All skills
semgrep avatar

/code-security

@327da93 official
by semgrepsemgrep/skills317 stars
31

Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also use when users ask to 'review my code', 'check this for bugs', or 'is this safe'.

Use this Skill: https://skilld.dev/gh/semgrep/skills/code-security

This session only. Nothing lands on disk.

rulesgithub-actions.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Secure GitHub Actions

GitHub Actions workflows can be vulnerable to several security issues including script injection, secrets exposure, and supply chain attacks. Attackers who exploit these vulnerabilities can steal repository secrets, inject malicious code, or compromise the entire CI/CD pipeline.

Key Security Risks

  1. Script Injection: Using untrusted input (like PR titles or issue bodies) directly in run: commands allows attackers to inject arbitrary code
  2. Privileged Triggers: pull_request_target and workflow_run events run with elevated privileges, making checkout of untrusted code dangerous
  3. Supply Chain: Third-party actions not pinned to commit SHAs can be compromised

Run Shell Injection (CWE-78)

Using variable interpolation ${{...}} with github context data in a run: step could allow an attacker to inject their own code into the runner. This would allow them to steal secrets and code.

Incorrect (vulnerable to script injection via PR title):

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Check PR title
        run: |
          title="${{ github.event.pull_request.title }}"
          echo "$title"

Correct (use environment variable):

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Check PR title
        env:
          PR_TITLE: ${{ github.event.pull_request.title }}
        run: |
          echo "$PR_TITLE"

Fix: Use an intermediate environment variable with env: to store the data and use the environment variable in the run: script. Be sure to use double-quotes around the environment variable.

References: GitHub Actions Security Hardening - Script Injections


Pull Request Target Code Checkout (CWE-913)

When using pull_request_target, the Action runs in the context of the target repository with access to all repository secrets. Checking out the incoming PR code while having access to secrets is dangerous because you may inadvertently execute arbitrary code from the incoming PR.

Incorrect (checking out PR code with pull_request_target):

on:
  pull_request_target:

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v2
        with:
          ref: ${{ github.event.pull_request.head.sha }}
      - run: npm install && npm build

Correct (no checkout of PR code):

on:
  pull_request_target:

jobs:
  safe-job:
    runs-on: ubuntu-latest
    steps:
      - name: echo
        run: echo "Hello, world"

References: GitHub Actions Preventing Pwn Requests


Workflow Run Target Code Checkout (CWE-913)

Similar to pull_request_target, when using workflow_run, the Action runs in the context of the target repository with access to all repository secrets. Checking out incoming PR code with this trigger is dangerous.

Incorrect (checking out PR code with workflow_run):

on:
  workflow_run:
    workflows: ["CI"]
    types: [completed]

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v2
        with:
          ref: ${{ github.event.workflow_run.head.sha }}
      - run: npm install

Correct (no checkout of PR code):

on:
  workflow_run:
    workflows: ["CI"]
    types: [completed]

jobs:
  safe-job:
    runs-on: ubuntu-latest
    steps:
      - run: echo "Safe operation"

References: GitHub Privilege Escalation Vulnerability


Third-Party Action Not Pinned to Commit SHA (CWE-1357)

An action sourced from a third-party repository on GitHub is not pinned to a full length commit SHA. Pinning an action to a full length commit SHA is currently the only way to use an action as an immutable release.

Incorrect (using tag reference):

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: fakerepo/comment-on-pr@v1
        with:
          message: "Thank you!"

Correct (pinned to full commit SHA):

jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - uses: fakerepo/comment-on-pr@5fd3084fc36e372ff1fff382a39b10d03659f355
        with:
          message: "Thank you!"

Note: GitHub-owned actions (actions/*, github/*) and local actions (./.github/actions/*) don't require SHA pinning.

References: GitHub Actions Security Hardening - Using Third-Party Actions


References:

Source: SKILL.md on GitHub

2 warnings16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive library of security guidelines and code examples to help AI agents write secure code and perform security reviews. It covers OWASP Top 10 vulnerabilities, infrastructure security (Terraform, Kubernetes, Docker), and general best practices. While the files contain examples of vulnerable code (such as SQL injection and hardcoded secrets), these are used exclusively for educational purposes to demonstrate what to avoid and are part of the 'Incorrect' examples within the security rules.

  • Socket16d

    2 alerts: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    4/34 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 327da93. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 7 months ago
  • Security
  • Infrastructure
  • code-review
  • owasp
  • sql-injection
  • xss
  • command-injection
  • authentication
  • terraform
  • kubernetes
  • docker

README badge

README badge for semgrep/skills/code-security

Provides security rules across 15+ languages covering OWASP Top 10 vulnerabilities, infrastructure configuration, and secure coding practices. Includes SQL injection, XSS, command injection, cryptography, and Kubernetes/Terraform security with language-specific priority guidelines and rule files for detailed code examples.

Generated from the current SKILL.md.

Does this skill cover infrastructure security like Terraform and Kubernetes?
Yes. The skill includes 28 rule categories covering Terraform (AWS, Azure, GCP), Kubernetes, Docker, and GitHub Actions alongside language-specific rules for Python, JavaScript, Java, Go, C/C++, Ruby, and PHP.
When should I use this skill — only when the user asks about security?
No. The skill is designed for proactive mode: automatically check for vulnerabilities when writing or reviewing any code that handles user input, authentication, databases, file operations, network requests, cryptography, or infrastructure configuration — even if the user doesn't explicitly mention security.
What vulnerabilities does this skill prioritize?
It prioritizes Critical impact rules first: SQL injection, command injection, XSS, XXE, path traversal, insecure deserialization, code injection, hardcoded secrets, and memory safety. High impact rules include insecure crypto, SSRF, JWT issues, and CSRF.
Does this skill provide code examples for each vulnerability type?
Yes. Each rule category (e.g., `rules/sql-injection.md`) contains detailed vulnerable and secure code examples in the relevant language.

Generated from the current SKILL.md. These answers refresh after source changes.