Lightlines
Catalogue
Sign in
By trailofbits

codeql

trailofbits

Find vulnerabilities before they ship.

static analysis

What it does

Scans a codebase for security vulnerabilities with CodeQL's interprocedural data-flow and taint-tracking analysis.

When to use it

Use it for CodeQL scans, database builds, SAST, taint analysis, data-flow analysis, or vulnerability searches; use semgrep for fast single-file matching and sarif-parsing for existing SARIF.

How to use it

Give it a codebase and scan request; it builds a CodeQL database, creates data extensions, runs analysis, and stores the generated artifacts in the output directory.

What you provide

  • a codebase scan target
  • An existing project

Access · 0

No additional actions listed in the analysis.

What you need · 3

The CodeQL CLI must be installed and available on PATH.

jq must be installed and available on PATH to parse CodeQL database metadata.

uv must be installed and available on PATH to run the guard scripts and suite generators.


About this skill

Visibility
Public
Repository
trailofbits/skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
34