implementing-semgrep-for-custom-sast-rules

mukul975/implementing-semgrep-for-custom-sast-rules · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines.

SKILL.md

Files

This skill is a package of 5 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 5.1 KB
  • 📄standards.md 1.1 KB
  • 📁scripts
  • ⚙️agent.py 7.6 KB
  • 📄LICENSE 11.0 KB

Related

  1. semgrep · comeonoliver
    Runs Semgrep static analysis to find bugs and security vulnerabilities, with guidance on installation, rule selection, custom rule writing, and CI/CD integration.
    61
    repo stars
  2. semgrep · trailofbits bundle
    Run Semgrep static analysis scans with automatic language detection, parallel subagent execution, and merged SARIF output. Supports full ruleset coverage or high-confidence security vulnerability filtering.
    6k
    repo stars
  3. integrating-sast-into-github-actions-pipeline · mukul975 bundle
    Integrates Static Application Security Testing (SAST) tools—CodeQL and Semgrep—into GitHub Actions CI/CD pipelines, configuring automated code scanning, tuning rules, uploading SARIF results, and establishing quality gates that block merges on high-severity vulnerabilities.
    24.6k
    repo stars
  4. sarif-parsing · trailofbits bundle
    Parse, analyze, and process SARIF files from static analysis tools like CodeQL and Semgrep, including filtering, deduplication, aggregation, and CI/CD integration.
    6k
    repo stars
  5. security-reviewer · jeffallan bundle
    Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance for code, infrastructure, and cloud environments.
    10.4k
    repo stars
  6. codebase · shulkwisec bundle
    Performs a white-box source code security review structured around OWASP ASVS 5.0, mapping attack surfaces, tracing data flows, and chaining into downstream penetration testing and threat modeling skills.
    21
    repo stars

Frequently asked questions

How do I install the implementing-semgrep-for-custom-sast-rules skill?

Run npx skillmds add mukul975/implementing-semgrep-for-custom-sast-rules in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the implementing-semgrep-for-custom-sast-rules skill do?

Write custom Semgrep SAST rules in YAML to detect application-specific vulnerabilities, enforce coding standards, and integrate into CI/CD pipelines. It is listed under Security, DevOps & Infra, CI/CD, Secure Coding on SkillMD.

Is implementing-semgrep-for-custom-sast-rules safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with implementing-semgrep-for-custom-sast-rules?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is implementing-semgrep-for-custom-sast-rules free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published implementing-semgrep-for-custom-sast-rules?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.