create-semgrep-rule
Installation
SKILL.md
Create Custom Semgrep Rules
Expert workflow for creating high-quality, low-false-positive Semgrep rules for security vulnerability detection.
When to Create Custom Rules
Create custom rules when:
- Novel vulnerability patterns not covered by
p/defaultor existing custom rules - Org-specific code patterns (custom frameworks, internal APIs, coding conventions)
- Chained vulnerabilities requiring multi-step detection
- Language/framework-specific bugs (e.g., PHP
parse_urlbypass, Go unsafe patterns) - High-value targets warranting deeper, targeted analysis
- CVE variant hunting - Finding the same vulnerable pattern in other codebases
CVE-to-Rule Workflow
When creating rules from CVEs, the goal is to find the underlying vulnerable code pattern in OTHER codebases - NOT to detect the vulnerable library (SCA tools like Dependabot/Snyk do that better).