Run Semgrep static analysis for fast security scanning and pattern matching. Use when asked to scan code with Semgrep, write custom YAML rules, find vulnerabilities quickly, use taint mode, or set up Semgrep in CI/CD pipelines.
Trit: -1 (MINUS) Category: static-analysis Author: Trail of Bits Source: trailofbits/skills License: AGPL-3.0
Run Semgrep static analysis for fast security scanning and pattern matching. Use when asked to scan code with Semgrep, write custom YAML rules, find vulnerabilities quickly, use taint mode, or set up Semgrep in CI/CD pipelines.
This is a Trail of Bits security skill. Refer to the original repository for detailed usage guidelines and examples.
See: https://github.com/trailofbits/skills
This skill connects to Software Design for Flexibility (Hanson & Sussman, 2021):
Concepts: unification, match, segment variables, pattern
semgrep (+) + SDF.Ch4 (+) + [balancer] (+) = 0
Skill Trit: 1 (PLUS - generation)
Pattern matching extracts structure. This skill recognizes and transforms patterns.
Category:other