metrics off, and do not scan sensitive code with unapproved network access.
SECURITY
What the permission profile means
- Verify every command retains --metrics=off and the approved target scope.
- Report failed and skipped rulesets instead of presenting a partial scan as clean.
Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.
COMMON QUESTIONS
semgrep Skill FAQ
What is the semgrep Skill?
Approval-gated Semgrep security scans with telemetry disabled and auditable SARIF output. Semgrep is Trail of Bits' approval-gated security scan workflow. It detects languages, proposes exact official and third-party rulesets, disables telemetry, runs approved scans in batches, and merges auditable results into SARIF while recording failures and skipped coverage.
How do I install the semgrep Skill?
Open and review the listed source, choose the project or personal path for your Agent, then verify the first run in a controlled project. Open the pinned commit and read the current SKILL.md.
Is the semgrep Skill safe to use?
SkillSignal checked the source on 2026-09-23, but that is not a runtime test or security certification. Review the “Third-party rules and source exposure” risk first and begin with the least access required.
INSIDE THE PACKAGE
Indexed files
TAGS
Original SkillSignal editorial profile grounded in Trail of Bits commit 32e34f81, checked 2026-09-23; not independently executed or security-certified.