home/categories/code-quality/trailofbits-skills-plugins-testing-handbook-skills-skills-semgrep-skill-md
code-qualitytesting-security

semgrep

Semgrep is a fast static analysis tool for finding bugs and enforcing code standards. Use when scanning code for security issues or integrating into CI/CD pipelines.

trailofbits
maintainer
trailofbits
更新于 1/19/2026
星标
1466
分支
113
quick start

Installation and usage

Semgrep is a fast static analysis tool for finding bugs and enforcing code standards. Use when scanning code for security issues or integrating into CI/CD pipelines.

安装
$ install --globalskills.sh
使用

安装后,您可以通过在终端运行以下命令来使用此技能:

skills use semgrep