Why this server?
Direct integration of the Semgrep static analysis tool, allowing users to perform static code analysis, manage rules, and process scan results for security and code quality checks.
-securityAlicense-qualityEnables integration of Semgrep in development environments via the MCP protocol, supporting static code analysis, rule management, and scan result operations.Last updated2MITWhy this server?
Provides a comprehensive interface to Semgrep for scanning code for security vulnerabilities, creating custom rules, and analyzing scan results through the Model Context Protocol.

Semgrep MCP Serverofficial
AsecurityAlicense-qualityAn MCP server that provides a comprehensive interface to Semgrep, enabling users to scan code for security vulnerabilities, create custom rules, and analyze scan results through the Model Context Protocol.Last updated6649MITWhy this server?
A specific implementation integrating the Semgrep static analysis tool with AI assistants like Claude for advanced code analysis and security vulnerability detection.
-securityAlicense-qualityA Model Context Protocol compliant server that integrates Semgrep static analysis tool with AI assistants like Anthropic Claude, enabling advanced code analysis, security vulnerability detection, and code quality improvements through a conversational interface.Last updated33427MITWhy this server?
Integrates static application security testing (SAST) tools, specifically mentioning Semgrep as one of the 15+ integrated tools for security analysis.
-securityAlicense-qualityIntegrates 15+ static application security testing tools (Semgrep, Bandit, TruffleHog, etc.) with Claude Code AI, enabling automated vulnerability scanning and security analysis through natural language commands. Supports cross-platform operation with remote execution on dedicated security VMs.Last updated5MITWhy this server?
Enables intelligent semantic search and discovery of relevant Claude Agent Skills using vector embeddings, likely useful for finding or managing Semgrep-related skills or configurations.
-securityAlicense-qualityEnables intelligent semantic search and discovery of relevant Claude Agent Skills using vector embeddings. Provides access to curated scientific skills and supports both GitHub repositories and local skill directories.Last updated374MITWhy this server?
Enables security scanning of codebases for vulnerabilities, a general category directly relevant to Semgrep's function.
-securityAlicense-qualityEnables security scanning of codebases through integrated tools for secret detection, SCA, SAST, and DAST vulnerabilities, with AI-powered remediation suggestions based on findings.Last updatedMITWhy this server?
A specialized security tool for scanning vulnerabilities, similar in function to Semgrep, making it a highly relevant alternative or complementary service.
-securityAlicense-qualityProvides Trivy security scanning capabilities through a standardized interface, allowing users to scan projects for vulnerabilities and automatically fix them by updating dependencies.Last updated10MITWhy this server?
Enables comprehensive security scanning of code repositories to detect secrets, vulnerabilities, and configuration problems, matching Semgrep's core purpose.
-securityAlicense-qualityEnables comprehensive security scanning of code repositories to detect secrets, vulnerabilities, dependency issues, and configuration problems. Provides real-time security checks and best practice recommendations to help developers identify and prevent security issues.Last updated22MITWhy this server?
An advanced code search and transformation MCP server for AI assistants, providing functionality relevant to static analysis and code hygiene.
AsecurityAlicense-qualityAdvanced code search and transformation MCP server for AI assistants. Combines ugrep's speed with intelligent replace capabilities, dry-run previews, and language-aware refactoring across 11 tools.Last updated17MIT