Research: semgrep
Cached research evidence for semgrep (not authority).
Purpose
Section titled “Purpose”Fast pattern-based (and taint) security scanning with Semgrep using built-in (OWASP, CWE, Trail of Bits), custom YAML rules, taint tracking. Parallel scanner agents per lang category; triager agent (Read/Grep/Glob/Write) for FP classification. SARIF/CI friendly. Part of static-analysis plugin.
Harness Coverage
Section titled “Harness Coverage”Security scan agents.
Trust And Risks
Section titled “Trust And Risks”trust_tier=needs-inspection; status=inspect-then-install; provenance=verified-install-command; risks=Rule creation surface (potential for overly broad rules); triage burden on FPs; assumes semgrep available. policy=Inspect.; evidence=trailofbits/skills + docs/src/authoring/skills.
Install Prerequisites
Section titled “Install Prerequisites”npx skills add trailofbits/skills --skill semgrep ... status=inspect-then-install; selector=named (grouped w/ codeql).
Upstream Maintainer
Section titled “Upstream Maintainer”Comparable Alternatives
Section titled “Comparable Alternatives”codeql (deeper), insecure-defaults, variant-analysis, sast-configuration.
> Web evidence.
