Sast Semgrep · AgentSecOps/SecOpsAgentKit

Scan code for security bugs with Semgrep

Runs Semgrep static analysis across multiple languages to catch security vulnerabilities, review pull requests for risky changes, and map findings to OWASP Top 10 and CWE categories, with support for custom organization-specific rules.

Good for

  • Scan changed files in a pull request for vulnerabilities
  • Map findings to OWASP Top 10 and CWE
  • Write a custom Semgrep rule for an internal pattern
Category
Coding

Open-source skills are maintained by their authors and listed as published, with attribution. Results depend on how well the skill fits your task and material.

A good place to start

Run Semgrep on the files changed in this PR and flag any high-severity security issues.

Make your next great thing.

Bring a question, a file, or an idea that’s not quite there yet.