Scan for vulnerabilities
Find security flaws across thirty languages.
Equip your AI coding agents with Agent Skills to scan codebases for security vulnerabilities.
Official Agent Skills published by Semgrep
Run fast static analysis checks with Semgrep. Use these skills to enforce coding standards and detect injection flaws.
Find security flaws across thirty languages.
Official Agent Skills published by Semgrep.
Provides comprehensive security rules and best practices to identify and prevent vulnerabilities across 15+ programming languages and infrastructure configurations.
Secures AI applications by implementing OWASP Top 10 for LLM 2025 standards and proactive vulnerability mitigation.
Scans codebases for security vulnerabilities, identifies bug patterns, and enforces custom coding standards using fast, pattern-based static analysis.
Add Semgrep Skills to agents that support the Agent Skills format, including Claude, Claude Code, Codex, and OpenCode. Install manually from source, or use MCP Market Hub to sync and share them with your team.
Add official skills once, keep them current across your agents, and share the same skill set with your team.
Prefer manual control? Download the skills from source, then follow the install guide for your agent.
semgrep/agent-skillsReal workflows powered by Semgrep skills.
Enforce custom coding standards
Create custom YAML rules to block deprecated APIs and verify internal guidelines.
Automate codebase security audits
Run static analysis scans to detect injection flaws on untrusted code.
Create secure CI pipelines
Configure automated security guardrails inside your GitHub Actions pipelines.
Verified, first-party skills from other brands you know.