semgrep skills
COMMUNITYLABSCO SUMMARY
code-security is a broad set of secure-coding guidelines spanning SQL and command injection, XSS, hardcoded secrets, and infrastructure-as-code checks across Terraform, Kubernetes, Docker, and GitHub Actions, written to apply whenever an agent touches code that handles input, auth, files, or network calls. llm-security is the same kind of reference guide narrowed to the OWASP Top 10 for LLM Applications 2025 — prompt injection, excessive agency, unbounded consumption — aimed at anyone building chatbots, RAG pipelines, or tool-using agents. The third, semgrep, is the only skill that does anything itself: it runs semgrep --config scans and writes custom YAML detection rules, and it is the one skill in the package that needs a local tool — the semgrep CLI — to work; the other two are pure reference and need nothing installed.
This is for a team that wants an agent to consult security guidance by default while writing or reviewing code — both guide skills instruct the agent to apply them "even if the user doesn't explicitly mention security" — plus anyone who already runs Semgrep and wants help authoring custom rules.
READ THE FULL ANALYSIS
Where this comes from. The README credits one named individual, "@DrewDennison at Semgrep," as the creator, and says the package was "heavily inspired by Vercel's React Best Practices" skill. This reads as one engineer's project published under the Semgrep org, not a formal cross-team release.
The README says it plainly: this is beta and machine-generated. Its own words: "This should be considered beta-level software; it's primarily generated by transforming open-source Semgrep rules into skill format." The guidance inside code-security and llm-security was templated out of existing rule sets rather than written as original prose, which is worth knowing before treating either as a definitive standard.
WHAT'S INSIDE
3 showing · 3 totalNothing else to set up — install it and go.
code-security
A catalogue of the ways code gets broken into - 28 of them, across more than fifteen languages and the config files that set up servers - each shown as a broken example and the fix for it.
llm-security
Chatbots, document-search systems and tool-using agents each get attacked in their own way; this works through the ten risks on OWASP's 2025 list for AI applications and what stops each one.
semgrep
Semgrep hunts for suspicious patterns by reading code rather than running it, so a scan takes minutes. This runs one over your project and, where the stock rules miss something, helps you write your own.
HOW TO GET IT
npx skills add semgrep/skillsnpx skills add semgrep/skills --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.