home/categories/code-quality/trailofbits-skills-plugins-testing-handbook-skills-skills-semgrep-skill-md
code-qualitytesting-security
semgrep
Semgrep is a fast static analysis tool for finding bugs and enforcing code standards. Use when scanning code for security issues or integrating into CI/CD pipelines.
maintainer
trailofbits
Updated 1/19/2026
Stars
1466
Forks
113
quick start
Installation and usage
Semgrep is a fast static analysis tool for finding bugs and enforcing code standards. Use when scanning code for security issues or integrating into CI/CD pipelines.
Installation
$ install --globalskills.sh
Usage
Once installed, you can use this skill by running the following command in your terminal:
skills use semgrep