How to Perform Static Analysis Using Trail of Bits Agent Skills

Use the Trail of Bits static-analysis skill via https://officialskills.sh/trailofbits/skills/static-analysis to run CodeQL and Semgrep against your codebase, producing a unified SARIF report.

The Trail of Bits static-analysis skill provides agent-ready access to industry-grade security analyzers. Listed in the VoltAgent Awesome Agent Skills repository under Security Skills by Trail of Bits, this remote skill executes a three-stage pipeline that ingests code, runs parallel analyses, and returns standardized results your agent can act upon.


What the Static-Analysis Skill Provides

The skill bundles two primary analysis engines with automatic SARIF output generation:

Component Purpose
CodeQL Semantic analysis using pre-written or custom queries to find bugs, security flaws, and quality issues
Semgrep Pattern-based rule matching across the codebase with support for custom rule sets
SARIF Generator Unified output format that merges and deduplicates findings from both tools

This combination lets you catch vulnerabilities that pattern matching alone might miss, while maintaining the speed and flexibility of rule-based scanning.


Three-Stage Analysis Pipeline

When your agent invokes the static-analysis skill, execution follows this pipeline:

Stage 1: Code Ingestion

The skill receives a file-system snapshot or list of source-file paths from your agent. It packages these into a temporary workspace that CodeQL and Semgrep can access.

Stage 2: Analysis Execution

Both analyzers run in parallel:

  • CodeQL executes its query suite against the code's semantic representation
  • Semgrep applies pattern rules across raw source files

Each tool writes findings to separate SARIF files following the Static Analysis Results Interchange Format specification.

Stage 3: Result Aggregation

The skill merges the individual SARIF files, deduplicates overlapping findings, and returns a single consolidated report. Your agent can then display results, store them as artifacts, or trigger remediation workflows.


How to Invoke the Static-Analysis Skill

The skill is hosted remotely on officialskills.sh and referenced by URL. Here are two ways to use it with your agent.

Method 1: TypeScript with VoltAgent

import { Agent } from '@voltagent/core'

const agent = new Agent({
  skills: [
    'https://officialskills.sh/trailofbits/skills/static-analysis'
  ]
})

const repoPath = '/path/to/your/codebase'

const result = await agent.runSkill({
  name: 'static-analysis',
  input: { workspace: repoPath }
})

console.log('Static-analysis SARIF report:', result.sarif)

The result.sarif object contains the complete merged analysis results in SARIF format.

Method 2: Command Line with opencode

opencode run \
  --skill https://officialskills.sh/trailofbits/skills/static-analysis \
  --input '{"workspace":"/home/user/project"}' \
  --output sarif.json

The generated sarif.json can be uploaded to GitHub Code Scanning, VS Code SARIF viewers, or other compatible tools.


Key Configuration Options

While the basic invocation requires only a workspace path, you can customize analysis behavior:

Parameter Effect
Custom CodeQL queries Override default query suite with organization-specific checks
Custom Semgrep rules Apply proprietary or domain-specific pattern rules
Severity thresholds Filter findings by severity before returning SARIF

These options are passed through the input object when calling runSkill() or via the --input CLI flag.


Source Reference: Awesome Agent Skills Repository

The Trail of Bits static-analysis skill is cataloged in the VoltAgent/awesome-agent-skills repository, which serves as the authoritative index for official agent skills.

Location Significance
README.md line 360 Direct entry for the static-analysis skill with description and URL
README.md lines 342-361 Full Security Skills by Trail of Bits section showing related skills that can chain with static analysis

Because the skill is remote-hosted, this README entry is the primary documentation for discovering and invoking the capability.


Summary

  • The Trail of Bits static-analysis skill provides agent-accessible CodeQL and Semgrep analysis via https://officialskills.sh/trailofbits/skills/static-analysis
  • Execution follows three stages: code ingestion, parallel analysis with CodeQL and Semgrep, and unified SARIF output
  • Invocation methods include TypeScript with VoltAgent's Agent class or command-line via opencode run
  • The skill is cataloged in VoltAgent/awesome-agent-skills at README.md line 360, with related security skills documented in lines 342-361

Frequently Asked Questions

What analyzers does the Trail of Bits static-analysis skill include?

The skill bundles CodeQL for semantic analysis and Semgrep for pattern-based scanning. Both run simultaneously and output findings in SARIF format, which the skill merges and deduplicates before returning.

Can I use custom rules or queries with this skill?

Yes. The skill accepts custom CodeQL query suites and custom Semgrep rule sets through its input parameters. Pass these configurations via the input object when calling runSkill() in TypeScript, or through the --input JSON string in CLI usage.

Where is the actual skill implementation located?

The skill is remotely hosted on officialskills.sh. The VoltAgent/awesome-agent-skills repository serves as the discovery index—specifically README.md line 360—where you find the canonical URL and description, but the execution environment runs on Trail of Bits's infrastructure.

What output format does the static-analysis skill produce?

The skill returns results in SARIF (Static Analysis Results Interchange Format), a standardized JSON schema. This unified SARIF report combines and deduplicates findings from both CodeQL and Semgrep, making it compatible with GitHub Code Scanning, VS Code extensions, and other SARIF-consuming tools.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →