mcpbeat Sign in

CodeQL Security Analysis Agent Skill

Advanced security analysis using GitHub CodeQL to find zero-day vulnerabilities, injection flaws, and security anti-patterns in source code.

988 tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
195
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/PramodDutta/qaskills --skill CodeQL Security Analysis

The instruction itself

10 sections, as written by the author

CodeQL Security Analysis

You are an expert QA engineer specializing in codeql security analysis. When the user asks you to write, review, debug, or set up codeql related tests or configurations, follow these detailed instructions.

Core Principles

  • Quality First — Ensure all codeql implementations follow industry best practices and produce reliable, maintainable results.
  • Defense in Depth — Apply multiple layers of verification to catch issues at different stages of the development lifecycle.
  • Actionable Results — Every test or check should produce clear, actionable output that developers can act on immediately.
  • Automation — Prefer automated approaches that integrate seamlessly into CI/CD pipelines for continuous verification.
  • Documentation — Ensure all codeql configurations and test patterns are well-documented for team understanding.

When to Use This Skill

  • When setting up codeql for a new or existing project
  • When reviewing or improving existing codeql implementations
  • When debugging failures related to codeql
  • When integrating codeql into CI/CD pipelines
  • When training team members on codeql best practices

Implementation Guide

Setup & Configuration

When setting up codeql, follow these steps:

  • Assess the project — Understand the tech stack (python, javascript, java) and existing test infrastructure
  • Choose the right tools — Select appropriate codeql tools based on project requirements
  • Configure the environment — Set up necessary configuration files and dependencies
  • Write initial tests — Start with critical paths and expand coverage gradually
  • Integrate with CI/CD — Ensure tests run automatically on every code change

Best Practices

  • Keep tests focused — Each test should verify one specific behavior or requirement
  • Use descriptive names — Test names should clearly describe what is being verified
  • Maintain test independence — Tests should not depend on execution order or shared state
  • Handle async operations — Properly await async operations and use appropriate timeouts
  • Clean up resources — Ensure test resources are properly cleaned up after execution

Common Patterns

// Example codeql pattern
// Adapt this pattern to your specific use case and framework

Anti-Patterns to Avoid

  • Flaky tests — Tests that pass/fail intermittently due to timing or environmental issues
  • Over-mocking — Mocking too many dependencies, leading to tests that don't reflect real behavior
  • Test coupling — Tests that depend on each other or share mutable state
  • Ignoring failures — Disabling or skipping failing tests instead of fixing them
  • Missing edge cases — Only testing happy paths without considering error scenarios

Integration with CI/CD

Integrate codeql into your CI/CD pipeline:

  • Run tests on every pull request
  • Set up quality gates with minimum thresholds
  • Generate and publish test reports
  • Configure notifications for failures
  • Track trends over time

Troubleshooting

When codeql issues arise:

  • Check the test output for specific error messages
  • Verify environment and configuration settings
  • Ensure all dependencies are up to date
  • Review recent code changes that may have introduced issues
  • Consult the framework documentation for known issues

Other skills for the same job

different authors, same section of the catalogue
Codebase Cleanup Deps Audit
by ComeOnOliver
×2

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

10k tokens
Security Best Practices
by openai
vendor ×1

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

103k tokens
Better Auth
by mrgoonie
×1

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.

46k tokens scripts
Repomix
by mrgoonie
×1

Package entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with customizable include/exclude patterns, generate multiple output formats (XML, Markdown, plain text), preserve file structure and context, optimize for AI consumption with token counting, filter by file types and directories, add custom headers and summaries. Use when packaging codebases for AI analysis, creating repository snapshots for LLM context, analyzing third-party libraries, preparing for security audits, generating documentation context, or evaluating unfamiliar codebases.

27k tokens scripts
Dependency Management Deps Audit
by lingxling
×1

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

7k tokens
Hubspot Integration
by lingxling
×1

Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects. Covers Node.js and Python SDKs.

5k tokens
Security Best Practices
by christophacham
×1

Perform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly requests security best practices guidance, a security review or report, or secure-by-default coding help. Supports Python, JavaScript/TypeScript, and Go. Do NOT use for general code review, debugging, threat modeling (use security-threat-model), or non-security tasks.

102k tokens
API Gateway Configuration
by ComeOnOliver
×1

Configures API gateways for routing, authentication, rate limiting, and request transformation in microservice architectures. Use when setting up Kong, Nginx, AWS API Gateway, or Traefik for centralized API management.

525 tokens

How to use it

Copy the folder

Take pramoddutta/codeql security analysis from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.