All skills
semgrep avatar

/code-security

@327da93 official
by semgrepsemgrep/skills316 stars
31

Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also use when users ask to 'review my code', 'check this for bugs', or 'is this safe'.

Use this Skill: https://skilld.dev/gh/semgrep/skills/code-security

This session only. Nothing lands on disk.

rulesinsecure-crypto.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Avoid Insecure Cryptography

Using weak or broken cryptographic algorithms puts sensitive data at risk. Attackers can exploit known vulnerabilities in deprecated algorithms to decrypt data, forge signatures, or predict "random" values.

Key vulnerabilities:

  • Weak hashing: MD5 and SHA1 are vulnerable to collision attacks
  • Weak encryption: DES is deprecated due to small key/block sizes

References: CWE-327 (Broken Crypto Algorithm), CWE-328 (Weak Hash), CWE-326 (Inadequate Encryption Strength)


Python

Incorrect (MD5/SHA1 hashing):

import hashlib

hash_val = hashlib.md5(data).hexdigest()
hash_val = hashlib.sha1(data).hexdigest()

Correct (SHA256 hashing):

import hashlib

hash_val = hashlib.sha256(data).hexdigest()

Incorrect (DES cipher):

from Crypto.Cipher import DES

key = b'-8B key-'
cipher = DES.new(key, DES.MODE_CTR, counter=ctr)

Correct (AES cipher):

from Crypto.Cipher import AES

key = b'Sixteen byte key'
cipher = AES.new(key, AES.MODE_EAX, nonce=nonce)

JavaScript

Incorrect (MD5 hashing):

const crypto = require("crypto");

function hashPassword(pwtext) {
    return crypto.createHash("md5").update(pwtext).digest("hex");
}

Correct (bcrypt for password hashing):

const bcrypt = require("bcrypt");

async function hashPassword(pwtext) {
    return bcrypt.hash(pwtext, 12);
}

async function verifyPassword(pwtext, hash) {
    return bcrypt.compare(pwtext, hash);
}

Note: SHA-256/SHA-512 are fine for data integrity but too fast for password hashing. Use bcrypt, scrypt, or Argon2 for passwords.


Java

Incorrect (MD5/SHA1 hashing):

import java.security.MessageDigest;

MessageDigest md5 = MessageDigest.getInstance("MD5");
md5.update(password.getBytes());
byte[] hash = md5.digest();

MessageDigest sha1 = MessageDigest.getInstance("SHA-1");

Correct (BCrypt for password hashing):

import org.springframework.security.crypto.bcrypt.BCryptPasswordEncoder;

BCryptPasswordEncoder encoder = new BCryptPasswordEncoder();
String hash = encoder.encode(password);
boolean matches = encoder.matches(password, hash);

Note: MessageDigest (SHA-256/SHA-512) is appropriate for data integrity checks but not for password storage. Use BCrypt, scrypt, or Argon2 for passwords.

Incorrect (DES cipher):

Cipher c = Cipher.getInstance("DES/ECB/PKCS5Padding");
c.init(Cipher.ENCRYPT_MODE, k);

Correct (AES with GCM):

Cipher c = Cipher.getInstance("AES/GCM/NoPadding");
c.init(Cipher.ENCRYPT_MODE, k, iv);

Go

Incorrect (MD5 hashing):

import (
    "crypto/md5"
    "fmt"
)

func hashData(data []byte) {
    h := md5.New()
    h.Write(data)
    fmt.Printf("%x", h.Sum(nil))
}

Correct (SHA256 hashing):

import (
    "crypto/sha256"
    "fmt"
)

func hashData(data []byte) {
    h := sha256.New()
    h.Write(data)
    fmt.Printf("%x", h.Sum(nil))
}

Incorrect (DES cipher):

import "crypto/des"

func encrypt() {
    key := []byte("example key 1234")
    block, _ := des.NewCipher(key[:8])
}

Correct (AES cipher):

import "crypto/aes"

func encrypt() {
    key := []byte("example key 12345678901234567890")
    block, _ := aes.NewCipher(key[:32])
}

Remediation Summary

Language Weak Algorithm Secure Alternative
Python hashlib.md5, hashlib.sha1 hashlib.sha256, hashlib.sha512
Python DES.new() AES.new() with EAX/GCM mode
JavaScript createHash("md5") createHash("sha256")
Java getInstance("MD5"), getInstance("SHA-1") getInstance("SHA-512")
Java getInstance("DES") getInstance("AES/GCM/NoPadding")
Go crypto/md5, crypto/sha1 crypto/sha256, crypto/sha512
Go crypto/des crypto/aes

Best Practices

  1. Hashing: Use SHA-256 or SHA-512 for general hashing. For passwords, use bcrypt, scrypt, or Argon2.
  2. Encryption: Use AES with authenticated modes (GCM, EAX). Avoid ECB mode.
  3. Key sizes: RSA keys should be at least 2048 bits. AES keys should be 256 bits.
  4. Random numbers: Use cryptographically secure random number generators for security-sensitive operations.

Source: SKILL.md on GitHub

2 warnings16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive library of security guidelines and code examples to help AI agents write secure code and perform security reviews. It covers OWASP Top 10 vulnerabilities, infrastructure security (Terraform, Kubernetes, Docker), and general best practices. While the files contain examples of vulnerable code (such as SQL injection and hardcoded secrets), these are used exclusively for educational purposes to demonstrate what to avoid and are part of the 'Incorrect' examples within the security rules.

  • Socket16d

    2 alerts: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    4/34 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 327da93. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 7 months ago
  • Security
  • Infrastructure
  • code-review
  • owasp
  • sql-injection
  • xss
  • command-injection
  • authentication
  • terraform
  • kubernetes
  • docker

README badge

README badge for semgrep/skills/code-security

Provides security rules across 15+ languages covering OWASP Top 10 vulnerabilities, infrastructure configuration, and secure coding practices. Includes SQL injection, XSS, command injection, cryptography, and Kubernetes/Terraform security with language-specific priority guidelines and rule files for detailed code examples.

Generated from the current SKILL.md.

Does this skill cover infrastructure security like Terraform and Kubernetes?
Yes. The skill includes 28 rule categories covering Terraform (AWS, Azure, GCP), Kubernetes, Docker, and GitHub Actions alongside language-specific rules for Python, JavaScript, Java, Go, C/C++, Ruby, and PHP.
When should I use this skill — only when the user asks about security?
No. The skill is designed for proactive mode: automatically check for vulnerabilities when writing or reviewing any code that handles user input, authentication, databases, file operations, network requests, cryptography, or infrastructure configuration — even if the user doesn't explicitly mention security.
What vulnerabilities does this skill prioritize?
It prioritizes Critical impact rules first: SQL injection, command injection, XSS, XXE, path traversal, insecure deserialization, code injection, hardcoded secrets, and memory safety. High impact rules include insecure crypto, SSRF, JWT issues, and CSRF.
Does this skill provide code examples for each vulnerability type?
Yes. Each rule category (e.g., `rules/sql-injection.md`) contains detailed vulnerable and secure code examples in the relevant language.

Generated from the current SKILL.md. These answers refresh after source changes.