Semgrep security scan with approval-gated workflow
Detect languages, select official plus third-party rulesets, present a scan plan for explicit approval, then run parallel Semgrep scans merged to SARIF
- What
- Detect languages, select official plus third-party rulesets, present a scan plan for explicit approval, then run parallel Semgrep scans merged to SARIF
- Cost
- Free
- Needs
- Semgrep CLI installed (semgrep --version); Semgrep Pro optional but recommended for cross-file taint analysis; only scan code you own or are authorized to audit
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security testing tool: only scan codebases you own or are authorized to audit.** @trailofbits' opinionated Semgrep workflow: automatic language detection with a Semgrep Pro availability check (cross-file taint tracking catches far more true positives), selection from a curated ruleset catalog where third-party rulesets (Trail of Bits, 0xdea, Decurity) are mandatory, a hard approval gate on the exact scan plan before anything runs, execution through `run-scans.sh` that enforces `--metrics=off` (no telemetry leakage during audits) and parallel batching, then post-filtering and a SARIF merge — with two modes ("run all" for full coverage, "important only" for medium-to-high confidence security findings) and strict reporting of failed, skipped or partial scans. By @trailofbits, listed here with credit to its creator. Honest caveats: requires the Semgrep CLI installed (Pro optional but recommended); Pro is slower per ruleset. License CC-BY-SA-4.0. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: Semgrep CLI installed (semgrep --version); Semgrep Pro optional but recommended for cross-file taint analysis; only scan code you own or are authorized to audit Install "Semgrep security scan with approval-gated workflow" for me. It gives the agent @trailofbits' Semgrep discipline: detect languages and check Pro availability, select official plus third-party rulesets, present the exact scan plan for explicit approval (hard gate), run every approved ruleset through scripts/run-scans.sh with --metrics=off in parallel, then post-filter, merge to SARIF, and report failures honestly. CC-BY-SA-4.0 licensed. Repository: https://github.com/trailofbits/skills/blob/main/plugins/static-analysis/skills/semgrep/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "semgrep". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install the Semgrep CLI and check Pro availability if you want cross-file analysis). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.