Semgrep + CodeRabbit Review Skill
A comprehensive two-stage code review workflow that combines fast pattern detection with AI-powered semantic analysis for maximum coverage and efficiency.
What I Do
I orchestrate a complete code review process:
Stage 1: Fast Pattern Detection (10-20 seconds)
- Run Semgrep to catch security patterns, architecture violations, and code quality issues
- Identify hardcoded secrets, SQL injection risks, XSS vulnerabilities
- Check Repository Pattern compliance (API layer)
- Validate authentication guards and error handling patterns
- Flag console.log and weak cryptography patterns
Stage 2: AI-Powered Semantic Review (5-30 minutes)
- Run CodeRabbit to analyze code logic, architecture, and business context
- Verify OpenAPI contracts and breaking changes
- Validate test coverage and error handling
- Review multi-tenant isolation and data flow
- Provide context-aware recommendations
Combined Report
- Prioritized findings (CRITICAL → HIGH → MEDIUM → LOW)
- Clear explanation of each issue with fix guidance
- Performance metrics and improvement suggestions
- Compliance verification (security, architecture, code quality)
When to Use Me
Use this skill when you need to:
- ✅ Review uncommitted changes before committing
- ✅ Audit specific feature implementations
- ✅ Verify API layer compliance
- ✅ Check database query safety
- ✅ Review frontend code (Svelte 5, TypeScript)
- ✅ Pre-merge security and architecture validation
- ✅ Ensure multi-tenant isolation and data protection
- ✅ Validate API contracts (OpenAPI synchronization)
Do NOT use if you only need:
- ❌ Quick syntax/linter check (use linters directly)
- ❌ Style or formatting fixes (use Prettier/ESLint)
- ❌ Documentation review (use Codex security review)
How I Work
1. Fast Feedback Loop (Stage 1)
semgrep scan --config .semgrep.yaml --error
Catches in 10-20 seconds:
- 🔐 Hardcoded secrets (API keys, tokens, passwords)
- 🔐 SQL injection patterns (string concat, unvalidated input)
- 🔐 XSS vulnerabilities (unsafe {@html}, template injection)
- 🔐 Missing authentication guards on protected routes
- 🏗️ Direct database access (bypassing Repository Pattern)
- 📋 Weak cryptography (MD5, SHA1, deprecated functions)
- 📋 Code quality (console.log, any types, commented code)
Action: Fix all Semgrep violations immediately. They are deterministic and indicate real issues.
2. Comprehensive Review (Stage 2)
coderabbit --prompt-only -t uncommitted
Catches in 5-30 minutes:
- ✅ Logic correctness and edge cases
- ✅ Test coverage gaps on behavioral changes
- ✅ Error handling and resilience
- ✅ Architecture and design patterns
- ✅ API contracts and breaking changes
- ✅ Multi-tenant isolation and security
- ✅ Performance optimization opportunities
Action: Fix CRITICAL + HIGH issues. Consider MEDIUM issues if reasonable.
3. Verification & Iteration
Re-run both tools after fixes to ensure no new issues introduced:
semgrep scan --config .semgrep.yaml --error
coderabbit --prompt-only -t uncommitted
Review Focus Areas by Layer
API Layer (Fastify Routes)
What Semgrep catches:
- Missing
preHandler: [fastify.authenticate] on protected routes
- Direct
db.query() instead of Repository Pattern
- SQL injection patterns in raw queries
- Hardcoded secrets or API keys in route definitions
What CodeRabbit catches:
- OpenAPI schema mismatches
- HTTP status code errors (should be 201 for create, 204 for delete, etc.)
- Inconsistent error response format
- Rate limiting misconfiguration
- Breaking changes to API contracts
Checklist:
Database Layer (Repository Pattern)
What Semgrep catches:
- Raw SQL queries (should use Oracle parameterized queries)
- Missing error handling
- Direct database access in routes
What CodeRabbit catches:
- Parameterization correctness
- User context scoping (multi-tenant isolation)
- Error recovery logic
- Query performance patterns
Checklist:
Frontend Layer (Svelte 5, TypeScript)
What Semgrep catches:
- Legacy Svelte 4 syntax (
$:, export let, bind:)
{@html} without sanitization (XSS risk)
any types (type safety lost)
- console.log statements
What CodeRabbit catches:
- Svelte 5 runes compliance (proper use of $state, $derived, etc.)
- Component logic correctness
- Performance (N+1 queries, unnecessary re-renders)
- Accessibility issues
- Mobile responsiveness
Checklist:
Shared Types & Contracts
What Semgrep catches:
any types in shared definitions
- Hardcoded values (should be constants or env vars)
What CodeRabbit catches:
- Zod schema completeness (match OpenAPI definitions)
- Type inference correctness
- Breaking change documentation
Checklist:
Priority & Workflow
Execution Sequence
Stage 1: Semgrep (10-20 seconds)
- Run scan
- If FAIL → Fix ALL violations → Re-run until PASS
- If PASS → Proceed to Stage 2
Stage 2: CodeRabbit (5-30 minutes)
- Run review
- Evaluate findings
Fix Issues
- CRITICAL: Fix immediately (security, auth, data corruption)
- HIGH: Fix before merge (architecture, breaking changes)
- MEDIUM: Fix if reasonable (code quality)
- LOW: Consider optional (suggestions)
Verify
- Re-run both tools
- Confirm no new issues
Issue Priority Reference
| Priority |
Level |
Examples |
Deadline |
| 🚫 CRITICAL |
Blocking |
Secrets, auth bypass, SQL injection, XSS, data leakage |
MUST fix before merge |
| 🚫 HIGH |
Architectural |
Missing guards, schema mismatch, breaking changes, race conditions |
Fix before merge |
| ⚠️ MEDIUM |
Quality |
Weak crypto, poor error handling, type safety, duplication |
Fix if reasonable |
| 💡 LOW |
Polish |
Suggestions, optimization, style |
Consider optional |
Common Issues & Fixes
Security Issues
| Pattern |
Fix |
const secret = "hardcoded-key" |
Move to process.env.SECRET or OCI Vault |
| SQL string concat |
Use SELECT * FROM users WHERE id = ? with bindings |
{@html userContent} |
Use {@html DOMPurify.sanitize(userContent)} |
| No auth guard |
Add preHandler: [fastify.authenticate] |
console.log(token) |
Remove or use safe logger without secrets |
Architecture Issues
| Pattern |
Fix |
await fastify.db.query(...) |
Use await request.repos.entity.method(ctx) |
| Missing DbContext |
Pass user ID context to all DB operations |
export let prop (Svelte) |
Use let { prop } = $props() (Svelte 5) |
| Wrong status code |
201 for create, 204 for delete, 400 for validation |
any type |
Define explicit type or unknown with type guard |
Code Quality Issues
| Pattern |
Fix |
console.log() in prod |
Remove or use proper logging layer |
MD5.hash() |
Use crypto.subtle.digest('SHA-256', ...) |
| No test coverage |
Add test for new behavior/branch |
| Duplicate logic |
Extract to reusable function/component |
| N+1 queries |
Batch queries or use database join |
Tips for Efficiency
Fix Semgrep First
- Patterns are deterministic and quick to verify
- No ambiguity in fixes
- Fail fast mentality
Read CodeRabbit Carefully
- It provides context and reasoning
- Use inline comments for clarification
- Ask it to explain if unclear
Batch Similar Fixes
- Don't context-switch between issue types
- Fix all secret issues, then auth issues, etc.
- Run unit tests after each batch
Maximum 3 Passes
- If you need more than 3 review cycles, break into smaller PRs
- Each cycle should be more targeted
Test as You Go
- Run unit tests after each fix batch
- Verify Semgrep passes immediately
- Run CodeRabbit once before committing
Related Skills & References
- Plugin:
opencode-semgrep-coderabbit-plugin (provides tools for this skill)
- Docs:
AGENTS.md, .semgrep.yaml, .coderabbit.yaml
- Repository Pattern:
packages/database/src/repositories/
- API Examples:
apps/api/src/routes/
Troubleshooting
| Issue |
Cause |
Solution |
| Semgrep takes >30s |
Large change set or complex patterns |
Run on smaller subset or filter by rule |
| CodeRabbit takes >30min |
Very large changes (>500 lines) |
Break into smaller PRs |
| Too many findings |
Code quality debt accumulation |
Fix critical/high, schedule follow-up for medium/low |
| Same issue on re-run |
Fix incomplete or misunderstood |
Read feedback again, ask CodeRabbit for clarification |
| Semgrep false positives |
Rule too broad or context-specific |
Review rule definition, can mark as intended if safe |
| Conflicting tool feedback |
Tools have different perspectives |
Trust Semgrep (deterministic), validate CodeRabbit with context |
Next Steps
- Load this skill: Use
/skill semgrep-coderabbit-review in OpenCode
- Install plugin: Install
opencode-semgrep-coderabbit-plugin for tools
- Run review: Use one of the provided commands
- Follow workflow: Stage 1 (Semgrep) → Stage 2 (CodeRabbit) → Fix → Verify
- Share feedback: Help improve this skill for your team
Questions?
- Check the plugin README for detailed usage
- Review
.semgrep.yaml for specific rule definitions
- Check
.coderabbit.yaml for CodeRabbit configuration
- Ask CodeRabbit inline if feedback is unclear
- Open an issue on the plugin repository
Version: 1.0
Last Updated: Jan 22, 2026
Status: Production Ready
Plugin Required: opencode-semgrep-coderabbit-plugin >= 1.0.0
1---2name: semgrep-coderabbit-review3description: Two-stage code review combining fast pattern detection (Semgrep) with AI-powered semantic analysis (CodeRabbit)4license: MIT5---67# Semgrep + CodeRabbit Review Skill89A comprehensive two-stage code review workflow that combines **fast pattern detection** with **AI-powered semantic analysis** for maximum coverage and efficiency.1011## What I Do1213I orchestrate a complete code review process:1415### Stage 1: Fast Pattern Detection (10-20 seconds)1617- Run Semgrep to catch security patterns, architecture violations, and code quality issues18- Identify hardcoded secrets, SQL injection risks, XSS vulnerabilities19- Check Repository Pattern compliance (API layer)20- Validate authentication guards and error handling patterns21- Flag console.log and weak cryptography patterns2223### Stage 2: AI-Powered Semantic Review (5-30 minutes)2425- Run CodeRabbit to analyze code logic, architecture, and business context26- Verify OpenAPI contracts and breaking changes27- Validate test coverage and error handling28- Review multi-tenant isolation and data flow29- Provide context-aware recommendations3031### Combined Report3233- Prioritized findings (CRITICAL → HIGH → MEDIUM → LOW)34- Clear explanation of each issue with fix guidance35- Performance metrics and improvement suggestions36- Compliance verification (security, architecture, code quality)3738## When to Use Me3940Use this skill when you need to:4142- ✅ Review uncommitted changes before committing43- ✅ Audit specific feature implementations44- ✅ Verify API layer compliance45- ✅ Check database query safety46- ✅ Review frontend code (Svelte 5, TypeScript)47- ✅ Pre-merge security and architecture validation48- ✅ Ensure multi-tenant isolation and data protection49- ✅ Validate API contracts (OpenAPI synchronization)5051**Do NOT use if you only need:**5253- ❌ Quick syntax/linter check (use linters directly)54- ❌ Style or formatting fixes (use Prettier/ESLint)55- ❌ Documentation review (use Codex security review)5657## How I Work5859### 1. Fast Feedback Loop (Stage 1)6061```bash62semgrep scan --config .semgrep.yaml --error63```6465**Catches in 10-20 seconds:**6667- 🔐 Hardcoded secrets (API keys, tokens, passwords)68- 🔐 SQL injection patterns (string concat, unvalidated input)69- 🔐 XSS vulnerabilities (unsafe {@html}, template injection)70- 🔐 Missing authentication guards on protected routes71- 🏗️ Direct database access (bypassing Repository Pattern)72- 📋 Weak cryptography (MD5, SHA1, deprecated functions)73- 📋 Code quality (console.log, any types, commented code)7475**Action:** Fix all Semgrep violations immediately. They are deterministic and indicate real issues.7677### 2. Comprehensive Review (Stage 2)7879```bash80coderabbit --prompt-only -t uncommitted81```8283**Catches in 5-30 minutes:**8485- ✅ Logic correctness and edge cases86- ✅ Test coverage gaps on behavioral changes87- ✅ Error handling and resilience88- ✅ Architecture and design patterns89- ✅ API contracts and breaking changes90- ✅ Multi-tenant isolation and security91- ✅ Performance optimization opportunities9293**Action:** Fix CRITICAL + HIGH issues. Consider MEDIUM issues if reasonable.9495### 3. Verification & Iteration9697Re-run both tools after fixes to ensure no new issues introduced:9899```bash100semgrep scan --config .semgrep.yaml --error101coderabbit --prompt-only -t uncommitted102```103104## Review Focus Areas by Layer105106### API Layer (Fastify Routes)107108**What Semgrep catches:**109110- Missing `preHandler: [fastify.authenticate]` on protected routes111- Direct `db.query()` instead of Repository Pattern112- SQL injection patterns in raw queries113- Hardcoded secrets or API keys in route definitions114115**What CodeRabbit catches:**116117- OpenAPI schema mismatches118- HTTP status code errors (should be 201 for create, 204 for delete, etc.)119- Inconsistent error response format120- Rate limiting misconfiguration121- Breaking changes to API contracts122123**Checklist:**124125- [ ] All protected routes have authentication guards126- [ ] All DB ops use `await request.repos.entity.method(ctx)`127- [ ] Correct HTTP status codes for all scenarios128- [ ] Error responses follow consistent format129- [ ] OpenAPI schema synchronized with implementation130131### Database Layer (Repository Pattern)132133**What Semgrep catches:**134135- Raw SQL queries (should use Oracle parameterized queries)136- Missing error handling137- Direct database access in routes138139**What CodeRabbit catches:**140141- Parameterization correctness142- User context scoping (multi-tenant isolation)143- Error recovery logic144- Query performance patterns145146**Checklist:**147148- [ ] All queries use Oracle parameterized bindings (no string concat)149- [ ] User context (DbContext) properly scoped150- [ ] Errors thrown with ApplicationError(code, message)151- [ ] 100% test coverage for security-critical queries152- [ ] Multi-tenant isolation verified153154### Frontend Layer (Svelte 5, TypeScript)155156**What Semgrep catches:**157158- Legacy Svelte 4 syntax (`$:`, `export let`, `bind:`)159- `{@html}` without sanitization (XSS risk)160- `any` types (type safety lost)161- console.log statements162163**What CodeRabbit catches:**164165- Svelte 5 runes compliance (proper use of $state, $derived, etc.)166- Component logic correctness167- Performance (N+1 queries, unnecessary re-renders)168- Accessibility issues169- Mobile responsiveness170171**Checklist:**172173- [ ] Only Svelte 5 runes used ($state, $derived, $props, $effect, {#snippet})174- [ ] HTML output sanitized or text interpolation used175- [ ] No `any` types (explicit types or `unknown` with guards)176- [ ] Mobile-first responsive design177- [ ] Accessibility verified (ARIA labels, semantic HTML)178179### Shared Types & Contracts180181**What Semgrep catches:**182183- `any` types in shared definitions184- Hardcoded values (should be constants or env vars)185186**What CodeRabbit catches:**187188- Zod schema completeness (match OpenAPI definitions)189- Type inference correctness190- Breaking change documentation191192**Checklist:**193194- [ ] Zod schemas match OpenAPI definitions195- [ ] Types exported from schemas (type User = z.infer<...>)196- [ ] Discriminated unions for error types197- [ ] No `any` types (use `unknown` with guards)198- [ ] Breaking changes documented in JSDoc199200## Priority & Workflow201202### Execution Sequence2032041. **Stage 1: Semgrep** (10-20 seconds)205 - Run scan206 - If FAIL → Fix ALL violations → Re-run until PASS207 - If PASS → Proceed to Stage 22082092. **Stage 2: CodeRabbit** (5-30 minutes)210 - Run review211 - Evaluate findings2122133. **Fix Issues**214 - CRITICAL: Fix immediately (security, auth, data corruption)215 - HIGH: Fix before merge (architecture, breaking changes)216 - MEDIUM: Fix if reasonable (code quality)217 - LOW: Consider optional (suggestions)2182194. **Verify**220 - Re-run both tools221 - Confirm no new issues222223### Issue Priority Reference224225| Priority | Level | Examples | Deadline |226| ----------- | ------------- | ------------------------------------------------------------------ | --------------------- |227| 🚫 CRITICAL | Blocking | Secrets, auth bypass, SQL injection, XSS, data leakage | MUST fix before merge |228| 🚫 HIGH | Architectural | Missing guards, schema mismatch, breaking changes, race conditions | Fix before merge |229| ⚠️ MEDIUM | Quality | Weak crypto, poor error handling, type safety, duplication | Fix if reasonable |230| 💡 LOW | Polish | Suggestions, optimization, style | Consider optional |231232## Common Issues & Fixes233234### Security Issues235236| Pattern | Fix |237| -------------------------------- | ---------------------------------------------------- |238| `const secret = "hardcoded-key"` | Move to `process.env.SECRET` or OCI Vault |239| SQL string concat | Use `SELECT * FROM users WHERE id = ?` with bindings |240| `{@html userContent}` | Use `{@html DOMPurify.sanitize(userContent)}` |241| No auth guard | Add `preHandler: [fastify.authenticate]` |242| `console.log(token)` | Remove or use safe logger without secrets |243244### Architecture Issues245246| Pattern | Fix |247| ----------------------------- | -------------------------------------------------- |248| `await fastify.db.query(...)` | Use `await request.repos.entity.method(ctx)` |249| Missing DbContext | Pass user ID context to all DB operations |250| `export let prop` (Svelte) | Use `let { prop } = $props()` (Svelte 5) |251| Wrong status code | 201 for create, 204 for delete, 400 for validation |252| `any` type | Define explicit type or `unknown` with type guard |253254### Code Quality Issues255256| Pattern | Fix |257| ----------------------- | ------------------------------------------ |258| `console.log()` in prod | Remove or use proper logging layer |259| `MD5.hash()` | Use `crypto.subtle.digest('SHA-256', ...)` |260| No test coverage | Add test for new behavior/branch |261| Duplicate logic | Extract to reusable function/component |262| N+1 queries | Batch queries or use database join |263264## Tips for Efficiency2652661. **Fix Semgrep First**267 - Patterns are deterministic and quick to verify268 - No ambiguity in fixes269 - Fail fast mentality2702712. **Read CodeRabbit Carefully**272 - It provides context and reasoning273 - Use inline comments for clarification274 - Ask it to explain if unclear2752763. **Batch Similar Fixes**277 - Don't context-switch between issue types278 - Fix all secret issues, then auth issues, etc.279 - Run unit tests after each batch2802814. **Maximum 3 Passes**282 - If you need more than 3 review cycles, break into smaller PRs283 - Each cycle should be more targeted2842855. **Test as You Go**286 - Run unit tests after each fix batch287 - Verify Semgrep passes immediately288 - Run CodeRabbit once before committing289290## Related Skills & References291292- **Plugin:** `opencode-semgrep-coderabbit-plugin` (provides tools for this skill)293- **Docs:** `AGENTS.md`, `.semgrep.yaml`, `.coderabbit.yaml`294- **Repository Pattern:** `packages/database/src/repositories/`295- **API Examples:** `apps/api/src/routes/`296297## Troubleshooting298299| Issue | Cause | Solution |300| ------------------------- | ------------------------------------ | --------------------------------------------------------------- |301| Semgrep takes >30s | Large change set or complex patterns | Run on smaller subset or filter by rule |302| CodeRabbit takes >30min | Very large changes (>500 lines) | Break into smaller PRs |303| Too many findings | Code quality debt accumulation | Fix critical/high, schedule follow-up for medium/low |304| Same issue on re-run | Fix incomplete or misunderstood | Read feedback again, ask CodeRabbit for clarification |305| Semgrep false positives | Rule too broad or context-specific | Review rule definition, can mark as intended if safe |306| Conflicting tool feedback | Tools have different perspectives | Trust Semgrep (deterministic), validate CodeRabbit with context |307308## Next Steps3093101. **Load this skill:** Use `/skill semgrep-coderabbit-review` in OpenCode3112. **Install plugin:** Install `opencode-semgrep-coderabbit-plugin` for tools3123. **Run review:** Use one of the provided commands3134. **Follow workflow:** Stage 1 (Semgrep) → Stage 2 (CodeRabbit) → Fix → Verify3145. **Share feedback:** Help improve this skill for your team315316## Questions?317318- Check the plugin README for detailed usage319- Review `.semgrep.yaml` for specific rule definitions320- Check `.coderabbit.yaml` for CodeRabbit configuration321- Ask CodeRabbit inline if feedback is unclear322- Open an issue on the plugin repository323324---325326**Version:** 1.0 327**Last Updated:** Jan 22, 2026 328**Status:** Production Ready 329**Plugin Required:** opencode-semgrep-coderabbit-plugin >= 1.0.0