Sponsor Suno AI Music arrow_forward
Plugin

Semgrep Rule Variant Creator

Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation

Type
Plugin
Repository
trailofbits/skills
GitHub stars
7.3k
License
CC-BY-SA-4.0
Repo last updated
Sep 25, 2026
Version
1.1.3
Author
Maciej Domanski

What Semgrep Rule Variant Creator is

Semgrep Rule Variant Creator is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”

A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.

Installing Semgrep Rule Variant Creator adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.

How to install Semgrep Rule Variant Creator

Claude Code

  1. Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
  2. Install the plugin: claude plugin install semgrep-rule-variant-creator@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
  3. Restart the session if the new skills or commands don't appear straight away.

Claude Cowork

  1. Open Customize → Plugins and choose Add marketplace.
  2. Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
  3. Find Semgrep Rule Variant Creator in the list, click Install, then connect any connectors it needs from its Connectors tab.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/semgrep-rule-variant-creator/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.

A Claude Code skill for porting existing Semgrep rules to new target languages with proper applicability analysis and test-driven validation.

Overview

This skill takes an existing Semgrep rule and one or more target languages, then generates independent rule variants for each applicable language. Each variant goes through a complete 4-phase cycle:

  1. Applicability Analysis - Determine if the vulnerability pattern applies to the target language
  2. Test Creation - Write test-first with vulnerable and safe cases
  3. Rule Creation - Translate patterns and adapt for target language idioms
  4. Validation - Ensure all tests pass before proceeding

Components

The split follows what needs a person. Which rule to port, which languages to target, and whether to accept a language being dropped are decisions the skill puts to you, and a workflow cannot ask questions mid-run — which is exactly why those questions come first. Everything after that is the same four phases over many languages, so it runs as a workflow, with the phase order and the retry bound held in code rather than in prose.

Prerequisites

  • Semgrep installed and available in PATH
  • Existing Semgrep rule to port (in YAML)
  • Target languages specified
  • Dynamic workflows enabled — [Claude Code v2.1.154 or later, on any paid plan](https://code.claude.com/docs/en/workflows). Where they are unavailable the slash command does not exist and the skill falls back to running phases by hand

Usage

Porting is the same four phases repeated per language, so the orchestration ships as a dynamic workflow:

/semgrep-rule-variant-creator:port-rule-to-languages

It reads the rule once, then runs each language through its own applicability, test, translation, and validation cycle, and reports which languages passed, which failed validation, which were not applicable, and which Semgrep cannot analyze at all — Perl has no frontend and Elixir's parser is Pro-only, and in both cases the bug class is present while the rule is ungradeable. Validation is measured against one specific Semgrep, the version recorded when the rule was read, because "All tests passed" is also what Semgrep prints for a rule it skipped and for a test file it never matched. Two annotations is the floor on both sides of a spec, and the ok: side is counted by a second Semgrep run over it, because --test --json reports the lines the rule matched and nothing about the lines it must leave alone — so vulnerable cases alone grade clean for a rule that flags every construct in the target language. The script pins a reasoning effort per phase and encodes the phase order, so a rule cannot be written before the tests that specify it. It also sends a NOT_APPLICABLE verdict to an independent refuter before dropping a language, and retries failed validation up to three times instead of trusting one agent to iterate until the tests pass.

The skill also triggers on a plain request, for porting a single language by hand:

Port the sql-injection.yaml Semgrep rule to Go and Java
Create Semgrep rule variants of my-rule.yaml for TypeScript, Rust, and C#
Create the same Semgrep rule for JavaScript and Ruby
Port this Semgrep rule to Golang

Output Structure

For each applicable target language, the skill produces:

<original-rule-id>-<language>/
├── <original-rule-id>-<language>.yaml     # Ported rule
└── <original-rule-id>-<language>.<ext>    # Test file

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Semgrep Rule Variant Creator?

Semgrep Rule Variant Creator is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Creates language variants of existing Semgrep rules with proper applicability analysis and test-driven validation

How do I install Semgrep Rule Variant Creator in Claude Code?

Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install semgrep-rule-variant-creator@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.

Can I use Semgrep Rule Variant Creator in Claude Cowork?

Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Semgrep Rule Variant Creator in the list, click Install, then connect any connectors it needs from its Connectors tab.

Is Semgrep Rule Variant Creator safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under CC-BY-SA-4.0. This directory is independent and not affiliated with Anthropic or the resource's authors.