Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
semgrep-rules β€” Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple languages. | Kitploit
Tools/GitHubGitHub/trailofbits/semgrep-rules
Static AnalysisVulnerability AnalysisCode AnalysisDevSecOpsMisconfiguration
GitHubtrailofbits/semgrep-rules

semgrep-rules

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple languages.

View Repository
531591054 months agoReviewed by Kitploit

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

Trail of Bits public Semgrep rules

This repository contains Semgrep rules developed by Trail of Bits and made available to the public. They are part of our ongoing development efforts and are used in our security audits, vulnerability reseach, and internal projects. They will evolve over time as we identify new techniques.

Visit Testing Handbook for Semgrep guidance.

Using Semgrep

The easiest way to run the rules is to run them from the Semgrep registry. To do so, navigate to the root folder of your project and run the following:

$ semgrep --config "p/trailofbits"

Alternatively, you can clone this repository, navigate to the root folder of your project, and run individual rules using the command below :

$ semgrep --config /path/to/semgrep-rules/semgreprule.yml

To run all rules from the cloned repository:

$ semgrep --config /path/to/semgrep-rules/ .

Useful flags

Semgrep will run against all supported code files except for those in your .gitignore file. If you want to run the rules against all files and directories, including those in your .gitignore, add the --no-git-ignore flag.

$ semgrep --config /path/to/semgrep-rules/ . --no-git-ignore

You can also tell Semgrep to ignore files and directories that match any pattern. For instance, if you want to tell Semgrep to ignore all Go test files you can run the following:

$ semgrep --config /path/to/semgrep-rules/ . --exclude='*_test.go'

Use -o to output results to a file:

$ semgrep --config /path/to/semgrep-rules/hanging-goroutine.yml -o leaks.txt'

Rules

go

IDPlaygroundImpactConfidenceDescription
eth-rpc-tracetransactionπŸ›πŸ”—πŸŸ₯πŸŒ•Detects attempts to extract trace information from an EVM transaction or block. In exchange or bridge applications, extra logic must be implemented encapsulating these endpoints to prevent the values transferred during reverted call frames from being counted.
eth-txreceipt-statusπŸ›πŸ”—πŸŸ₯πŸŒ•Detects when a transaction receipt's status is read
hanging-goroutineπŸ›πŸ”—πŸŸ©πŸŒ—Goroutine leaks
invalid-usage-of-modified-variableπŸ›πŸ”—πŸŸ§πŸŒ˜Possible unintentional assignment when an error occurs
iterate-over-empty-mapπŸ›πŸ”—πŸŸ©πŸŒ—Probably redundant iteration over an empty map
missing-runlock-on-rwmutexπŸ›πŸ”—πŸŸ§πŸŒ—Missing RUnlock on an RWMutex lock before returning from a function
missing-unlock-before-returnπŸ›πŸ”—πŸŸ§πŸŒ—Missing mutex unlock before returning from a function
nil-check-after-callπŸ›πŸ”—πŸŸ§πŸŒ—Possible nil dereferences
racy-append-to-sliceπŸ›πŸ”—πŸŸ§πŸŒ—Concurrent calls to append from multiple goroutines
racy-write-to-mapπŸ›πŸ”—πŸŸ§πŸŒ—Concurrent writes to the same map in multiple goroutines
servercodec-readrequestbody-unhandled-nilπŸ›πŸ”—πŸŸ©πŸŒ˜Possible incorrect ServerCodec interface implementation
string-to-int-signedness-castπŸ›πŸ”—πŸŸ§πŸŒ˜Integer underflows
sync-mutex-value-copiedπŸ›πŸ”—πŸŸ©πŸŒ˜Copying of sync.Mutex via value receivers
unmarshal-tag-is-dashπŸ›πŸ”—πŸŸ§πŸŒ˜
unmarshal-tag-is-omitemptyπŸ›πŸ”—πŸŸ©πŸŒ˜
unsafe-dll-loadingπŸ›πŸ”—πŸŸ₯🌘Use of function vulnerable to DLL hijacking attacks
waitgroup-add-called-inside-goroutineπŸ›πŸ”—πŸŸ§πŸŒ—Calls to sync.WaitGroup.Add inside of anonymous goroutines
waitgroup-wait-inside-loopπŸ›πŸ”—πŸŸ§πŸŒ—Calls to sync.WaitGroup.Wait inside a loop

python

Download Tool