Back to Skills

sarif-parsing

Parses and processes SARIF files from static analysis tools like CodeQL, Semgrep, or other scanners. Triggers on "parse sarif", "read scan results", "aggregate findings", "deduplicate alerts", or "process sarif output". Handles filtering, deduplication, format conversion, and CI/CD integration of SARIF data. Does NOT run scans — use the Semgrep or CodeQL skills for that.

5,266stars466forksUpdated 5/18/2026

Security Assessment

Safe(100/100)
Security Score100/100

About sarif-parsing

The sarif-parsing skill is designed to efficiently process and analyze SARIF (Static Analysis Results Interchange Format) files generated by tools like CodeQL, Semgrep, and other static analysis scanners. It addresses the challenge of managing and interpreting large volumes of static analysis data, enabling users to read scan results, aggregate findings, deduplicate alerts, and convert SARIF output for further use. By focusing exclusively on processing existing scan results rather than performing scans, this skill streamlines the post-analysis workflow and ensures that security and development teams can work effectively with standardized SARIF data.

Key features of this skill include filtering, deduplication, format conversion, and CI/CD integration of SARIF files. It supports detailed exploration of findings, including severity levels, rule IDs, file locations, and fingerprints for stable tracking across multiple analysis runs. Users can leverage command-line tools like jq for quick queries or Python libraries such as pysarif and sarif-tools for more advanced scripting. The skill also guides users in selecting appropriate tools for different programming environments and validating SARIF files according to the OASIS 2.1.0 standard.

This skill is particularly useful for developers, security engineers, and DevOps professionals who need to interpret static analysis results without manually combing through raw scan outputs. Typical use cases include aggregating findings from multiple scanners, deduplicating recurring alerts, integrating security results into automated CI/CD pipelines, and converting SARIF data to alternative formats for reporting or further analysis. By providing structured and repeatable processing capabilities, sarif-parsing enables teams to maintain a clear and consistent understanding of code vulnerabilities and quality issues across projects and analysis runs.

FAQ

Can I use sarif-parsing to run static analysis scans?

No, this skill is only for processing existing SARIF files. To perform scans, use the CodeQL or Semgrep skills.

Which tools are compatible with sarif-parsing?

It works with SARIF files generated by any standard-compliant static analysis tool, including CodeQL, Semgrep, and others. You can use Bash, jq, or Python libraries like pysarif and sarif-tools for processing.

Can this skill deduplicate and filter findings?

Yes, it supports deduplication of alerts, filtering by severity or rule ID, and aggregation of results across multiple scans.

Is this skill suitable for CI/CD integration?

Yes, sarif-parsing can be integrated into CI/CD pipelines to process SARIF results automatically and track changes between runs.

Does it require fingerprints in SARIF files?

While not strictly required, stable fingerprints are recommended to track findings reliably across multiple runs and environments.

All Files

3 files
SKILL.md14.8 KB
View
resources/sarif_helpers.py9.9 KB
View
resources/jq-queries.md5.1 KB
View

Install sarif-parsing

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill