Semgrep Rule Variant Creator
Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Version
- 1.1.3
- Author
- Maciej Domanski
What Semgrep Rule Variant Creator is
Semgrep Rule Variant Creator is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Semgrep Rule Variant Creator adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Semgrep Rule Variant Creator
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install semgrep-rule-variant-creator@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Semgrep Rule Variant Creator in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/semgrep-rule-variant-creator/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
A Claude Code skill for porting existing Semgrep rules to new target languages with proper applicability analysis and test-driven validation.
Overview
This skill takes an existing Semgrep rule and one or more target languages, then generates independent rule variants for each applicable language. Each variant goes through a complete 4-phase cycle:
- Applicability Analysis - Determine if the vulnerability pattern applies to the target language
- Test Creation - Write test-first with vulnerable and safe cases
- Rule Creation - Translate patterns and adapt for target language idioms
- Validation - Ensure all tests pass before proceeding
Components
The split follows what needs a person. Which rule to port, which languages to target, and whether to accept a language being dropped are decisions the skill puts to you, and a workflow cannot ask questions mid-run — which is exactly why those questions come first. Everything after that is the same four phases over many languages, so it runs as a workflow, with the phase order and the retry bound held in code rather than in prose.
Prerequisites
- Semgrep installed and available in PATH
- Existing Semgrep rule to port (in YAML)
- Target languages specified
- Dynamic workflows enabled — [Claude Code v2.1.154 or later, on any paid plan](https://code.claude.com/docs/en/workflows). Where they are unavailable the slash command does not exist and the skill falls back to running phases by hand
Usage
Porting is the same four phases repeated per language, so the orchestration ships as a dynamic workflow:
/semgrep-rule-variant-creator:port-rule-to-languagesIt reads the rule once, then runs each language through its own applicability, test, translation, and validation cycle, and reports which languages passed, which failed validation, which were not applicable, and which Semgrep cannot analyze at all — Perl has no frontend and Elixir's parser is Pro-only, and in both cases the bug class is present while the rule is ungradeable. Validation is measured against one specific Semgrep, the version recorded when the rule was read, because "All tests passed" is also what Semgrep prints for a rule it skipped and for a test file it never matched. Two annotations is the floor on both sides of a spec, and the ok: side is counted by a second Semgrep run over it, because --test --json reports the lines the rule matched and nothing about the lines it must leave alone — so vulnerable cases alone grade clean for a rule that flags every construct in the target language. The script pins a reasoning effort per phase and encodes the phase order, so a rule cannot be written before the tests that specify it. It also sends a NOT_APPLICABLE verdict to an independent refuter before dropping a language, and retries failed validation up to three times instead of trusting one agent to iterate until the tests pass.
The skill also triggers on a plain request, for porting a single language by hand:
Port the sql-injection.yaml Semgrep rule to Go and JavaCreate Semgrep rule variants of my-rule.yaml for TypeScript, Rust, and C#Create the same Semgrep rule for JavaScript and RubyPort this Semgrep rule to GolangOutput Structure
For each applicable target language, the skill produces:
<original-rule-id>-<language>/
├── <original-rule-id>-<language>.yaml # Ported rule
└── <original-rule-id>-<language>.<ext> # Test file Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Semgrep Rule Variant Creator?
Semgrep Rule Variant Creator is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation
How do I install Semgrep Rule Variant Creator in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install semgrep-rule-variant-creator@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Semgrep Rule Variant Creator in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Semgrep Rule Variant Creator in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Semgrep Rule Variant Creator safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Draw Draw the 12 Houses of the Zodiac Tarot spread and return a concise structured reading. Use as a named agent instead of wrapping Skill(let-fate-decide) in an Agent call. Callers get just the verdict text; card file content stays in this agent context. Subagent · trailofbits/skills
- Function Analyzer Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a compact record. Use for dense functions, data-flow chains, cryptographic code, and state machines. Subagent · trailofbits/skills
- Gh Cli Intercepts GitHub URL fetches (WebFetch and MCP fetch tools) and curl/wget commands, redirecting to the authenticated gh CLI. Plugin · trailofbits/skills
- Git Cleanup Safely analyzes and cleans up local git branches and worktrees by categorizing them as merged, squash-merged, superseded, or active work. Plugin · trailofbits/skills
- Sharp Edges Identify error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes Plugin · trailofbits/skills
- Semgrep Rule Creator Create custom Semgrep rules for detecting bug patterns and security vulnerabilities Plugin · trailofbits/skills
- Skill Improver Automatically reviews and fixes Claude Code skills through iterative refinement until they meet quality standards. Requires plugin-dev… Plugin · trailofbits/skills
- Second Opinion Gets independent code reviews from Codex or Antigravity for uncommitted changes, branch diffs, and commits. Plugin · trailofbits/skills