semgrep_scan
Run deterministic static analysis over repository files to substantiate suspected defects, returning exact line numbers and matched source snippets for direct review.
Instructions
Run deterministic static analysis (Semgrep) over repository files and return findings with exact line numbers plus the matched source snippet.
Use this to substantiate a suspected defect rather than guessing at it: the results are rule matches, so a hit is a fact. The snippet can be reused directly as existing_code when emitting a comment.
Scope paths to the file currently under review. OpenCodeReview only allows comments on the file being reviewed, so findings in other files cannot be reported even when the tool returns them.
An empty result is not a clean bill of health — it means no configured rule matched. The ruleset is broad but not exhaustive.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| paths | Yes | ||
| ruleset | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |