Labsco
Labsco/Repos/semgrep/skills
REPO PACKAGE

semgrep skills

COMMUNITY
semgrep · publisher232 repository starsFreegithub.com/semgrep/skills
3skills
2ready to use

code-security is a broad set of secure-coding guidelines spanning SQL and command injection, XSS, hardcoded secrets, and infrastructure-as-code checks across Terraform, Kubernetes, Docker, and GitHub Actions, written to apply whenever an agent touches code that handles input, auth, files, or network calls. llm-security is the same kind of reference guide narrowed to the OWASP Top 10 for LLM Applications 2025 — prompt injection, excessive agency, unbounded consumption — aimed at anyone building chatbots, RAG pipelines, or tool-using agents. The third, semgrep, is the only skill that does anything itself: it runs semgrep --config scans and writes custom YAML detection rules, and it is the one skill in the package that needs a local tool — the semgrep CLI — to work; the other two are pure reference and need nothing installed.

This is for a team that wants an agent to consult security guidance by default while writing or reviewing code — both guide skills instruct the agent to apply them "even if the user doesn't explicitly mention security" — plus anyone who already runs Semgrep and wants help authoring custom rules.

READ THE FULL ANALYSIS

Where this comes from. The README credits one named individual, "@DrewDennison at Semgrep," as the creator, and says the package was "heavily inspired by Vercel's React Best Practices" skill. This reads as one engineer's project published under the Semgrep org, not a formal cross-team release.

The README says it plainly: this is beta and machine-generated. Its own words: "This should be considered beta-level software; it's primarily generated by transforming open-source Semgrep rules into skill format." The guidance inside code-security and llm-security was templated out of existing rule sets rather than written as original prose, which is worth knowing before treating either as a definitive standard.

2Work with nothing else to set up.
232Stars on the GitHub repository, at last check.