# How to Perform Static Analysis Using Trail of Bits Agent Skills

> Discover how to perform static analysis with Trail of Bits agent skills. Effortlessly run CodeQL and Semgrep, generating a unified SARIF report for your codebase.

- Repository: [VoltAgent/awesome-agent-skills](https://github.com/VoltAgent/awesome-agent-skills)
- Tags: how-to-guide
- Published: 2026-04-22

---

**Use the Trail of Bits static-analysis skill via `https://officialskills.sh/trailofbits/skills/static-analysis` to run CodeQL and Semgrep against your codebase, producing a unified SARIF report.**

The Trail of Bits static-analysis skill provides agent-ready access to industry-grade security analyzers. Listed in the VoltAgent Awesome Agent Skills repository under [Security Skills by Trail of Bits](https://github.com/VoltAgent/awesome-agent-skills/blob/main/README.md#L360), this remote skill executes a three-stage pipeline that ingests code, runs parallel analyses, and returns standardized results your agent can act upon.

---

## What the Static-Analysis Skill Provides

The skill bundles two primary analysis engines with automatic SARIF output generation:

| Component | Purpose |
|-----------|---------|
| **CodeQL** | Semantic analysis using pre-written or custom queries to find bugs, security flaws, and quality issues |
| **Semgrep** | Pattern-based rule matching across the codebase with support for custom rule sets |
| **SARIF Generator** | Unified output format that merges and deduplicates findings from both tools |

This combination lets you catch vulnerabilities that pattern matching alone might miss, while maintaining the speed and flexibility of rule-based scanning.

---

## Three-Stage Analysis Pipeline

When your agent invokes the static-analysis skill, execution follows this pipeline:

### Stage 1: Code Ingestion

The skill receives a file-system snapshot or list of source-file paths from your agent. It packages these into a temporary workspace that CodeQL and Semgrep can access.

### Stage 2: Analysis Execution

Both analyzers run in parallel:

- **CodeQL** executes its query suite against the code's semantic representation
- **Semgrep** applies pattern rules across raw source files

Each tool writes findings to separate SARIF files following the [Static Analysis Results Interchange Format](https://sarifweb.azurewebsites.net/) specification.

### Stage 3: Result Aggregation

The skill merges the individual SARIF files, deduplicates overlapping findings, and returns a single consolidated report. Your agent can then display results, store them as artifacts, or trigger remediation workflows.

---

## How to Invoke the Static-Analysis Skill

The skill is hosted remotely on [`officialskills.sh`](https://github.com/VoltAgent/awesome-agent-skills/blob/main/officialskills.sh) and referenced by URL. Here are two ways to use it with your agent.

### Method 1: TypeScript with VoltAgent

```typescript
import { Agent } from '@voltagent/core'

const agent = new Agent({
  skills: [
    'https://officialskills.sh/trailofbits/skills/static-analysis'
  ]
})

const repoPath = '/path/to/your/codebase'

const result = await agent.runSkill({
  name: 'static-analysis',
  input: { workspace: repoPath }
})

console.log('Static-analysis SARIF report:', result.sarif)

```

The `result.sarif` object contains the complete merged analysis results in SARIF format.

### Method 2: Command Line with opencode

```bash
opencode run \
  --skill https://officialskills.sh/trailofbits/skills/static-analysis \
  --input '{"workspace":"/home/user/project"}' \
  --output sarif.json

```

The generated [`sarif.json`](https://github.com/VoltAgent/awesome-agent-skills/blob/main/sarif.json) can be uploaded to GitHub Code Scanning, VS Code SARIF viewers, or other compatible tools.

---

## Key Configuration Options

While the basic invocation requires only a workspace path, you can customize analysis behavior:

| Parameter | Effect |
|-----------|--------|
| Custom CodeQL queries | Override default query suite with organization-specific checks |
| Custom Semgrep rules | Apply proprietary or domain-specific pattern rules |
| Severity thresholds | Filter findings by severity before returning SARIF |

These options are passed through the `input` object when calling `runSkill()` or via the `--input` CLI flag.

---

## Source Reference: Awesome Agent Skills Repository

The Trail of Bits static-analysis skill is cataloged in the [VoltAgent/awesome-agent-skills](https://github.com/VoltAgent/awesome-agent-skills) repository, which serves as the authoritative index for official agent skills.

| Location | Significance |
|----------|------------|
| [`README.md`](https://github.com/VoltAgent/awesome-agent-skills/blob/main/README.md) line 360 | Direct entry for the static-analysis skill with description and URL |
| [`README.md`](https://github.com/VoltAgent/awesome-agent-skills/blob/main/README.md) lines 342-361 | Full *Security Skills by Trail of Bits* section showing related skills that can chain with static analysis |

Because the skill is remote-hosted, this README entry is the primary documentation for discovering and invoking the capability.

---

## Summary

- **The Trail of Bits static-analysis skill** provides agent-accessible CodeQL and Semgrep analysis via `https://officialskills.sh/trailofbits/skills/static-analysis`
- **Execution follows three stages**: code ingestion, parallel analysis with CodeQL and Semgrep, and unified SARIF output
- **Invocation methods** include TypeScript with VoltAgent's `Agent` class or command-line via `opencode run`
- **The skill is cataloged** in `VoltAgent/awesome-agent-skills` at [`README.md`](https://github.com/VoltAgent/awesome-agent-skills/blob/main/README.md) line 360, with related security skills documented in lines 342-361

---

## Frequently Asked Questions

### What analyzers does the Trail of Bits static-analysis skill include?

The skill bundles **CodeQL** for semantic analysis and **Semgrep** for pattern-based scanning. Both run simultaneously and output findings in SARIF format, which the skill merges and deduplicates before returning.

### Can I use custom rules or queries with this skill?

Yes. The skill accepts custom CodeQL query suites and custom Semgrep rule sets through its input parameters. Pass these configurations via the `input` object when calling `runSkill()` in TypeScript, or through the `--input` JSON string in CLI usage.

### Where is the actual skill implementation located?

The skill is **remotely hosted** on [`officialskills.sh`](https://github.com/VoltAgent/awesome-agent-skills/blob/main/officialskills.sh). The `VoltAgent/awesome-agent-skills` repository serves as the discovery index—specifically [`README.md`](https://github.com/VoltAgent/awesome-agent-skills/blob/main/README.md) line 360—where you find the canonical URL and description, but the execution environment runs on Trail of Bits's infrastructure.

### What output format does the static-analysis skill produce?

The skill returns results in **SARIF** (Static Analysis Results Interchange Format), a standardized JSON schema. This unified SARIF report combines and deduplicates findings from both CodeQL and Semgrep, making it compatible with GitHub Code Scanning, VS Code extensions, and other SARIF-consuming tools.