CodeQL, Semgrep and SARIF static-analysis toolkit from Trail of Bits: taint tracking, fast pattern scans and merged, deduplicated security findings for coding agents.
Semgrep
Semgrep-based static analysis: writing and testing custom rules, running published rulesets, and wiring pattern-based vulnerability detection into review and CI.
2 skills and 1 MCP server tagged Semgrep.
Skills
11 views
Skill: Semgrep Rule Creator
by Trail of Bits
Trail of Bits' skill for writing production-quality Semgrep rules — pattern design, taint mode for data-flow bugs, and mandatory test-driven validation.
9 views
MCP servers
MCP: Semgrep MCP
by Semgrep
Semgrep's official MCP server — scan code for security vulnerabilities, write and test custom rules, and pull findings from Semgrep Cloud, from inside an agent session.
9 views
Related tags
Tags that appear alongside this one, ranked by how often.