CodeQL, Semgrep and SARIF static-analysis toolkit from Trail of Bits: taint tracking, fast pattern scans and merged, deduplicated security findings for coding agents.
Static Analysis
Finding bugs and vulnerabilities by inspecting source code without running it.
5 skills and 3 MCP servers tagged Static Analysis.
Skills
Skill: Zeroize Audit
by Trail of Bits
Finds secrets left in memory in C, C++ and Rust — including wipes the compiler deleted — and requires IR or assembly evidence before calling one optimized away.
Skill: Constant-Time Analysis
by Trail of Bits
Compiles cryptographic code and reads the emitted assembly for variable-time instructions, then triages which flagged operations actually touch secrets.
Skill: CodeQL Security Analysis
by Trail of Bits
Trail of Bits' CodeQL skill: build databases, run taint-tracking and data-flow queries across eight languages, and model project-specific sources and sinks.
Skill: Semgrep Rule Creator
by Trail of Bits
Trail of Bits' skill for writing production-quality Semgrep rules — pattern design, taint mode for data-flow bugs, and mandatory test-driven validation.
MCP servers
Red Hat's zero-dependency C++23 code-context engine — ranked call graphs and blast-radius analysis, indexing a repo in under half a second with no server and no database.
MCP: Semgrep MCP
by Semgrep
Semgrep's official MCP server — scan code for security vulnerabilities, write and test custom rules, and pull findings from Semgrep Cloud, from inside an agent session.
MCP: SonarQube MCP Server
by SonarSource
Official SonarSource MCP server — pull code-quality issues, security hotspots, quality gates and rule explanations from SonarQube Cloud or Server into your agent.
Related tags
Tags that appear alongside this one, ranked by how often.