Find security flaws before they ship.
static analysis
Scans a codebase for security vulnerabilities and produces merged SARIF results.
When to use it
Use it for security audits, vulnerability finding, known bug patterns, or first-pass static analysis.
Give it a codebase; it detects languages, selects approved rulesets, runs the scan, and writes SARIF results.
What you provide
This skill
third-party rule repositories
Clones third-party repositories
The Semgrep CLI must be installed and available for `semgrep --version`.