All skills
semgrep avatar

/code-security

@327da93 official
by semgrepsemgrep/skills317 stars
31

Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also use when users ask to 'review my code', 'check this for bugs', or 'is this safe'.

Use this Skill: https://skilld.dev/gh/semgrep/skills/code-security

This session only. Nothing lands on disk.

rulesperformance.md

≈874 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Performance Best Practices

This document covers performance optimizations to write efficient code. These rules identify patterns that cause unnecessary computational overhead, extra database queries, or memory inefficiency.


Python

Django - Access Foreign Keys Directly

Use ITEM.user_id rather than ITEM.user.id to prevent running an extra query. Accessing .user.id causes Django to fetch the entire related User object just to get the ID, when the foreign key ID is already available on the model.

INCORRECT - Extra query to fetch related object:

def get_user_id(item):
    return item.user.id

CORRECT - Use the foreign key directly:

def get_user_id(item):
    return item.user_id

SQLAlchemy - Use count() Instead of len(all())

Using QUERY.count() instead of len(QUERY.all()) sends less data to the client since the count is performed server-side. The len(all()) approach fetches all records into memory just to count them.

INCORRECT - Fetches all records into memory:

total = len(persons.all())

CORRECT - Count performed server-side:

total = persons.count()

SQLAlchemy - Batch Database Operations

Rather than adding one element at a time, use batch loading to improve performance. Looping db.session.add() increases session bookkeeping overhead and can trigger per-iteration SQL if autoflush is enabled (e.g., when a query runs during the loop).

INCORRECT - Adding one at a time in a loop:

for song in songs:
    db.session.add(song)

CORRECT - Batch add all at once:

db.session.add_all(songs)

JavaScript/TypeScript

React - Define Styled Components at Module Level

By declaring a styled component inside the render method, you dynamically create a new component on every render. This forces React to discard and re-calculate that part of the DOM subtree on each render, leading to performance bottlenecks.

INCORRECT - Styled component declared inside function:

import styled from "styled-components";

function FunctionalComponent() {
  const StyledDiv = styled.div`
    color: blue;
  `
  return <StyledDiv />
}

CORRECT - Styled component declared at module level:

import styled from "styled-components";

const StyledDiv = styled.div`
  color: blue;
`

function FunctionalComponent() {
  return <StyledDiv />
}

Avoid Unnecessary Operations in Loops

Hoist expensive work (object allocations, RegExp compilation, function creation) out of loops.

INCORRECT - RegExp compiled on every iteration:

for (const line of lines) {
  const match = line.match(new RegExp('\\d{4}-\\d{2}-\\d{2}'));
  if (match) results.push(match[0]);
}

CORRECT - Compile once, reuse in loop:

const datePattern = /\d{4}-\d{2}-\d{2}/;
for (const line of lines) {
  const match = line.match(datePattern);
  if (match) results.push(match[0]);
}

For operations that require iterating, prefer built-in methods that short-circuit:

INCORRECT - Full iteration to find one item:

const found = items.filter(x => x.id === targetId)[0];

CORRECT - Short-circuit on first match:

const found = items.find(x => x.id === targetId);

Source: SKILL.md on GitHub

2 warnings16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a comprehensive library of security guidelines and code examples to help AI agents write secure code and perform security reviews. It covers OWASP Top 10 vulnerabilities, infrastructure security (Terraform, Kubernetes, Docker), and general best practices. While the files contain examples of vulnerable code (such as SQL injection and hardcoded secrets), these are used exclusively for educational purposes to demonstrate what to avoid and are part of the 'Incorrect' examples within the security rules.

  • Socket16d

    2 alerts: gptSecurity

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    4/34 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 327da93. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 7 months ago
  • Security
  • Infrastructure
  • code-review
  • owasp
  • sql-injection
  • xss
  • command-injection
  • authentication
  • terraform
  • kubernetes
  • docker

README badge

README badge for semgrep/skills/code-security

Provides security rules across 15+ languages covering OWASP Top 10 vulnerabilities, infrastructure configuration, and secure coding practices. Includes SQL injection, XSS, command injection, cryptography, and Kubernetes/Terraform security with language-specific priority guidelines and rule files for detailed code examples.

Generated from the current SKILL.md.

Does this skill cover infrastructure security like Terraform and Kubernetes?
Yes. The skill includes 28 rule categories covering Terraform (AWS, Azure, GCP), Kubernetes, Docker, and GitHub Actions alongside language-specific rules for Python, JavaScript, Java, Go, C/C++, Ruby, and PHP.
When should I use this skill — only when the user asks about security?
No. The skill is designed for proactive mode: automatically check for vulnerabilities when writing or reviewing any code that handles user input, authentication, databases, file operations, network requests, cryptography, or infrastructure configuration — even if the user doesn't explicitly mention security.
What vulnerabilities does this skill prioritize?
It prioritizes Critical impact rules first: SQL injection, command injection, XSS, XXE, path traversal, insecure deserialization, code injection, hardcoded secrets, and memory safety. High impact rules include insecure crypto, SSRF, JWT issues, and CSRF.
Does this skill provide code examples for each vulnerability type?
Yes. Each rule category (e.g., `rules/sql-injection.md`) contains detailed vulnerable and secure code examples in the relevant language.

Generated from the current SKILL.md. These answers refresh after source changes.