openclaw-skills/semgrep-appsec-scanner/SKILL.md
用于通过 Semgrep 执行应用安全 SAST、源码扫描、自定义规则、密钥流程和供应链依赖分析。
npx skillsauth add seaworld008/commonly-used-high-value-skills semgrep-appsec-scannerInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill when the user asks for source-code vulnerability scanning, secure coding rule enforcement, custom SAST checks, secret scanning workflow design, or Semgrep Supply Chain dependency analysis.
Good trigger phrases:
Before scanning, inspect the repo:
rg --files | sed -n '1,120p'
Classify:
semgrep --version
If missing, recommend official installation. For one-off local scans, a package manager or containerized Semgrep run is usually enough.
semgrep scan --config auto
For stricter security-focused scans:
semgrep scan --config p/security-audit
semgrep scan --config p/owasp-top-ten
For JSON output:
semgrep scan --config auto --json --output semgrep-results.json
For SARIF:
semgrep scan --config auto --sarif --output semgrep-results.sarif
For each finding, record:
Prioritize:
Use custom rules when the project has a known unsafe wrapper or banned API:
rules:
- id: no-dangerous-shell
message: Avoid shell=True with interpolated input.
severity: ERROR
languages: [python]
patterns:
- pattern: subprocess.run($CMD, shell=True, ...)
Validate the rule with positive and negative examples before adding it to CI.
For code fixes:
For dependency findings:
name: semgrep
on: [pull_request]
jobs:
semgrep:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Semgrep scan
run: semgrep scan --config auto --error
.semgrep/
rules/
no-dangerous-shell.yml
no-raw-sql-wrapper.yml
tests/
no-dangerous-shell.py
## Semgrep Finding
- Rule:
- Severity:
- Location:
- User input source:
- Sensitive sink:
- Exploit path:
- Fix:
- Test:
- Suppression status:
development
Enumerating failure modes via pre-mortem analysis. Systematically identifies failure scenarios for plans, designs, and features, scoring them with RPN/AP. Does not write code.
testing
Orchestrating specialist AI agent teams as a meta-coordinator. Decomposes requests into minimum viable chains, spawns each as an independent session in AUTORUN modes, and drives to final output. Use when a task spans multiple specialist domains, requires parallel agent execution, or needs hub-and-spoke routing across the skill ecosystem.
development
Converting document formats (Markdown/Word/Excel/PDF/HTML). Converts specs from Scribe and reports from Harvest into distributable formats; generates reusable conversion scripts. Use when converting documents, building accessibility-compliant PDFs, or creating Pandoc/LibreOffice pipelines.
testing
Curating cross-agent knowledge and guarding institutional memory. Extracts patterns from agent journals into METAPATTERNS.md, detects knowledge decay, propagates best practices, prevents organizational forgetting. Use when consolidating cross-agent insights, curating memory, or auditing knowledge decay.