sast-semgrep

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading and installing the "semgrep" tool, which is a well-known security utility. The CI/CD examples also reference official Semgrep Docker images and GitHub Actions.\n- [COMMAND_EXECUTION]: The documentation provides multiple examples of shell commands for running security scans. These commands are consistent with the skill's stated purpose of providing SAST capabilities.\n- [NO_CODE]: The skill's main documentation (SKILL.md) references several bundled scripts (e.g., "scripts/semgrep_scan.py") that are missing from the provided files. Consequently, the skill functions primarily as a reference guide rather than an executable toolkit.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 11:00 AM
Security Audit — agent-trust-hub — sast-semgrep