semgrep

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill description presents a coherent and serviceable plan for orchestrating Semgrep-based static analysis with optional Pro features, parallel scanning, triage, and SARIF aggregation. The data flows are primarily local (codebase -> local outputs) with external dependencies limited to the Semgrep tooling and third-party rule sources. There are no evident credential reads, secret handling, or unintended data exfiltration patterns in the provided fragment. The most notable concerns are the heavy workflow gating and multi-agent orchestration, which could complicate trust boundaries and error handling in real usage; this could be leveraged for misconfiguration or misexecution if access to the Task system is abused. Overall risk remains low-to-medium with respect to direct malicious intent, but the complexity and reliance on external rule sources warrant careful access control and input validation in the orchestration layer.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 11:32 AM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Fsemgrep%2F@7be6fe5a8a34965888680e60142b889d8b3c7050