---
title: semgrep vs trail-of-bits
slug: semgrep-scan-vs-trail-of-bits
type: skill-comparison
a: semgrep-scan
b: trail-of-bits
category: security-auditing
canonical: https://top-agent-skills.com/compare-skills/semgrep-scan-vs-trail-of-bits
published: 2026-08-19
updated: 2026-08-19
---

# semgrep vs trail-of-bits

Pick semgrep when you want machine findings: it runs the Semgrep engine across 30-plus languages and lets you author custom YAML rules for patterns specific to your codebase. Pick trail-of-bits when you want expert review method applied to a change — the reasoning a scanner cannot encode. Scanners find known patterns; review finds the design mistake that created them, so mature teams run both.

## Pick semgrep when

You want reproducible, gate-able findings in CI, and the ability to encode a house rule as a scanner rule rather than a review comment.

## Pick trail-of-bits when

You want a severity-tagged review of a specific change, including the architectural and cryptographic judgement a pattern matcher cannot express.

## Side by side

| | semgrep | trail-of-bits |
| --- | --- | --- |
| What it does | Runs the Semgrep engine; authors custom YAML rules | Applies a security firm's review method to code |
| Output | Findings with rule IDs — gate-able | Severity-tagged review prose |
| Coverage | 30+ languages, pattern-based | Judgement-based, not language-limited |
| Custom rules | Yes — writing rules is a first-class use | No |
| Needs a CLI | Yes — the semgrep CLI (or its MCP tools) | No |
| Licence | Semgrep Rules License v1.0 — not OSI | Apache-2.0 |
| Capability | Action-taking — runs scans | Read-only |

## Bottom line

These are complements with a licence caveat worth knowing. semgrep is the right default for anything you want to run repeatedly and block a merge on, and its custom-rule authoring is the cheapest way to make a house convention enforceable. trail-of-bits is what you reach for on the change that actually matters, where the question is whether the design is sound rather than whether a known pattern appears. Note that Semgrep ships its skill under its own Rules License rather than MIT or Apache — read it before vendoring the rules into a commercial product.

## Common questions

**Do I need both a scanner skill and a review skill?**

For code that handles auth, untrusted input, secrets or money, yes. They fail differently: a scanner misses the novel mistake, and a review pass misses the boring instance of a known pattern buried in a large diff. Running one and calling it security is the common gap.

**Is the Semgrep skill open source?**

Not under an OSI licence. Its repository ships the Semgrep Rules License v1.0, which GitHub reports as "Other". The skill is free to use; redistributing or vendoring the rules is what the licence governs, so read it before shipping them inside a product.

**Does semgrep need an API key?**

No. It needs the semgrep CLI installed locally (brew or pip), and it will use Semgrep MCP tools if they are available. There is no key requirement for scanning your own code.

Entries: https://top-agent-skills.com/skill/semgrep-scan · https://top-agent-skills.com/skill/trail-of-bits
Category: https://top-agent-skills.com/top-skills-for-security-auditing

---

_Top Agent Skills. Machine-readable twin of https://top-agent-skills.com/compare-skills/semgrep-scan-vs-trail-of-bits._
