
Semgrep
Securityby trailofbits
3/3 audits passCC-BY-SA-4.0
Runs a Semgrep security scan over a codebase: detects languages, selects rulesets, presents the plan for explicit approval, then runs every approved ruleset through scripts/run-scans.sh, which batches the semgrep…
Semgrep is Trail of Bits' static-analysis skill (publisher trailofbits, CC-BY-SA-4.0) for running a Semgrep security scan over a codebase. The agent detects languages, selects rulesets, and must present the exact plan (rulesets, target, engine and mode) for explicit approval before any scan runs. Its bundled scripts/run-scans.sh then generates and batches every semgrep command, and a Python script merges the results to SARIF. Its principles are strict: every command uses --metrics=off, third-party rulesets from Trail of Bits, 0xdea and Decurity are included when the language matches, Semgrep Pro is checked for cross-file taint analysis, and rulesets that failed or were skipped must be reported rather than presented as a complete scan. It offers two modes, "run all" and "important only".
Use it for a first-pass security audit or to find known bug patterns before code review. The skill says not to use it for binary analysis, where Semgrep CI already exists, or for writing custom rules.
This is mainly for coding agents such as Claude Code that can run Semgrep locally. The skill depends on its bundled scripts; BusinessMCP imports skills as instructions only and does not run those scripts, so an imported copy serves as guidance rather than a working scanner.
What you can do with it
- Run a first-pass security scan of a new codebase
- Scan only high-confidence, high-impact security findings
- Merge per-ruleset Semgrep output into one SARIF file
- Check a repo with Trail of Bits and Decurity rulesets
Run it on your business data
Imported into BusinessMCP, Semgrep becomes a playbook your AI business analyst applies to your connected GitHub repositories.
Use Semgrep in BusinessMCPInstall it in a coding agent
One command adds Semgrep to your project.
npx skills add https://github.com/trailofbits/skills --skill semgrepHow we vetted it
- Source
- trailofbits/skills at 0cc1c73
- Licence
- CC-BY-SA-4.0
- Security audits (skills.sh)
- Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
- Bundled scripts
- Yes — read them before installing
Checked 2026-09-25 against its skills.sh listing. How we vet skills
Related skills
All skillsDifferential Review
Performs security-focused differential review of code changes. Adapts analysis depth to codebase size, uses git blame for context, calculates blast radius by counting callers, checks test coverage of modified code, and…
Supply Chain Risk Auditor
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration, and install-time script…
Security and Hardening
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…
Frequently asked questions
Does the Semgrep skill scan without asking?
No. Presenting the scan plan and waiting for an explicit yes is a hard gate; the original "scan this codebase" request does not count as approval.
Why does it always use --metrics=off?
Semgrep sends telemetry by default and --config auto also contacts its servers, so the skill turns metrics off on every command to avoid leaking data during a security audit.
How do I install Semgrep?
Run `npx skills add trailofbits/skills --skill semgrep`, or import it from the BusinessMCP dashboard, where only its instructions are kept and its scripts are not run.