semgrep skills

39 tagged semgrep, measured the same way as everything else here.

Browse within: sast 38appsec 35threat-modeling 32

cairo-auditor

01

keep-starknet-strange/starknet-agentic

Skill Claude CodeCodex

Security audit of Cairo/Starknet code. Trigger on "audit", "check this contract", "review for security". Modes - default (full repo), deep (+ adversarial reasoning), or specific filenames.

80 3d ago A 47 tokens original MIT

Cache Poisoning

02

allsmog/vuln-scout

Skill Claude CodeCodex

This skill should be used when the user asks about "cache poisoning", "web cache deception", "CDN cache", "proxy cache", "nginx cache", "varnish", "cache key manipulation", "response caching", or needs to find cache-related vulnerabilities during whitebox security review.

24 2mo ago A 64 tokens original MIT

allsmog/vuln-scout

Skill Claude CodeCodex

This skill should be used when the user is auditing a "polyglot monorepo", "multi-language codebase", "microservices with different languages", "Go + Python + TypeScript", or any codebase with services written in different programming languages. Provides strategies for cross-service security analysis and unified…

24 2mo ago A 71 tokens original MIT

allsmog/vuln-scout

Skill Claude CodeCodex

This skill should be used when the user asks about "API security", "OWASP API Top 10", "BOLA", "broken object level authorization", "API authentication", "mass assignment", "GraphQL security", "gRPC security", "rate limiting", "API abuse", "REST API vulnerabilities", or needs to identify API-specific security issues…

24 2mo ago A 85 tokens original MIT