semgrep/skills

COLLECTIONcommunity
semgrepNOASSERTIONUpdated 25d agoGitHub

A collection of skills for AI coding agents from Semgrep

A collection of skills for AI coding agents. Skills are packaged instructions and scripts that extend agent capabilities. This should be considered beta-level software; it's primarily generated by transforming open-source Semgrep rules into skill format. Skills follow the Agent Skills format. Comprehensive code security guidelines from Semgrep Engineering covering OWASP Top 10, infrastructure…

This collection bundles
3 skills

⚠ The trust score below reflects the collection's repository only. The bundled units are not individually verified or scanned — review them before use.

Automatically indexed from public sources. Not yet verified by the developer on Forge.Claim this listing →
227GitHub stars
29Forks
25d agoLast update
Package
Authorsemgrep
LicenseNOASSERTION
Sourcegithub
Trust Status
B
60/100Good
Listed in Forge index+10/10
Publisher identity verified+0/25
Publisher: run `forge publish` from the package repo to claim ownership
Ed25519 publish signature+0/10
Included automatically when the publisher runs `forge publish`
Domain verification+0/5
Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
CVE scan · not run+0/30
Not yet scanned — package must be on npm
Static analysis · clean+20/20
npm provenance (Sigstore)+0/5
Publish from GitHub Actions with the --provenance flag
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusCommunity-indexed
PublisherUnverified
SignatureUnsigned
Domain
Provenance
DependenciesNot audited
Tool surface
Security scan✓ CleanvHEAD · 19d ago
EvalsNone
IndexedJun 14, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.

About

A collection of skills for AI coding agents. Skills are packaged instructions and scripts that extend agent capabilities. This should be considered beta-level software; it's primarily generated by transforming open-source Semgrep rules into skill format. Skills follow the Agent Skills format. Comprehensive code security guidelines from Semgrep Engineering covering OWASP Top 10, infrastructure security, and secure coding best practices across 15+ languages. Reviewing code for security…

Keywords
agentsclaude-codesecurityskillscollection