Skip to content
SkillsBundleby SANTACONCHA
ES EN

Individual AI skill · AI for Inteligencia e Investigación

semgrep

Run a Semgrep scan with automatic language detection, parallel execution via Task subagents, and merged SARIF output.

Source content · review pending Source language: EN

Choose how you use AI

Agent format only: this skill needs tools or scripts that web projects cannot execute.

Free ZIP · One canonical method · Usage example · Installation guide · Licence notices

From file to useful result

How to ask with this skill installed

Installing the skill gives your AI a method. Your request still has to provide the case-specific facts, constraints and expected output.

1Name the real task

Describe the decision or deliverable, not just the topic.

2Provide the evidence

Add source material, audience, limits and known facts.

3Define done

Set format, quality criteria and checks.

Adaptable starting prompt Replace the brackets with your case

When to use it

  • Security audit of a codebase
  • Finding vulnerabilities before code review
  • Scanning for known bug patterns
  • First-pass static analysis

When not to use it

  • Binary analysis → Use binary analysis tools
  • Already have Semgrep CI configured → Use existing pipeline
  • Need cross-file analysis but no Pro license → Consider CodeQL as alternative
  • Creating custom Semgrep rules → Use semgrep-rule-creator skill
  • Porting existing rules to other languages → Use semgrep-rule-variant-creator skill

What you need first

Required: Semgrep CLI (semgrep --version). If not installed, see Semgrep installation docs.

Optional: Semgrep Pro — enables cross-file taint tracking, inter-procedural analysis, and additional languages (Apex, C#, Elixir). Check with:

semgrep --pro --validate --config p/default 2>/dev/null && echo "Pro available" || echo "OSS only"

Limitations: OSS mode cannot track data flow across files. Pro mode uses -j 1 for cross-file analysis (slower per ruleset, but parallel rulesets compensate).

Choose the right scope

Packs that include this skill

Download only this method or take it together with the rest of its professional area.

This page

Individual skill

The smallest useful download, prepared for a web project or an agent.

Choose format →
Professional pack

AI for Inteligencia e Investigación

This skill plus the other methods selected for this professional area.

Same method, different setup

Where will you use it?

We do not duplicate the skill for every platform. We keep one canonical method and explain the correct installation route.

Traceable by design

Source and licence travel with the file.

SkillsBundle catalogues material of its own and from third parties. Inclusion does not claim original authorship. The individual ZIP preserves the canonical catalogue path and includes the applicable licence notices.

Catalogue path
skills/transversal/knowledge/trailofbits-skills/plugins/static-analysis/skills/semgrep
Ficha origin
Extracted from SKILL.md
Read terms and licence policy →

Start with one real task

Install the method. Keep your judgement.

Choose format