🔍
QualityPython

CodeQL Analysis

by waybarrios

CodeQL Analysis is a Quality skill for Claude Code, published by waybarrios in opencode-power-pack.

482 stars39 forkson waybarrios/opencode-power-packAdded 2026/08/26+2% in starsRepository updated 2026/08/24
ai-agentsanthropicclaude-codecode-reviewcodexcodex-clideveloper-toolsgradiohuggingfacellm-toolsmachine-learningml-trainingopenai-codexopencodepipi-coding-agentpi-packagepluginsecurity-auditskills
Install in seconds
Install CodeQL Analysis
Copy CodeQL Analysis into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/waybarrios/opencode-power-pack/tree/main/skills/codeql ~/.claude/skills/codeql

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/waybarrios/opencode-power-pack.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/codeql/SKILL.md in waybarrios/opencode-power-pack
Installs to
~/.claude/skills/codeql
Collection
One of 25 skills cataloged from this repository
Category
Quality1354 skills

What CodeQL Analysis does

CodeQL Analysis runs CodeQL database creation, data extensions, and security queries, and can process SARIF output. Use it when CodeQL is explicitly requested or when you need deeper taint-flow security analysis.

CodeQL Analysis is cataloged under Quality on DirSkills. CodeQL Analysis comes from a repository tagged ai-agents, anthropic, claude-code, code-review and codex.

Documentation

README

CodeQL Analysis

Supported languages: Python, JavaScript/TypeScript, Go, Java/Kotlin, C/C++, C#, Ruby, Swift.

Skill resources: Reference files and templates are located at references/ and workflows/.

Essential Principles

  1. Database quality is non-negotiable. A database that builds is not automatically good. Always run quality assessment (file counts, baseline LoC, extractor errors) and compare against expected source files. A cached build produces zero useful extraction.

  2. Data extensions catch what CodeQL misses. Even projects using standard frameworks (Django, Spring, Express) have custom wrappers around database calls, request parsing, or shell execution. Skipping the create-data-extensions workflow means missing vulnerabilities in project-specific code paths.

This is the opening of the README. Read the full README on GitHub.

Frequently asked about CodeQL Analysis

  • What else does waybarrios publish alongside CodeQL Analysis?

    CodeQL Analysis is one of 25 skills that DirSkills catalogs from waybarrios/opencode-power-pack, the repository it ships in. Its siblings there include AI Slop Rubric, AWS Context Discovery and Agentic Actions Auditor. Each one is a separate skill with its own page in this directory, installs the same way CodeQL Analysis does, and is maintained by waybarrios in that same repository. The rest of the collection is listed on the waybarrios/opencode-power-pack page.

  • How does CodeQL Analysis compare to other Quality skills?

    CodeQL Analysis ranks #1260 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of CodeQL Analysis against them. Open each page to compare what they document and how they install.

More from waybarrios/opencode-power-pack

CodeQL Analysis is one of 25 skills cataloged on DirSkills from waybarrios/opencode-power-pack.

See all 25 skills
🧩
5d ago

AI Slop Rubric

AI Slop Rubric defines observable signs of generic or poorly grounded interface design, with severity levels, evidence needs, and repair actions. Use it to review marketing sites, product pages, dashboards, portfolios, and e-commerce layouts.
Frontend
48239
☁️
5d ago

AWS Context Discovery

AWS Context Discovery reads the local AWS profile, region, account, and caller identity before AWS or SageMaker work. Use it when cloud context is needed and you want to avoid guessing configuration.
DevOps
48239
🛡️
5d ago

Agentic Actions Auditor

Agentic Actions Auditor reviews GitHub Actions workflows that invoke AI agents for prompt injection, unsafe interpolation, sandbox gaps, and permissive actor rules. Use it when auditing agentic CI workflows and cross-file references in Actions configs.
Quality
48239
📝
5d ago

Agents MD Revise

Agents MD Revise captures recurring learnings from a session into AGENTS.md, CLAUDE.md, or a local override so future sessions have the same context. Use it when you need to remember project-specific commands, conventions, or gotchas.
Writing
48239
🧭
5d ago

Agents Md Improver

Agents Md Improver audits AGENTS.md, CLAUDE.md, and related rules files for coverage, clarity, and freshness. Use it when project rules need review or targeted updates after code changes.
AI Engineering
48239
🏗️
5d ago

Code Architect

Code Architect analyzes an existing codebase’s patterns and conventions to produce an implementation blueprint for a non-trivial feature. Use it when planning architecture, file changes, component design, data flow, and build steps.
AI Engineering
48239