Codeql

Codeql taxonomy generated by the site skill importer.

7 skills
T
coverage-analysis

by trailofbits

coverage-analysis helps you measure code exercised during fuzzing, spot blockers like magic value checks, and compare harness changes. Use this coverage-analysis skill for Security Audit workflows when you need clear coverage-analysis usage, install guidance, and repeatable coverage-analysis guide decisions.

Security Audit
Favorites 0GitHub 5k
T
semgrep

by trailofbits

Semgrep skill for static analysis on codebases with automatic language detection, parallel workers, merged SARIF output, and plan-first approval. Built for semgrep for Security Audit workflows, it supports run all and important only modes, uses --metrics=off, and can leverage Semgrep Pro when available.

Security Audit
Favorites 0GitHub 5k
T
sarif-parsing

by trailofbits

sarif-parsing is a post-scan skill for reading, filtering, deduplicating, summarizing, and converting SARIF 2.1.0 results from tools like CodeQL and Semgrep. Use it when you already have scan output and need clear parsing, aggregation, or CI/CD-ready transformation. It is not for running scans.

Code Editing
Favorites 0GitHub 5k
T
codeql

by trailofbits

The codeql skill helps you run CodeQL with fewer blind spots during a security audit. It focuses on database quality, suite selection, data extensions, and SARIF review so you can use codeql usage more reliably across supported languages. Use it for repeatable codeql guide steps when analyzing real repositories.

Security Audit
Favorites 0GitHub 5k
A
cpg-analysis

by alinaqi

cpg-analysis is a deep code analysis skill for control flow, data flow, taint paths, and security auditing using Joern CPG and CodeQL. Use the cpg-analysis skill when a normal repo skim is not enough and you need evidence-backed tracing across functions, files, and sinks.

Security Audit
Favorites 0GitHub 607
O
finding-duplicate-functions

by obra

Use the finding-duplicate-functions skill to identify semantic duplicates: functions that do the same job with different names or implementations. It is built for LLM-generated and fast-growing JavaScript or TypeScript codebases, and it supports finding-duplicate-functions for Code Review, consolidation planning, and cleanup before refactors.

Code Review
Favorites 0GitHub 0
T
variant-analysis

by trailofbits

variant-analysis helps you find similar vulnerabilities and bugs across a codebase after one issue is confirmed. Use it to build CodeQL or Semgrep queries, follow a root-cause-first workflow, and run a focused variant-analysis guide for Security Audit work. It is best for post-discovery searches, not broad initial review.

Security Audit
Favorites 0GitHub 0
Codeql