Semgrep Scan
semgrep_scanScan source code with Semgrep to detect security vulnerabilities. Passive analysis of workspace files using customizable rules.
Instructions
Run Semgrep (plugin class D) over source in the engagement workspace.
Passive: reads files already fetched into the workspace and sends nothing to the target. Rules in rules/semgrep/ always participate; config may add a registry pack ('p/security-audit') or another workspace path.
Use source_fetch first to bring a repository into the workspace.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | source | |
| config | No | ||
| severity | No | ||
| wait_seconds | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||