Author, test, and tune Semgrep rules for org-owned codebases: YAML rule schema, pattern/pattern-either/pattern-not, metavariables, taint mode, message/severity/metadata, language packs, and rule tests. Use when writing custom Semgrep rules, fixing false positives/negatives in .semgrep.yml or rules/, Semgrep OSS/Pro patterns, taint-mode sinks/sources, or packaging org rule packs for CI.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
Author, test, and tune Semgrep rules for org-owned codebases: YAML rule schema, pattern/pattern-either/pattern-not, metavariables, taint mode, message/severity/metadata, language packs, and rule tests. Use when writing custom Semgrep rules, fixing false positives/negatives in .semgrep.yml or rules/, Semgrep OSS/Pro patterns, taint-mode sinks/sources, or packaging org rule packs for CI.
Semgrep Rule Authoring
Write high-signal custom Semgrep rules for repositories you own or are
authorized to scan. Prefer repo config and existing packs. Fix code under
code-quality-standards. Hand broad SAST ops/triage to
sast-dast-tooling-usage; CI wiring to ci-cd-pipeline-patterns.
When To Use
Authoring or editing custom Semgrep YAML (rules/, .semgrep.yml)
Encoding org anti-patterns: forbidden APIs, raw SQL helpers, unsafe crypto
Reducing false positives/negatives with tighter patterns or taint mode
Adding rule tests (positive/negative fixtures) and packaging team packs
Keywords: Semgrep rule, pattern-either, metavariable-regex, taint mode,
semgrep --validate, custom SAST rule, p/ packs vs local rules
Do not use as primary for: run/triage scanners → sast-dast-tooling-usage;
SSDLC gates → secure-sdlc-checklist; secrets lifecycle →
secrets-management-hygiene; SCA/CVE → sbom-and-supply-chain; pipeline YAML
only → ci-cd-pipeline-patterns; secure fixes → code-quality-standards.
Repo Config First
Repo and org policy outrank examples below.
Configs:.semgrep.yml, .semgrep/, semgrep.yaml, CI --config paths
Extend the real config tree; do not invent a second root.
Workflow
1. Capture the bug pattern
Collect ≥2 true positives and ≥1 near-miss (must not match).
Name source, sink, and trust boundary in plain language.
Prefer AST patterns over brittle regex; constrain metavariables when needed.
Choose search (structural) vs taint (source → sink dataflow).
2. Draft the rule skeleton
rules:-id:org.python.security.raw-cursor-executelanguages: [python]
severity:ERRORmessage:>
Parameterize SQL; do not pass user-controlled strings to cursor.execute.
metadata:category:securitycwe:"CWE-89"confidence:MEDIUMpatterns:-pattern:$CURSOR.execute($QUERY,...)-pattern-not:$CURSOR.execute("...",...)