semgrep-rule-creator
Semgrep rule creator
semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass.
Install Semgrep rule creator
Install this skill with the skills CLI
npx skills add trailofbits/skills --skill semgrep-rule-creatorOr, in Claude Code, add Trail of Bits' plugin marketplace
/plugin marketplace add trailofbits/skillsOr, in Codex, add the same marketplace from your terminal
codex plugin marketplace add trailofbits/skillsThen install the semgrep-rule-creator plugin in Codex
codex plugin add semgrep-rule-creator@trailofbitsIn Claude Code, open /plugin menu after adding the marketplace and install the semgrep-rule-creator plugin. For a ChatGPT workspace, Trail of Bits' README says to import the repository's .claude-plugin/marketplace.json.
Or paste this into your coding agent: Install the agent skill semgrep-rule-creator from github.com/trailofbits/skills.
A skill can include scripts that run on your computer, so read its source first.
What Semgrep rule creator does
semgrep-rule-creator is an agent skill from security firm Trail of Bits for writing new Semgrep rules, the YAML pattern files that Semgrep runs to find bugs and vulnerabilities in source code. It covers rules for a specific bug pattern, a class of security vulnerability, data flow from user input to a dangerous function, and coding standards a team wants enforced.
The semgrep-rule-creator workflow is strict and test-first. The agent writes a test file with both vulnerable cases and safe cases before the rule, looks at Semgrep's syntax tree dump of the code, writes the rule, then iterates until every test passes with semgrep --test. Only then may it simplify the patterns. Each rule lives in its own folder with exactly one YAML file and one test file.
The skill prefers taint mode for injection-style bugs, because a plain pattern such as eval matches safe constant input too, while taint mode alerts only when untrusted data reaches the sink. It lists anti-patterns to avoid: rules so broad they match every call, rules so narrow they miss variations, generic-language rules, and tests with no safe cases.
When to use Semgrep rule creator
- You found a bug pattern in your code and want a Semgrep rule that catches every instance.
- You want a taint rule that tracks user input to a dangerous function.
- You want to enforce a team coding standard in CI with Semgrep.
- Your existing custom rule has too many false positives and needs tests.
When to pick something else
- Scanning a codebase with Semgrep rulesets that already exist: Trail of Bits' static-analysis plugin covers that.
- Porting a rule to another language: use semgrep-rule-variant-creator from the same repository.
What Semgrep rule creator needs
- The Semgrep CLI installed locally
Which agents Semgrep rule creator works in
Trail of Bits documents Semgrep rule creator for Claude Code, Codex, ChatGPT workspace marketplace. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 1, 2026). See where each agent looks for skills.
Semgrep rule creator license
Semgrep rule creator is published under CC-BY-SA-4.0. CC-BY-SA-4.0 is a share-alike license. You can copy the skill into a project and change it, even for commercial work, if you credit Trail of Bits, link the license and say what you changed. If you share a changed version, for example in a public repository, it must stay under CC-BY-SA-4.0. It is a content license, not a software license, so ask your legal team before bundling it inside a closed product.
Questions people ask
Can I copy Trail of Bits' semgrep-rule-creator skill into my own repository?
Yes, with conditions. The skills are CC-BY-SA-4.0. You may copy and adapt them, even commercially, if you credit Trail of Bits, link the license and note your changes. Any changed version you share must carry the same CC-BY-SA-4.0 license. Using the skill unchanged in your own work does not put your code under that license.
Does semgrep-rule-creator run Semgrep scans on my whole codebase?
No. It writes and tests new rules, one rule and one test file at a time. For scanning a codebase with existing rulesets, Trail of Bits points to its static-analysis plugin, which has separate semgrep, codeql and sarif-parsing skills.
Related skills for security
- Firebase security rules auditor: firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON.
- GitHub Actions security review: gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding.
- Security review: security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence.
- Differential review: differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report.
More from Trail of Bits
- Mutation testing: mutation-testing is Trail of Bits' agent skill for configuring mutation testing campaigns with its mewt or muton tools, reading surviving mutants, telling equivalent mutants from real test gaps, and hunting bugs they expose.
- Supply chain risk auditor: supply-chain-risk-auditor is Trail of Bits' agent skill for auditing a project's npm, PyPI and Go dependencies for known advisories, abandoned upstreams, publisher concentration and install scripts, measured by bundled scripts.