openclaw-skills/semgrep-appsec-scanner/SKILL.md
用于通过 Semgrep 执行应用安全 SAST、源码扫描、自定义规则、密钥流程和供应链依赖分析。
npx skillsauth add seaworld008/commonly-used-high-value-skills semgrep-appsec-scannerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when the user asks for source-code vulnerability scanning, secure coding rule enforcement, custom SAST checks, secret scanning workflow design, or Semgrep Supply Chain dependency analysis.
Good trigger phrases:
Before scanning, inspect the repo:
rg --files | sed -n '1,120p'
Classify:
semgrep --version
If missing, recommend official installation. For one-off local scans, a package manager or containerized Semgrep run is usually enough.
semgrep scan --config auto
For stricter security-focused scans:
semgrep scan --config p/security-audit
semgrep scan --config p/owasp-top-ten
For JSON output:
semgrep scan --config auto --json --output semgrep-results.json
For SARIF:
semgrep scan --config auto --sarif --output semgrep-results.sarif
For each finding, record:
Prioritize:
Use custom rules when the project has a known unsafe wrapper or banned API:
rules:
- id: no-dangerous-shell
message: Avoid shell=True with interpolated input.
severity: ERROR
languages: [python]
patterns:
- pattern: subprocess.run($CMD, shell=True, ...)
Validate the rule with positive and negative examples before adding it to CI.
For code fixes:
For dependency findings:
name: semgrep
on: [pull_request]
jobs:
semgrep:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Semgrep scan
run: semgrep scan --config auto --error
.semgrep/
rules/
no-dangerous-shell.yml
no-raw-sql-wrapper.yml
tests/
no-dangerous-shell.py
## Semgrep Finding
- Rule:
- Severity:
- Location:
- User input source:
- Sensitive sink:
- Exploit path:
- Fix:
- Test:
- Suppression status:
tools
飞书审批:查询和处理审批待办/已办/实例,搜索可发起审批定义、查看定义详情并发起原生审批实例。当用户要处理审批任务、查看审批实例、搜索或发起审批时使用。审批待办不是飞书任务;非审批类待办走 lark-task。不负责创建审批定义;三方审批定义不走原生提单。
development
Use when a user needs reproducible repository sizing, language composition, file counts, or code-versus-comment ratios with pygount; record exclusions and verify measurement scope before interpreting results.
development
Route a development task to the official Hermes Agent skill, Graphify Codex artifact set, Open GSD Core bundle, or optional GSD Pi bundle without duplicating their installers or state machines.
development
飞书 / Lark 通讯录:按姓名 / 邮箱解析成 open_id,或按 open_id 反查姓名 / 部门 / 邮箱 / 联系方式 / 个人状态 / 签名,以及按关键词搜索当前用户可见的机器人 / 智能体(agent)。当用户提到一个名字要下一步发消息 / 排日程,或拿到 open_id 想查具体信息时使用。不负责部门树遍历、按部门列员工、组织架构图,这类需求走原生 OpenAPI。