sast-semgrep

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill functions as a security auditing tool and correctly implements industry-standard development practices. No hardcoded credentials, malicious instructions, or persistence mechanisms were detected. Instructions for CI/CD secrets (e.g., SEMGREP_APP_TOKEN) correctly utilize secret stores rather than hardcoding values.
  • [EXTERNAL_DOWNLOADS]: The skill's CI/CD templates (GitHub Actions, GitLab CI) reference official resources from trusted organizations, such as GitHub's own checkout and security actions, and the official Semgrep Docker image. These are well-known, verified dependencies for software development and security workflows.
  • [COMMAND_EXECUTION]: The skill provides instructions for executing the Semgrep CLI and installing the package via standard managers like pip. These shell commands are limited to the intended security scanning functionality and do not exhibit any patterns of privilege escalation, unauthorized persistence, or unsafe dynamic execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 02:35 AM
Security Audit — agent-trust-hub — sast-semgrep