Model or dataset
semgrep/skills avatar
semgrep/skills

semgrep/skills: Security Knowledge Packages for AI Coding Agents

A collection of skills for AI coding agents from Semgrep

316 stars31 forksJavaScriptNOASSERTION

At a glance

What is it?
semgrep/skills is a beta collection of three security-focused skills for AI coding agents, primarily generated from open-source Semgrep rules. It follows the agentskills.io format and covers OWASP Top 10 code security across 15+ languages, OWASP LLM Top 10 security for AI applications, and Semgrep scan operation. Installing with one npx command makes the skills available to Claude Code, Codex, and compatible agents.
Who is it for?
Development teams using AI coding agents who want those agents to apply OWASP security guidance during code generation and review will find semgrep/skills provides structured coverage for code security, LLM application security, and Semgrep rule creation. The beta status means the API surface can change.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 64 days ago.
What is it written in?
Mainly JavaScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What semgrep/skills Packages and Who It Serves

AI coding agents like Claude Code and Codex execute tasks in a codebase by reading, writing, and running code. Without domain-specific guidance, those agents have no structured way to apply security best practices during code generation or review. semgrep/skills solves this by providing packaged instructions in a format agents can load and act on.

The README describes the collection as "primarily generated by transforming open-source Semgrep rules into skill format" and warns that it "should be considered beta-level software." The skills follow the agentskills.io format, which defines how packaged instructions are structured and distributed.

The target audience is a developer who uses an AI coding agent and wants that agent to catch SQL injection, XSS, path traversal, and similar vulnerabilities while generating or reviewing code, without running a separate scan manually. It is also useful for teams building LLM-powered applications who want their AI assistant to apply the OWASP LLM Top 10 during code review.

code-security: OWASP Coverage Across 15+ Languages

The `code-security` skill provides comprehensive code security guidelines derived from Semgrep rules. It covers the OWASP Top 10, infrastructure security, and secure coding patterns across more than 15 languages.

Critical-impact categories include SQL injection (parameterized queries, ORM safety), command injection (shell command safety, input validation), cross-site scripting (output encoding, DOM safety), XML External Entity injection (XML parser configuration), path traversal (file path validation), insecure deserialization, code injection (eval safety, template injection), hardcoded secrets (environment variables, secret management), and memory safety (buffer overflows, use-after-free in C/C++).

High-impact categories cover insecure cryptography (SHA-256+, AES), insecure transport (HTTPS, TLS, certificate validation), SSRF (URL validation, allowlists), JWT authentication (signature verification, algorithm safety), CSRF (tokens, SameSite cookies), prototype pollution in JavaScript, unsafe functions, and infrastructure-as-code security for Terraform on AWS, Azure, and GCP, plus Kubernetes, Docker, and GitHub Actions.

Languages covered include Python, JavaScript and TypeScript, Java, Go, Ruby, PHP, C and C++, C#, Scala, Kotlin, Rust, HCL for Terraform, and YAML for Kubernetes.

llm-security: Securing AI-Powered Applications

The `llm-security` skill covers security guidelines specific to applications that use large language models. It is based on the OWASP Top 10 for Large Language Model Applications 2025 and also references MITRE ATLAS and NIST AI RMF.

Critical-impact categories are prompt injection (input validation, content segregation, output filtering), sensitive information disclosure (PII detection, permission-aware RAG), supply chain (model verification, safetensors, ML-BOM), data and model poisoning (training data validation, anomaly detection), and improper output handling (context-aware encoding, parameterized queries).

High-impact categories cover excessive agency (least privilege, human-in-the-loop), system prompt leakage (external guardrails, no secrets in prompts), vector and embedding weaknesses (permission-aware retrieval, tenant isolation), misinformation (RAG, fact verification, confidence scoring), and unbounded consumption (rate limiting, budget controls).

The README suggests using this skill when building LLM-powered applications, implementing RAG systems, securing AI and ML pipelines, or reviewing code that interacts with language models.

Installing Skills and Using the Semgrep Scan Skill

Installing the full skill collection requires one command:

bash
npx skills add semgrep/skills

After installation, skills are automatically available. The agent uses them when it detects a relevant task. The README gives example prompts: "Review this React component for security issues", "Help me implement input validation for my LLM chat endpoint", and "Create a Semgrep rule to detect hardcoded API keys in Python."

The third skill, `semgrep`, supports running Semgrep scans and creating custom rules. It documents quick scans (`semgrep --config auto`), curated rulesets (security-audit, owasp-top-ten, cwe-top-25, trailofbits), a test-driven rule creation workflow (write test cases first with `ruleid:` and `ok:` annotations, analyze AST structure with `semgrep --dump-ast`, write the rule, iterate until tests pass), and GitHub Actions CI/CD integration. Taint mode is recommended for injection vulnerabilities (SQL injection, command injection, XSS, path traversal, SSRF) where untrusted data flows to a dangerous sink.

Building and Contributing to the Skills Collection

The repository uses a Makefile to build and package the skills. The full build pipeline runs:

bash
make install     # Install dependencies
make validate    # Validate all skills
make build       # Build AGENTS.md for all skills
make zip         # Create distribution packages
make             # All of the above

Individual skills can be validated and built separately:

bash
make validate-skill SKILL=code-security
make build-skill SKILL=llm-security

Each skill has a directory under `skills/` containing a `SKILL.md` file with instructions for the agent, an optional `rules/` directory for individual Semgrep rule files, optional `scripts/` helpers, and optional `references/` documentation. The build process transforms open-source Semgrep rules into the skill format and generates the `AGENTS.md` file that agents read.

The README credits the original creation to Drew Dennison at Semgrep and notes it was inspired by Vercel's React Best Practices skills work.

Limitations: Beta Status, License Ambiguity, and Scope

The README explicitly marks the package as beta-level software. The skill definitions are primarily machine-generated from existing Semgrep rules, and the specific guidance within each category can change between versions. Teams building workflows that depend on the exact wording or categories of skill instructions should treat those as unstable.

The license field in the repository metadata is NOASSERTION, meaning the license is not definitively identified by GitHub's license detection. The README does not clarify this. Teams in organizations with strict open-source license policies should investigate the provenance of the Semgrep rules that form the skill content before adopting the package.

The skills cover general security patterns, not project-specific rules. The `semgrep` skill documents how to create custom Semgrep rules, but does not ship custom rules tuned to any particular codebase. Teams who need rules specific to their own frameworks or patterns will need to write those separately.

The collection contains exactly three skills (code-security, llm-security, semgrep). Coverage outside those three areas, such as infrastructure monitoring, access control design, or cryptographic protocol selection, is not included.

semgrep/skills vs. Running Semgrep Directly: Agent Context vs. CI Report

Running Semgrep directly in a CI pipeline (`semgrep --config auto` or with a specific ruleset) produces a scan report of findings against the current codebase. This runs as an independent process, requires no AI agent, and integrates with GitHub Actions, GitLab CI, or any CI system. The output is a list of matched rule findings with file and line references.

semgrep/skills provides security knowledge to an AI agent as structured context. The agent uses that context while generating or reviewing code, not as a post-generation scan. The difference is timing and mechanism: skills influence what the agent writes before a file exists, while a Semgrep CI scan checks what was written after the fact.

For teams that already run Semgrep in CI, adding semgrep/skills to their agent workflow provides a complementary layer: the agent avoids writing the vulnerability in the first place, and CI confirms the result. For teams with no static analysis in CI, skipping the skills and running Semgrep directly in CI provides deterministic, auditable results that do not depend on the agent's behavior.

Editorial conclusion

Development teams using AI coding agents who want those agents to apply OWASP security guidance during code generation and review will find semgrep/skills provides structured coverage for code security, LLM application security, and Semgrep rule creation. The beta status means the API surface can change. Teams who want deterministic static analysis results in CI, independent of an AI agent, should run Semgrep or CodeQL directly rather than through this skills layer. The last push was on 2026-07-28 and the repository is not archived.

Frequently asked questions

How do I install skills in Claude Code?

Run npx skills add semgrep/skills in the project directory. Once installed, the skills are automatically available to the agent and will be used when relevant tasks are detected, without any additional configuration.

How do I install skills from GitHub to Claude?

The semgrep/skills package follows the agentskills.io format and installs with npx skills add semgrep/skills. This command fetches the skills from the semgrep/skills GitHub repository and registers them with compatible agents including Claude Code.

How do I use skills in Claude Code?

After installation, skills are used automatically. The README notes that the agent applies them when relevant tasks are detected. Example prompts that trigger the skills include reviewing a component for security issues, implementing input validation for an LLM endpoint, or creating a Semgrep rule for a specific vulnerability pattern.

Official sources

  1. Issues
  2. Project website
  3. README
  4. semgrep/skills on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/semgrep-skills.svg)](https://hysenlabs.com/projects/semgrep-skills)