Research: semgrep

Cached research evidence for semgrep (not authority).

Back to catalog page

Fast pattern-based (and taint) security scanning with Semgrep using built-in (OWASP, CWE, Trail of Bits), custom YAML rules, taint tracking. Parallel scanner agents per lang category; triager agent (Read/Grep/Glob/Write) for FP classification. SARIF/CI friendly. Part of static-analysis plugin.

Security scan agents.

trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; risks=Rule creation surface (potential for overly broad rules); triage burden on FPs; assumes semgrep available. policy=Inspect.; evidence=trailofbits/skills + docs/src/authoring/skills.

npx skills add trailofbits/skills --skill semgrep ... status=inspect-then-install; selector=named (grouped w/ codeql).

trailofbits/skills.

codeql (deeper), insecure-defaults, variant-analysis, sast-configuration.

> Web evidence.