semgrep
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation, example command lines, and rule templates for Semgrep, which is a legitimate security tool for finding vulnerabilities in code. All external references are to the Semgrep registry (
p/...) or generic placeholders. - [REMOTE_CODE_EXECUTION]: While the skill contains examples of dangerous functions like
eval(),os.system(), andsubprocess.call(), these are explicitly provided as patterns for the tool to find during security scans, rather than instructions for the agent to execute itself. - [COMMAND_EXECUTION]: The skill documents standard CLI usage of the
semgreptool. No malicious or unauthorized command execution patterns were found.
Audit Metadata