All skills
semgrep avatar

/code-security

@327da93 official
by semgrepsemgrep/skills316 stars
31

Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also use when users ask to 'review my code', 'check this for bugs', or 'is this safe'.

Use this Skill: https://skilld.dev/gh/semgrep/skills/code-security

This session only. Nothing lands on disk.

rulescode-injection.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Prevent Code Injection

Code injection vulnerabilities occur when an attacker can insert and execute arbitrary code within your application. This includes direct code evaluation (eval, exec), reflection-based attacks, and dynamic method invocation. These vulnerabilities can lead to complete system compromise, data theft, and remote code execution.

Incorrect (Python - eval with user input):

def unsafe(request):
    code = request.POST.get('code')
    eval(code)

Correct (Python - avoid eval entirely, use safe alternatives):

import ast

def safe_parse(user_expr):
    # ast.literal_eval only allows literals (strings, numbers, tuples, lists, dicts, booleans, None)
    return ast.literal_eval(user_expr)

# For math expressions, use a purpose-built parser instead of eval

Note: Avoid eval()/exec() entirely. Even with hardcoded strings, it normalizes a dangerous pattern. Use ast.literal_eval() for parsing data literals, or purpose-built parsers for expressions.

Incorrect (JavaScript - eval with dynamic content):

let dynamic = window.prompt()

eval(dynamic + 'possibly malicious code');

function evalSomething(something) {
    eval(something);
}

Correct (JavaScript - avoid eval, use safe alternatives):

// Instead of eval for JSON parsing:
const data = JSON.parse(jsonString);

// Instead of eval for dynamic property access:
const value = obj[propertyName];

// Instead of eval for math: use a sandboxed expression parser

Note: There is almost never a legitimate reason to use eval(). Use JSON.parse(), computed property access, or a sandboxed parser. Avoid new Function() as well — it executes arbitrary code just like eval().

Incorrect (Java - ScriptEngine injection):

public class ScriptEngineSample {

    private static ScriptEngineManager sem = new ScriptEngineManager();
    private static ScriptEngine se = sem.getEngineByExtension("js");

    public static void scripting(String userInput) throws ScriptException {
        Object result = se.eval("test=1;" + userInput);
    }
}

Correct (Java - static ScriptEngine evaluation):

public class ScriptEngineSample {

    public static void scriptingSafe() throws ScriptException {
        ScriptEngineManager scriptEngineManager = new ScriptEngineManager();
        ScriptEngine scriptEngine = scriptEngineManager.getEngineByExtension("js");
        String code = "var test=3;test=test*2;";
        Object result = scriptEngine.eval(code);
    }
}

Incorrect (Ruby - dangerous eval):

b = params['something']
eval(b)
eval(params['cmd'])

Correct (Ruby - static eval):

eval("def zen; 42; end")

class Thing
end
a = %q{def hello() "Hello there!" end}
Thing.module_eval(a)

Incorrect (PHP - code injection via eval/assert):

$code = $_GET['code'];
eval($code);

$input = $_POST['input'];
assert($input);  // assert() evaluates strings as code in PHP < 8.0

Correct (PHP - avoid eval, use structured alternatives):

// Instead of eval for dynamic config, use a data format:
$config = json_decode(file_get_contents('config.json'), true);

// Instead of eval for templates, use a template engine (Twig, Blade)

Note: exec()/shell_exec()/system() are OS command execution — see the command-injection rule for those. This rule covers code evaluation via eval(), assert(), preg_replace with /e, and similar.

Key Prevention Patterns

  1. Avoid eval/exec entirely - Use safer alternatives (JSON.parse, ast.literal_eval, template engines, computed property access)
  2. Never pass user input to code evaluation functions - Treat all user input as untrusted
  3. If dynamic code execution is unavoidable - Validate against a strict allowlist and sandbox the execution
  4. Use parameterized alternatives - Most languages offer structured APIs that eliminate the need for eval

For OS command execution (exec, shell_exec, system) and shell-escaping (escapeshellarg), see the command-injection rule.

References

Source: SKILL.md on GitHub

2 warnings16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive library of security guidelines and code examples to help AI agents write secure code and perform security reviews. It covers OWASP Top 10 vulnerabilities, infrastructure security (Terraform, Kubernetes, Docker), and general best practices. While the files contain examples of vulnerable code (such as SQL injection and hardcoded secrets), these are used exclusively for educational purposes to demonstrate what to avoid and are part of the 'Incorrect' examples within the security rules.

  • Socket16d

    2 alerts: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    4/34 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 327da93. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 7 months ago
  • Security
  • Infrastructure
  • code-review
  • owasp
  • sql-injection
  • xss
  • command-injection
  • authentication
  • terraform
  • kubernetes
  • docker

README badge

README badge for semgrep/skills/code-security

Provides security rules across 15+ languages covering OWASP Top 10 vulnerabilities, infrastructure configuration, and secure coding practices. Includes SQL injection, XSS, command injection, cryptography, and Kubernetes/Terraform security with language-specific priority guidelines and rule files for detailed code examples.

Generated from the current SKILL.md.

Does this skill cover infrastructure security like Terraform and Kubernetes?
Yes. The skill includes 28 rule categories covering Terraform (AWS, Azure, GCP), Kubernetes, Docker, and GitHub Actions alongside language-specific rules for Python, JavaScript, Java, Go, C/C++, Ruby, and PHP.
When should I use this skill — only when the user asks about security?
No. The skill is designed for proactive mode: automatically check for vulnerabilities when writing or reviewing any code that handles user input, authentication, databases, file operations, network requests, cryptography, or infrastructure configuration — even if the user doesn't explicitly mention security.
What vulnerabilities does this skill prioritize?
It prioritizes Critical impact rules first: SQL injection, command injection, XSS, XXE, path traversal, insecure deserialization, code injection, hardcoded secrets, and memory safety. High impact rules include insecure crypto, SSRF, JWT issues, and CSRF.
Does this skill provide code examples for each vulnerability type?
Yes. Each rule category (e.g., `rules/sql-injection.md`) contains detailed vulnerable and secure code examples in the relevant language.

Generated from the current SKILL.md. These answers refresh after source changes.