Why this server?
Direct integration of the Semgrep static analysis tool, allowing users to perform static code analysis, manage rules, and process scan results for security and code quality checks.
Alicense-qualityDmaintenanceEnables integration of Semgrep in development environments via the MCP protocol, supporting static code analysis, rule management, and scan result operations.2MITWhy this server?
Provides a comprehensive interface to Semgrep for scanning code for security vulnerabilities, creating custom rules, and analyzing scan results through the Model Context Protocol.

Semgrep MCP Serverofficial
AlicenseBqualityFmaintenanceAn MCP server that provides a comprehensive interface to Semgrep, enabling users to scan code for security vulnerabilities, create custom rules, and analyze scan results through the Model Context Protocol.6683MITWhy this server?
A specific implementation integrating the Semgrep static analysis tool with AI assistants like Claude for advanced code analysis and security vulnerability detection.
AlicenseBqualityAmaintenanceA Model Context Protocol compliant server that integrates Semgrep static analysis tool with AI assistants like Anthropic Claude, enabling advanced code analysis, security vulnerability detection, and code quality improvements through a conversational interface.78028MITWhy this server?
Integrates static application security testing (SAST) tools, specifically mentioning Semgrep as one of the 15+ integrated tools for security analysis.
Alicense-qualityBmaintenanceIntegrates 15+ static application security testing tools (Semgrep, Bandit, TruffleHog, etc.) with Claude Code AI, enabling automated vulnerability scanning and security analysis through natural language commands. Supports cross-platform operation with remote execution on dedicated security VMs.6MITWhy this server?
Enables security scanning of codebases for vulnerabilities, a general category directly relevant to Semgrep's function.
Alicense-qualityBmaintenanceEnables security scanning of codebases through integrated tools for secret detection, SCA, SAST, and DAST vulnerabilities, with AI-powered remediation suggestions based on findings.MITWhy this server?
A specialized security tool for scanning vulnerabilities, similar in function to Semgrep, making it a highly relevant alternative or complementary service.
Alicense-qualityFmaintenanceProvides Trivy security scanning capabilities through a standardized interface, allowing users to scan projects for vulnerabilities and automatically fix them by updating dependencies.10MITWhy this server?
Enables comprehensive security scanning of code repositories to detect secrets, vulnerabilities, and configuration problems, matching Semgrep's core purpose.
Alicense-qualityDmaintenanceEnables comprehensive security scanning of code repositories to detect secrets, vulnerabilities, dependency issues, and configuration problems. Provides real-time security checks and best practice recommendations to help developers identify and prevent security issues.122MITWhy this server?
An advanced code search and transformation MCP server for AI assistants, providing functionality relevant to static analysis and code hygiene.
AlicenseBqualityDmaintenanceAdvanced code search and transformation MCP server for AI assistants. Combines ugrep's speed with intelligent replace capabilities, dry-run previews, and language-aware refactoring across 11 tools.19MITWhy this server?
Enables comprehensive GitHub PR reviews by integrating static analysis tools (like Semgrep) to provide structured reports and fix suggestions, directly utilizing Semgrep-like capabilities.
-licenseCquality-maintenanceEnables comprehensive GitHub PR reviews through Cursor's AI by fetching PR diffs, running static analysis tools (ESLint, Prettier, TypeScript, Semgrep), executing tests, and generating detailed code review reports with inline comments.92,5041