---
title: "semgrep&#x2F;skills skills · skilld"
canonical_url: "https://skilld.dev/gh/semgrep/skills"
meta:
  description: "A collection of skills for AI coding agents from Semgrep"
  "og:description": "A collection of skills for AI coding agents from Semgrep"
  "og:title": "semgrep/skills skills"
  "twitter:description": "A collection of skills for AI coding agents from Semgrep"
  "twitter:title": "semgrep/skills skills"
---

`

[All skills](https://skilld.dev/skills)

[![semgrep avatar](https://skilld.dev/_img/avatar?url=https%3A%2F%2Fgithub.com%2Fsemgrep.png)](https://skilld.dev/gh/semgrep)

# **semgrep/skills**

A collection of skills for AI coding agents from Semgrep

main Updated 2 months ago [GitHub](https://github.com/semgrep/skills)

![README badge for semgrep/skills](https://skilld.dev/b/semgrep/skills?theme=light&label=0)

## Repository statistics

- Indexed skills

  **3**
- Skill groups

  **1**
- GitHub stars

  **317**
- Forks

  **31**

## Skills

3 total

Sort skills

[<h3>**/code-security**</h3>Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also use when users ask to 'review my code', 'check this for bugs', or 'is this safe'. /code-security](https://skilld.dev/gh/semgrep/skills/code-security)

Updated 7 months ago

[<h3>**/llm-security**</h3>Security guidelines for LLM applications based on OWASP Top 10 for LLM 2025. Use when building LLM apps, reviewing AI security, implementing RAG systems, or asking about LLM vulnerabilities like 'prompt injection' or 'check LLM security'. IMPORTANT: Always consult this skill when building chatbots, AI agents, RAG pipelines, tool-using LLMs, agentic systems, or any application that calls an LLM API (OpenAI, Anthropic, Gemini, etc.) — even if the user doesn't explicitly mention security. Also use when users import 'openai', 'anthropic', 'langchain', 'llamaindex', or similar LLM libraries. /llm-security](https://skilld.dev/gh/semgrep/skills/llm-security)

Updated 7 months ago

[<h3>**/semgrep**</h3>Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code quality', 'find vulnerabilities', 'static analysis', 'lint for security', 'audit this code', or want to enforce coding standards — even if they don't mention Semgrep by name. Semgrep is the right tool for pattern-based code scanning across 30+ languages. /semgrep](https://skilld.dev/gh/semgrep/skills/semgrep)

Updated 7 months ago

## Add to your README

The badge links readers to this page. It shows the skilld mark and no counts, and it follows the reader's light or dark GitHub theme.

`<a href="https://skilld.dev/gh/semgrep/skills"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://skilld.dev/b/semgrep/skills?theme=dark"> <source media="(prefers-color-scheme: light)" srcset="https://skilld.dev/b/semgrep/skills?theme=light"> <img alt="Skill repository on skilld.dev" src="https://skilld.dev/b/semgrep/skills?theme=light"> </picture> </a>`