greprules.io docs

greprules.io is a community-oriented registry for reusable SAST rules. Search, inspect, and fetch rules for OpenGrep and coding-agent workflows.

What greprules provides

The registry helps teams discover rules that are reusable outside a single scanner or repository. Each rule page focuses on the information needed before local use: language, severity, license, source, validation status, trust signals, references, and fetch commands.

  • Curated CVE and 1-day rules with source and license context.
  • Rule packs that group related rules for local OpenGrep scans.
  • Agent plugin workflows for fetching packs and scanning code from coding agents.
  • Author profiles, authenticated stars, and trust signals for community discovery.
Agent pluginInstall greprules for Claude Code, Codex, or Hermes, then verify OpenGrep readiness.APIFetch public rules, YAML, and rule pack tarballs from the registry API.Open sourceUnderstand what Greprules publishes as open source and how Provally stewards the project.Trust policyReview the signals behind trust scores, validation badges, and official labels.ContributingRule publishing is not open yet; see what is available now and what will open later.