
Semgrep
semgrep/skills/skills/semgrepby semgrep68177b8830f9No license322 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 2 months ago
Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code quality', 'find vulnerabilities', 'static analysis', 'lint for security', 'audit this code', or want to enforce coding standards — even if they don't mention Semgrep by name. Semgrep is the right tool for pattern-based code scanning across 30+ languages.
Only the file list is public. File contents are available once the skill is installed in a workspace.
| Path | Size | Type |
|---|---|---|
| README.md | 3.2 KB | text/markdown |
| references/quick-reference.md | 7.1 KB | text/markdown |
| references/workflow.md | 9 KB | text/markdown |
| SKILL.md | 9.2 KB | text/markdown |
Source and attribution
Source:semgrep/skillsinskills/semgrepat commit68177b8
License: No license
Content belongs to its original authors. SourceWeft indexes it from a public repository.
More in Security

Kyc Rules
anthropics
Applies a firm's KYC/AML rules grid to a parsed onboarding record, scoring risk and routing outcomes.

Kyc Rules
anthropics
Applies a firm's KYC/AML rules grid to a parsed onboarding record, scoring risk and routing outcomes.

Compliance Tracking
anthropics
Tracks compliance requirements, audit readiness, and evidence for frameworks such as SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS.

Dpop Adoption
Guides implementation of OAuth 2.0 DPoP (RFC 9449) sender-constrained refresh tokens for Google's OAuth platform.

Secops Triage
Guides SOC analysts through triaging Google SecOps security alerts, from investigation to closure or escalation.

Secops Investigate
Guides SOC analysts through deep security incident and entity investigations in Google SecOps using UDM queries and timelines.