CodeQL Code Scanning
Independent PiSkill directory guide. The original skill remains hosted by GitHub Awesome Copilot.
What is CodeQL Code Scanning?
Guides CodeQL code scanning through GitHub Actions and the CodeQL CLI, including workflow setup, language configuration, query suites, SARIF output, monorepos, and troubleshooting.
What does CodeQL Code Scanning do?
CodeQL Code Scanning is a GitHub Awesome Copilot skill for setting up and troubleshooting static security analysis with CodeQL. It covers GitHub Actions workflows, default versus advanced setup, language and build-mode configuration, query suites, the CodeQL CLI, SARIF output and monorepo scanning.
Who is CodeQL Code Scanning best for?
- Teams enabling GitHub code scanning
- Security engineers customizing CodeQL workflows
- Developers troubleshooting CodeQL builds
- Monorepos that need language- or component-specific analysis
Common use cases
- Create a CodeQL GitHub Actions workflow
- Choose languages, build modes and query suites
- Run CodeQL locally with the CLI
- Generate or upload SARIF security results
How does CodeQL Code Scanning work?
The skill chooses between default and advanced setup, configures workflow triggers and least-privilege permissions, defines the language matrix and build mode, initializes and runs analysis, and helps separate results for monorepos. It also covers creating local CodeQL databases and analyzing them with the CLI.
Key benefits
- Supports both GitHub Actions and local CLI workflows
- Covers multiple major programming languages
- Handles monorepo and custom query scenarios
- Connects scanning output to SARIF-based security workflows
Things to know
- CodeQL only analyzes supported languages and query coverage
- Static analysis can produce false positives or miss runtime flaws
- Compiled languages may require project-specific build setup
Compatible tools
Frequently asked questions
What does the CodeQL Code Scanning skill help configure?
Can CodeQL scan JavaScript and TypeScript together?
Related skills
Agent Governance
Adds governance, policy, trust, audit, access-control, and safety patterns to AI-agent systems that call tools, APIs, databases, or other external systems.
Prompt Engineering Safety Review
Reviews prompts for safety, bias, security weaknesses, prompt-injection risk, effectiveness, and testing gaps, then provides structured improvements and safer prompt-engineering guidance.
Secret Scanning
Finds exposed secrets and risky credential patterns in repositories, distinguishes likely findings from noise, and recommends safe rotation and remediation steps.
Agent OWASP Compliance
Reviews an AI-agent codebase against the OWASP Agentic Security Initiative Top 10 and produces structured security and compliance findings for agentic systems.
Security Review
Performs an AI-assisted application security review that traces data flows and looks for injection flaws, broken access control, leaked secrets, weak cryptography, vulnerable dependencies, and business-logic issues.
AWS IAM
Provides verified IAM guidance for policy evaluation, trust relationships, least-privilege role creation, STS sessions, condition operators, and common security edge cases.