Del archivo al resultado útil
Cómo pedir trabajo con esta skill instalada
Instalar la skill da un método a tu IA. Tu petición todavía debe aportar los hechos del caso, las restricciones y el entregable esperado.
Describe la decisión o el entregable, no solo el tema.
Añade materiales, público, límites y hechos conocidos.
Fija formato, criterios de calidad y comprobaciones.
Cuándo usarla
- Security audit of a codebase
- Finding vulnerabilities before code review
- Scanning for known bug patterns
- First-pass static analysis
Cuándo no usarla
- Binary analysis → Use binary analysis tools
- Already have Semgrep CI configured → Use existing pipeline
- Need cross-file analysis but no Pro license → Consider CodeQL as alternative
- Creating custom Semgrep rules → Use
semgrep-rule-creatorskill - Porting existing rules to other languages → Use
semgrep-rule-variant-creatorskill
Qué necesitas antes
Required: Semgrep CLI (semgrep --version). If not installed, see Semgrep installation docs.
Optional: Semgrep Pro — enables cross-file taint tracking, inter-procedural analysis, and additional languages (Apex, C#, Elixir). Check with:
semgrep --pro --validate --config p/default 2>/dev/null && echo "Pro available" || echo "OSS only"
Limitations: OSS mode cannot track data flow across files. Pro mode uses -j 1 for cross-file analysis (slower per ruleset, but parallel rulesets compensate).