codeql/semgrep skills must skip analysing vendored, third-party, and test code. see appsec.guide on how that could be done.