Isn't "grep for code" called just "grep"?
Here’s an elaborate example: https://semgrep.dev/s/ievans:c-dataflow
Lots of workarounds it wouldn't find, like:
import builtins
builtins.print("whee")I don't think you can go in with the mindset that it will catch everything, but rather, it's about being able to iterate quickly with your rules.