trailofbits-semgrep
Trail of Bits security skill to run Semgrep for pattern-based static analysis of code.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for trailofbits-semgrep, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Security skill from Trail of Bits that drives Semgrep to scan code for vulnerable patterns. Runs Semgrep and interprets findings; part of the static-analysis plugin with bundled configuration and guidance.
Key features and capabilities
- Semgrep scanning
- Pattern-based detection
- Finding interpretation
Use cases
- Static security review
- Detecting known bug patterns