claudemods

ModsSemgrep

semgrep Plugin

Semgrep Guardian: Scans agent-generated code for security vulnerabilities.

Install View latest version Open upstream repository

More actions and subscriptions

Compare latest version View observed updates for this package Subscribe with Atom View source record

Only the newest 50 observations in this subscription, not a full archive, upstream releases or installs. Updates-page links keep observation type and package filters; package-page links include all kinds for that package. Your local following list is not sent.

Install

This version is listed in the verified marketplace semgrep-marketplace (repository semgrep/guardian). Run these in Claude Code, in order:

  1. Add the marketplace/plugin marketplace add semgrep/guardian
  2. Install the plugin/plugin install semgrep@semgrep-marketplace

These commands install the marketplace's current upstream state, not the pinned commit snapshot on this page; the two can differ.

Contents of latest version 2.5.4 (commit eee2e50)

Contents 9

Skill3
Hook5
MCP server1
Dependencies, compatibility and skill declarations

Recorded dependencies 0

No dependency requirements were recorded from plugin.json or marketplace entries. Only manifest fields saved with the snapshot are shown here; dependency declarations in other files are outside the current collection scope.

Recorded compatibility

No compatibility requirement was recorded for this snapshot from plugin.json or a marketplace entry. Only manifest fields saved with the snapshot are shown here. Declarations in a skill's SKILL.md header are collected separately and, when present, shown on their own under “Skill file declarations”; they never overwrite or fill in this value.

Skill file declarations 3

The content below was read separately from the header of each skill file (SKILL.md) at its pinned commit. It is text the file declares about itself, shown as an annotation only. It is stored apart from the snapshot's dependencies and compatibility (manifest fields) above and does not overwrite them. It is not the package license, version, install count or a release record, and none of it is verified.

Evidence scope and limits
  • Each entry is one file at one pinned commit, and field states hold for that file only. Components that point to the same file are merged into one entry; files with identical content share one extraction.
  • “Declared in file” means the file's header has the field. “Not declared in this file” appears only when the header parsed successfully and lacks the field. “Invalid declaration” means the field is present but its type, length or characters do not meet the requirements; it is never rewritten or truncated. “Not read” means no usable header was obtained (not yet read, read failed, no header, or an unparseable header), which says neither that the field was declared nor that it was not.
  • Compatibility and license text are the file's own wording. They do not show that anything runs, are not legal advice, and are not a license verification. metadata.version is only an annotation inside the file; it is not the package version and is not used to judge which is newer.
  • This list groups the version's skill components by their recorded source. A listed source may still be unpinned, unread or unavailable; each entry shows its state. Collection runs in bounded batches and does not promise complete coverage.
  • A file whose read failed shows a “retry eligible” time. It is only when the collector may try again, not a schedule, and it does not promise a read or completion.

1–3 of 3 skill file sources · As of

  1. plugin/skills/add-and-validate-guardian-developer-semgrep-rule/SKILL.md

    Header parsed

    Components using this file 1

    • add-and-validate-guardian-developer-semgrep-rule plugin/skills/add-and-validate-guardian-developer-semgrep-rule/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    License text (declared in file, unverified)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    metadata.version (file annotation)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    Repository
    semgrep/guardian
    Pinned commit
    eee2e5094e704da376c6fc8aca108708a2487ef7
    File identity
    Regular-file identity recorded
    Blob SHA
    1a82312984bafeed940684f34b5be381d7b5dc29
    Mode
    100644
    Identity recorded
    Header parse
    Header parsed

    Extraction record

    First extracted by extractor version 1.

    First read from
    The same file as above.
  2. plugin/skills/install-mfw/SKILL.md

    Header parsed

    Components using this file 1

    • install-mfw plugin/skills/install-mfw/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    License text (declared in file, unverified)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    metadata.version (file annotation)
    Not declared in this fileThe header parsed and has no such field; true for this file only.
    Repository
    semgrep/guardian
    Pinned commit
    eee2e5094e704da376c6fc8aca108708a2487ef7
    File identity
    Regular-file identity recorded
    Blob SHA
    03f25ca0a20017b9c4a2bd601d6595ffea27af3c
    Mode
    100644
    Identity recorded
    Header parse
    Header parsed

    Extraction record

    First extracted by extractor version 1.

    First read from
    The same file as above.
  3. plugin/skills/remove-guardian-developer-semgrep-rule/SKILL.md

    Not read

    Components using this file 1

    • remove-guardian-developer-semgrep-rule plugin/skills/remove-guardian-developer-semgrep-rule/SKILL.md

    Fields declared in the file

    Compatibility (declared in file)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    License text (declared in file, unverified)
    Not readNo usable header, which says neither that it was declared nor that it was not.
    metadata.version (file annotation)
    Not readNo usable header, which says neither that it was declared nor that it was not.

    This file has no usable extraction record yet, so all three fields show as “Not read”.

    Repository
    semgrep/guardian
    Pinned commit
    eee2e5094e704da376c6fc8aca108708a2487ef7
    File identity
    Regular-file identity recorded
    Blob SHA
    3fa43d502f7477cdb98d182df29cbadd972e793c
    Mode
    100644
    Identity recorded
    Header parse
    Not read
    Why not read
    The file identity is recorded, but its content has not been read yet. declaration_unread

    No extraction record yet.

Read this page as JSON

All versions2

Each commit is an immutable snapshot, newest first. One version label can map to several commits.

VersionCommitCapturedComponentsActions
2.5.4 Latest eee2e50 9 View Download Diff vs previous Compare…
2.3.0 f97e1ce 7 View Download Compare…