Creates custom Semgrep rules that detect security vulnerabilities and bug patterns.
By agent · Codex
Codex skills: 1008 worth installing
Skills in the open SKILL.md format that Codex reads. Each one has a plain-language summary and the command to install it.
Installing a skill in Codex
$ npx skills add <author>/<skill> --agent codexReplace the placeholder with the author and skill name from the skill's page. Start a new Codex session afterwards so the skill is picked up.
Skills for Codex
All skillsSharp Edges
Trail of BitsIdentifies error-prone APIs, dangerous configurations and designs that invite security mistakes.
Spec to Code Compliance
Trail of BitsChecks code against its specification: which requirements hold, which are contradicted and which are missing.
Scans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.
SARIF Parsing
Trail of BitsParses, aggregates and deduplicates SARIF files from static analysis tools such as CodeQL and Semgrep.
Runs a Semgrep security scan: detects languages, selects rulesets, asks for approval, then runs the scans.
Supply Chain Risk Auditor
Trail of BitsAudits a project's dependencies for supply-chain risk: advisories, abandoned upstreams and install-time scripts.
Designs and improves fuzzing harnesses for C, C++ and Rust targets.
Variant Analysis
Trail of BitsHunts for other instances of a bug that has already been found, across the whole codebase.
YARA Rule Authoring
Trail of BitsGuides the authoring of YARA-X detection rules for malware identification.
Detects missing zeroisation of sensitive data in C, C++ and Rust code, including cases removed by the compiler.
n8n Agents
Romuald CzłonkowskiGuides the design of n8n AI agents and LLM chains built from the LangChain AI nodes.
n8n Code JavaScript
Romuald CzłonkowskiWrites JavaScript for n8n Code nodes, covering $input, $json and $node syntax, HTTP helpers and date handling.
n8n Code Python
Romuald CzłonkowskiWrites native Python for n8n Code nodes and migrates older Pyodide-based code.
n8n Error Handling
Romuald CzłonkowskiWires error handling into n8n workflows so that failures are visible, structured and recoverable.
n8n Expression Syntax
Romuald CzłonkowskiValidates n8n expression syntax and fixes common errors when mapping data between nodes.
n8n MCP Tools Expert
Romuald CzłonkowskiGuides use of the n8n-mcp tools: searching nodes, validating configurations, using templates and managing workflows and credentials.
n8n Node Configuration
Romuald CzłonkowskiGuides node configuration in n8n: property dependencies, required fields and common patterns by node type.
n8n Validation Expert
Romuald CzłonkowskiInterprets n8n validation errors and warnings, and guides the fix.
Supplies workflow architecture patterns drawn from real n8n workflows, such as webhook processing and HTTP API integration.
Antfu
Anthony FuApplies Anthony Fu's tooling and conventions to JavaScript and TypeScript projects: linting, monorepos and library publishing.
Nitro
Anthony FuReference for Nitro, the server toolkit behind Nuxt: server routes, route rules, caching, storage, tasks and websockets.
Nuxt
Anthony FuReference for Nuxt: SSR, auto-imports, file-based routing, server routes, useFetch, middleware and hybrid rendering.
Pinia
Anthony FuReference for Pinia, Vue's state management library: defining stores, state, getters, actions and store patterns.
Questions
Codex and skills.
Do Claude skills work in Codex?
Often. A skill is a folder of instructions and scripts in the open SKILL.md format, which Codex reads. A skill that depends on tools only one agent provides will not carry over, so read the skill's source before you rely on it.
How do I install a skill in Codex?
Each skill page has an install command. Run it in a terminal, then start a new Codex session so the skill is picked up.
What is the difference between a skill and an instructions file such as AGENTS.md?
An instructions file is loaded in every session and describes the project. A skill is loaded only when a task calls for it, so it can be long and specific without costing context on every turn.