Security Reviewer (jeffallan) vs Semgrep Rule Creator (trailofbits)
Security Reviewer (jeffallan) and Semgrep Rule Creator (trailofbits) are both Security skills, so an agent choosing between them is matching on descriptions that overlap. Here is where they actually diverge.
Security Reviewer
jeffallan
Performs end-to-end security examinations of code, infrastructure, dependencies and secrets and compiles a prioritized audit report that assigns severity to each finding and lists concrete remediation steps. Unlike tools that only add inline comments, check authentication patterns, or scan a branch diff, this one is aimed at producing a compliance-aware, prioritized audit document rather than a quick pre-merge or single-file review.
1 scenario in the bank answer to it
Semgrep Rule Creator
trailofbits
Authors a custom Semgrep static-analysis rule for one specific bug or vulnerability pattern — building the match (or a taint-mode source-to-sink data flow), then the paired vulnerable-and-safe test cases that keep false positives in check. Its output is a reusable detection rule, not a finished audit: it does not run existing Semgrep rulesets over your repo, triage the findings a scan produces, or review a diff by hand.
1 scenario in the bank answer to it
What is the difference between Security Reviewer (jeffallan) and Semgrep Rule Creator (trailofbits)?
- Security Reviewer (jeffallan)
- Performs end-to-end security examinations of code, infrastructure, dependencies and secrets and compiles a prioritized audit report that assigns severity to each finding and lists concrete remediation steps. Unlike tools that only add inline comments, check authentication patterns, or scan a branch diff, this one is aimed at producing a compliance-aware, prioritized audit document rather than a quick pre-merge or single-file review.
- Semgrep Rule Creator (trailofbits)
- Authors a custom Semgrep static-analysis rule for one specific bug or vulnerability pattern — building the match (or a taint-mode source-to-sink data flow), then the paired vulnerable-and-safe test cases that keep false positives in check. Its output is a reusable detection rule, not a finished audit: it does not run existing Semgrep rulesets over your repo, triage the findings a scan produces, or review a diff by hand.
Should I use Security Reviewer or Semgrep Rule Creator?
The clearest answer is a situation each one is unambiguously right for. Both of these are drawn from the game's question bank.
Reach for Security Reviewer when
An auditor is coming and wants one document that grades the whole system — app code, servers, third-party libraries, leaked secrets — with a severity on every issue and a fix for each, ranked worst-first.
security-reviewer-jeffallan produces the end-to-end, severity-ranked audit document spanning code, infrastructure, dependencies and secrets. security-review-owasp and security-review-waybarrios only look at a diff or branch for exploits; security-review-affaan-m is build-time guidance, not an audit. The tell is a ranked document across the whole system.
Reach for Semgrep Rule Creator when
At a security audit you discover your app mishandles a proprietary protocol in a way command-line scanners default ignore. You need to codify a narrowly scoped gatekeeper with paired illustrations to avoid noisy CI runs.
The skill is designed for narrowing the focus to exactly one novel weakness in code, teaching how to build a pair of contrasting code snippets and package them into a portable, reusable gatekeeper that plugs into CI. That fits here because the bug is proprietary and off-the-shelf checkers are blind to it, so you need a self-contained, narrowly scoped artifact with paired positive and negative illustrations rather than a supply-chain sweep, a generic error-message rewrite, or an identity breach lookup.
What they have in common
Both are filed under Security, the axis along which they collide. That shared ground is what makes an agent pick between them on description alone — and what makes it pick wrong.
Nearby comparisons
Reading the difference is not the same as spotting it at speed. That is the game.
Today's session