Lightlines
By trailofbits

semgrep

trailofbits

Find security flaws before they ship.

static analysis

What it does

Scans a codebase for security vulnerabilities and produces merged SARIF results.

When to use it

Use it for security audits, vulnerability finding, known bug patterns, or first-pass static analysis.

How to use it

Give it a codebase; it detects languages, selects approved rulesets, runs the scan, and writes SARIF results.

What you provide

  • An existing project

Access · 1

This skill

third-party rule repositories

Read

Clones third-party repositories

Good to know

  • starts helper agents, number unstated
  • acts without asking

What you need · 1

The Semgrep CLI must be installed and available for `semgrep --version`.


About this skill

Visibility
Public
Repository
trailofbits/skills
Created
Oct 8, 2026
Updated
Oct 8, 2026
Files
9