by semgrep
Semgrep is a leading code analysis tool that scans code for vulnerabilities, helping developers fix issues swiftly withi
★ 638
GitHub stars
Runs Semgrep static analysis scans to find security vulnerabilities and code quality issues in your code. Can scan with built-in rules or custom rules you create.
Semgrep is an official MCP server published by semgrep that provides AI assistants with tools and capabilities via the Model Context Protocol. Semgrep is a leading code analysis tool that scans code for vulnerabilities, helping developers fix issues swiftly withi It is categorized under auth security, developer tools. This server exposes 8 tools that AI clients can invoke during conversations and coding sessions.
You can install Semgrep in your AI client of choice. Use the install panel on this page to get one-click setup for Cursor, Claude Desktop, VS Code, and other MCP-compatible clients. This server supports remote connections over HTTP, so no local installation is required.
MIT
Semgrep is released under the MIT license. This is a permissive open-source license, meaning you can freely use, modify, and distribute the software.
Add new capabilities to Claude beyond text generation
Example
Access external data sources, execute code, interact with tools and services
Transform Claude from chatbot to action-taking agent
Provide Claude with access to relevant context and data
Example
Load project documentation, access knowledge bases, query databases
Get more accurate, context-aware responses
Automate multi-step workflows combining AI and external tools
Example
Research → Summarize → Create document → Send notification
Complete complex tasks end-to-end without manual steps
Share your MCP server with the developer community
Semgrep reduced integration guesswork — categories and install configs on the listing matched the upstream repo.
Semgrep has been reliable for tool-calling workflows; the MCP profile page is a good permalink for internal docs.
Semgrep is among the better-indexed MCP projects we tried; the explainx.ai summary tracks the official description.
Semgrep is among the better-indexed MCP projects we tried; the explainx.ai summary tracks the official description.
Strong directory entry: Semgrep surfaces stars and publisher context so we could sanity-check maintenance before adopting.
Strong directory entry: Semgrep surfaces stars and publisher context so we could sanity-check maintenance before adopting.
Semgrep is among the better-indexed MCP projects we tried; the explainx.ai summary tracks the official description.
Useful MCP listing: Semgrep is the kind of server we cite when onboarding engineers to host + tool permissions.
According to our notes, Semgrep benefits from clear Model Context Protocol framing — fewer ambiguous “AI plugin” claims.
We wired Semgrep into a staging workspace; the listing’s GitHub and npm pointers saved time versus hunting across READMEs.
showing 1-10 of 54
Semgrep is a leading code analysis tool that scans code for vulnerabilities, helping developers fix issues swiftly withi
TL;DR: Runs Semgrep static analysis scans to find security vulnerabilities and code quality issues in your code. Can scan with built-in rules or custom rules you create.
Prerequisites
Time Estimate
15-60 minutes depending on server complexity
Steps
Troubleshooting
✓ Do
✗ Don't
💡 Pro Tips
Architecture
Model Context Protocol standardizes how AI hosts (Claude, Cursor) communicate with external tools and data sources through server implementations.
Protocols
Compatibility
✓ Use when
Use when you need Claude to access external data, execute actions, or integrate with tools. Best for extending AI capabilities beyond conversation.
✗ Avoid when
Avoid when native integrations exist (use official APIs directly), for real-time critical systems, or when security/compliance requires zero external dependencies.