{"repo":"semgrep/skills","free":true,"listed":false,"github":"https://github.com/semgrep/skills","clone":"git clone https://github.com/semgrep/skills.git","description":"A collection of skills for AI coding agents from Semgrep","language":"JavaScript","stars":268,"topics":["agents","claude-code","security","skills"],"license":null,"category":"security-tools","readme_excerpt":"Agent Skills [Beta] A collection of skills for AI coding agents. Skills are packaged instructions and scripts that extend agent capabilities. This should be considered beta-level software; it's primarily generated by transforming open-source Semgrep rules into skill format. Skills follow the Agent Skills format. Installation Available Skills code-security Comprehensive code security guidelines from Semgrep Engineering covering OWASP Top 10, infrastructure security, and secure coding best practices across 15+ languages. Use when: - Writing new code - Reviewing code for security vulnerabilities - Asking about secure coding practices - Configuring cloud infrastructure (Terraform, Kubernetes, Docker) Categories covered: Impact Category Description -------- ---------- ------------- Critical SQL Injection Parameterized queries, ORM safety Critical Command Injection Shell command safety, input validation Critical Cross-Site Scripting (XSS) Output encoding, DOM safety Critical XML External Entity (XXE) XML parser configuration Critical Path Traversal File path validation Critical Insecure Deserialization Safe deserialization patterns Critical Code Injection Eval safety, template injection Critical Hardcoded Secrets Environment variables, secret management Critical Memory Safety Buffer overflows, use-after-free (C/C++) High Insecure Cryptography Strong hashing (SHA-256+), encryption (AES) High Insecure Transport HTTPS, certificate validation, TLS High Server-Side Request Forgery URL v","default_branch":null,"files":null,"tree":[],"storefront":"/r/semgrep","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/semgrep/skills/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}