Li CodeQL LLM Security Scanner for Openclaw

A professional security automation skill that integrates CodeQL static analysis with LLM intelligence to detect, analyze, and prioritize code vulnerabilities.

43622283
v1.0.0
Mar 19, 2026
0
951
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install li-codeql-llm

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install li-codeql-llm using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Li CodeQL LLM Security Scanner?

The Li CodeQL LLM skill represents a significant leap in automated security auditing by merging the precision of GitHub's CodeQL engine with the contextual intelligence of Large Language Models. Built for the Openclaw Skills framework, this tool automates the tedious lifecycle of security scanning—from environment setup and database creation to the final report generation. It goes beyond simple pattern matching by using LLMs to interpret raw SARIF data, identifying false positives, and providing human-readable remediation advice tailored to the specific code context.

Li CodeQL LLM Security Scanner Use Cases

  • Automated security auditing for Python, JavaScript, Java, and Go projects to identify OWASP Top 10 vulnerabilities.
  • Enhancing DevSecOps pipelines by providing LLM-summarized security insights rather than just raw log files.
  • Rapid vulnerability research and exploit verification for security professionals and penetration testers.
  • Generating executable verification checklists to help developers confirm and fix security bugs effectively.

How Li CodeQL LLM Security Scanner Works

  1. Environment Verification: The skill checks for the CodeQL CLI and required language runtimes like Python or Java.
  2. Database Construction: It builds a relational representation of the target source code, ensuring all dependencies are accounted for.
  3. Deep Query Execution: Specialized security query suites are run against the database to identify complex data-flow issues and vulnerabilities.
  4. Intelligent Analysis: The skill extracts findings from SARIF results and utilizes an LLM to evaluate the severity and exploitability of each issue.
  5. Artifact Generation: It produces standardized SARIF files alongside human-centric Markdown reports and actionable verification checklists.

Li CodeQL LLM Security Scanner Setup

To get started with this addition to your Openclaw Skills library, ensure you have the CodeQL CLI installed.

# Download and install CodeQL CLI
wget https://github.com/github/codeql-cli-binaries/releases/latest/download/codeql-linux64.zip
unzip codeql-linux64.zip -d /opt/codeql
ln -s /opt/codeql/codeql/codeql /usr/local/bin/codeql

# Verify installation
codeql --version

Once installed, you can trigger a scan by providing the project path to the AI agent.

Li CodeQL LLM Security Scanner Data Schema & Taxonomy

The Li CodeQL LLM skill organizes its output into structured reports and standardized formats to ensure interoperability within Openclaw Skills workflows:

Output File Description
CODEQL_SECURITY_REPORT.md A comprehensive executive summary including severity distribution and code-level fix suggestions.
Vulnerability_Checklist.md An actionable list for security testers including payloads, expected results, and verification steps.
codeql-results.sarif Standardized Static Analysis Results Interchange Format for use in IDEs or CI/CD dashboards.

Li CodeQL LLM Security Scanner Advanced Features

  • Multi-agent support: Works with other Openclaw Skills to trigger automated patching or PR reviews.
  • Custom Query Suites: Support for security-extended, code-quality, and custom .qls configurations.
  • LLM Payload Generation: Automatically generates Proof-of-Concept (PoC) payloads for identified vulnerabilities like SQL injection or RCE.
  • CI/CD Integration: Ready-to-use patterns for GitHub Actions and Jenkins environments.
  • False Positive Filtering: Uses AI to reduce noise by analyzing the logic flow of detected issues.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*