codeql-semgrep

codeql-semgrep is a skill for Claude Code, Codex from itallstartedwithaidea/agent-skills. It costs 34 tokens per session (1,576 once invoked), scanned A, original, MIT.

A guide for using CodeQL and Semgrep to inspect source code for security and code-quality problems. CodeQL analyzes relationships and data flow in a program, while Semgrep checks code patterns.

In plain words
What is it for?
Use it to write and run custom CodeQL queries and Semgrep rules, review findings, check project-specific practices, and plan fixes.
Why use it?
It helps find issues that simple text searches may miss and lets teams express rules specific to their own codebase.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/itallstartedwithaidea/agent-skills/codeql-semgrep
Any agent
npx skills add itallstartedwithaidea/agent-skills --skill codeql-semgrep
Clone the repo
git clone --depth 1 https://github.com/itallstartedwithaidea/agent-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for codeql-semgrep

README.md
[![agentmods](https://agentmods.dev/badge/skills/itallstartedwithaidea/agent-skills/codeql-semgrep.svg)](https://agentmods.dev/skills/itallstartedwithaidea/agent-skills/codeql-semgrep)
Your own site
<a href="https://agentmods.dev/skills/itallstartedwithaidea/agent-skills/codeql-semgrep"><img src="https://agentmods.dev/badge/skills/itallstartedwithaidea/agent-skills/codeql-semgrep.svg" alt="Measured on agentmods" height="20"></a>
Per session 34 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,576 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00034 $0.01576
Opus 5 $0.00017 $0.00788
Sonnet 5 $0.00007 $0.00315
Haiku 4.5 $0.00003 $0.00158

Measured 4d ago against content hash a6d9be1f425a, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

codeql-semgrep scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/security/codeql-semgrep/SKILL.md · 191 lines

How it starts

The opening of the file, as written. The whole thing — 191 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CodeQL & Semgrep

Part of Agent Skills™ by googleadsagent.ai™

Description

CodeQL & Semgrep integrates production-grade static analysis into agent workflows for deep vulnerability detection, custom rule authoring, and automated code review enforcement. The agent writes CodeQL queries and Semgrep rules tailored to project-specific patterns, runs them against codebases, and interprets results with actionable remediation guidance.

Pattern-matching security scanners catch surface-level issues. CodeQL and Semgrep operate at a deeper level: CodeQL builds a relational database of the program's structure and evaluates queries that trace data flow from sources (user input) to sinks (dangerous operations). Semgrep matches syntactic patterns with type-aware analysis. Together, they catch vulnerabilities that regex-based scanners miss entirely.

This skill goes beyond running default rulesets. The agent writes custom rules for project-specific patterns: ensuring all database queries use the project's ORM wrapper, verifying that authentication middleware is applied to every route, or confirming that error responses never leak stack traces. Custom rules encode institutional security knowledge that persists beyond any individual reviewer.

Use When

  • Running static analysis on AI-generated or human-written code
  • Writing custom security rules for project-specific patterns
  • Integrating security scanning into CI/CD pipelines
  • Tracing data flow from user input to dangerous operations
  • Enforcing architectural security constraints (auth on all routes, ORM usage)
  • The user requests "static analysis", "CodeQL", or "Semgrep"

How It Works

graph TD
    A[Codebase] --> B{Analysis Engine}
    B -->|Data Flow| C[CodeQL: Build Database]
    B -->|Pattern Match| D[Semgrep: Parse AST]
    C --> E[Run CodeQL Queries]
    D --> F[Run Semgrep Rules]
    E --> G[Taint Tracking: Source → Sink]
    F --> H[Pattern Matches + Metavariables]
    G --> I[Merge Findings]
    H --> I
    I --> J[Deduplicate + Prioritize]
    J --> K[Remediation Report]
    K --> L[CI/CD Gate: Pass/Fail]

Read the full file on GitHub · 191 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 191 lines · 34 tokens per session scan A a6d9be1f425a

Subscribe to this mod's changes

codeql-semgrep is a skill published in the GitHub repository itallstartedwithaidea/agent-skills (36 stars, last pushed 4mo ago), licensed MIT. It adds 34 tokens to every session and 1,576 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

update-saasmail

Sync the local saasmail repo with the latest upstream changes from https://github.com/choyiny/saasmail. Use this skill whenever the user wants to update saasmail, pull upstream changes, sync with upstream, rebase on upstream, get the latest saasmail, or says "/update-saasmail". Handles adding the upstream remote if…

choyiny/saasmail · 105 tokens

story-html-publisher

Final step of the AI Storybook pipeline. Consolidates the scenes, images, and per-scene audio into ONE self-contained HTML storybook — a swipe/tap player with every image and audio clip embedded as base64 so the single file works offline and can be shared as-is. Reads {slug}scenes.json, {slug}images.json, and…

hassancs91/claude-image-generation · 207 tokens

tracking-health

Preventive audit of conversion tracking across all configured ad platforms — Meta pixels + CAPI, Google Ads conversion actions, and final-URL tracking-parameter consistency on every platform — with a GA4 cross-check. Use when the user asks to check tracking, audit conversion measurement, verify pixels / tags, check…

logly/mureo · 168 tokens

learn

Save a marketing diagnosis insight to the pro-diagnosis knowledge base so it is applied in future operations across all platforms. Use when the user runs /learn, explicitly teaches the agent a marketing insight, corrects the agent's analysis, or asks to remember/record an operational learning for next time. Also use…

logly/mureo · 98 tokens

sealeap-amazon-product-targeting

Research, diagnose, and draft Amazon Ads ASIN and category product-targeting plans that complement keyword targeting, including audience expansion, competitor and category traffic, cross-sell, upsell, self-defense, negative targeting, placement analysis, and single-variable experiments. Use for 商品投放, ASIN 定向, 品类定向…

xjli360/sealeap-amazon-ad-skills · 168 tokens

weekly-report

Generate a weekly summary report across all platforms. Use when the user asks for a weekly report, summary, recap, end-of-week review, or weekly digest. Also use when the user asks in Japanese (週次レポート / 今週のまとめ / 週報を作成して).

logly/mureo · 63 tokens