How to Perform Static Analysis Using Trail of Bits Agent Skills
Use the Trail of Bits static-analysis skill via https://officialskills.sh/trailofbits/skills/static-analysis to run CodeQL and Semgrep against your codebase, producing a unified SARIF report.
The Trail of Bits static-analysis skill provides agent-ready access to industry-grade security analyzers. Listed in the VoltAgent Awesome Agent Skills repository under Security Skills by Trail of Bits, this remote skill executes a three-stage pipeline that ingests code, runs parallel analyses, and returns standardized results your agent can act upon.
What the Static-Analysis Skill Provides
The skill bundles two primary analysis engines with automatic SARIF output generation:
| Component | Purpose |
|---|---|
| CodeQL | Semantic analysis using pre-written or custom queries to find bugs, security flaws, and quality issues |
| Semgrep | Pattern-based rule matching across the codebase with support for custom rule sets |
| SARIF Generator | Unified output format that merges and deduplicates findings from both tools |
This combination lets you catch vulnerabilities that pattern matching alone might miss, while maintaining the speed and flexibility of rule-based scanning.
Three-Stage Analysis Pipeline
When your agent invokes the static-analysis skill, execution follows this pipeline:
Stage 1: Code Ingestion
The skill receives a file-system snapshot or list of source-file paths from your agent. It packages these into a temporary workspace that CodeQL and Semgrep can access.
Stage 2: Analysis Execution
Both analyzers run in parallel:
- CodeQL executes its query suite against the code's semantic representation
- Semgrep applies pattern rules across raw source files
Each tool writes findings to separate SARIF files following the Static Analysis Results Interchange Format specification.
Stage 3: Result Aggregation
The skill merges the individual SARIF files, deduplicates overlapping findings, and returns a single consolidated report. Your agent can then display results, store them as artifacts, or trigger remediation workflows.
How to Invoke the Static-Analysis Skill
The skill is hosted remotely on officialskills.sh and referenced by URL. Here are two ways to use it with your agent.
Method 1: TypeScript with VoltAgent
import { Agent } from '@voltagent/core'
const agent = new Agent({
skills: [
'https://officialskills.sh/trailofbits/skills/static-analysis'
]
})
const repoPath = '/path/to/your/codebase'
const result = await agent.runSkill({
name: 'static-analysis',
input: { workspace: repoPath }
})
console.log('Static-analysis SARIF report:', result.sarif)
The result.sarif object contains the complete merged analysis results in SARIF format.
Method 2: Command Line with opencode
opencode run \
--skill https://officialskills.sh/trailofbits/skills/static-analysis \
--input '{"workspace":"/home/user/project"}' \
--output sarif.json
The generated sarif.json can be uploaded to GitHub Code Scanning, VS Code SARIF viewers, or other compatible tools.
Key Configuration Options
While the basic invocation requires only a workspace path, you can customize analysis behavior:
| Parameter | Effect |
|---|---|
| Custom CodeQL queries | Override default query suite with organization-specific checks |
| Custom Semgrep rules | Apply proprietary or domain-specific pattern rules |
| Severity thresholds | Filter findings by severity before returning SARIF |
These options are passed through the input object when calling runSkill() or via the --input CLI flag.
Source Reference: Awesome Agent Skills Repository
The Trail of Bits static-analysis skill is cataloged in the VoltAgent/awesome-agent-skills repository, which serves as the authoritative index for official agent skills.
| Location | Significance |
|---|---|
README.md line 360 |
Direct entry for the static-analysis skill with description and URL |
README.md lines 342-361 |
Full Security Skills by Trail of Bits section showing related skills that can chain with static analysis |
Because the skill is remote-hosted, this README entry is the primary documentation for discovering and invoking the capability.
Summary
- The Trail of Bits static-analysis skill provides agent-accessible CodeQL and Semgrep analysis via
https://officialskills.sh/trailofbits/skills/static-analysis - Execution follows three stages: code ingestion, parallel analysis with CodeQL and Semgrep, and unified SARIF output
- Invocation methods include TypeScript with VoltAgent's
Agentclass or command-line viaopencode run - The skill is cataloged in
VoltAgent/awesome-agent-skillsatREADME.mdline 360, with related security skills documented in lines 342-361
Frequently Asked Questions
What analyzers does the Trail of Bits static-analysis skill include?
The skill bundles CodeQL for semantic analysis and Semgrep for pattern-based scanning. Both run simultaneously and output findings in SARIF format, which the skill merges and deduplicates before returning.
Can I use custom rules or queries with this skill?
Yes. The skill accepts custom CodeQL query suites and custom Semgrep rule sets through its input parameters. Pass these configurations via the input object when calling runSkill() in TypeScript, or through the --input JSON string in CLI usage.
Where is the actual skill implementation located?
The skill is remotely hosted on officialskills.sh. The VoltAgent/awesome-agent-skills repository serves as the discovery index—specifically README.md line 360—where you find the canonical URL and description, but the execution environment runs on Trail of Bits's infrastructure.
What output format does the static-analysis skill produce?
The skill returns results in SARIF (Static Analysis Results Interchange Format), a standardized JSON schema. This unified SARIF report combines and deduplicates findings from both CodeQL and Semgrep, making it compatible with GitHub Code Scanning, VS Code extensions, and other SARIF-consuming tools.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →