Semgrep MCP Server
Semgrep 服务器
用于将 Semgrep 集成到开发环境中的模型上下文协议 (MCP) 服务器。该服务器允许直接通过 MCP 协议执行静态代码分析和管理 Semgrep 规则。
安装
# Repository klonen
git clone [repository-url]
cd semgrep-server
# Abhängigkeiten installieren
npm install
# Server bauen
npm run buildRelated MCP server: ACE-MCP
使用
可以通过以下方式启动服务器:
# Produktionsmodus
npm start
# Entwicklungsmodus
npm run dev可用工具
该服务器提供以下 MCP 工具:
scan_directory:在目录中运行 Semgrep 扫描list_rules:列出可用的 Semgrep 规则analyze_results:分析扫描结果create_rule:创建一个新的 Semgrep 规则filter_results:根据各种标准过滤扫描结果export_results:以各种格式导出扫描结果compare_results:比较两个扫描结果
发展
该项目使用 TypeScript 编写,并使用 MCP SDK 进行服务器实现。
项目结构
semgrep-server/
├── src/ # Quellcode
├── build/ # Kompilierte JavaScript-Dateien
├── test.js # Testdateien
└── test-rule.yaml # Beispiel Semgrep-Regel依赖项
Node.js 和 npm
TypeScript
MCP SDK
用于 HTTP 请求的 Axios
执照
该项目已获得 ISC 许可。更多详细信息请参阅LICENSE文件。
This server cannot be deployed
Maintenance
Related MCP Connectors
Enable secure connectivity between Sentry issues and debugging data, and LLM clients, using a Model Context Protocol (MCP) server.
MCP server for Statsig API - interact with Statsig's feature flags, experiments, and analytics
- SupabaseOAuthcom.supabase
MCP server for interacting with the Supabase platform
Scans remote MCP servers for protocol, security, and TLS issues; exposes scan tools via MCP.
Related MCP Servers
AlicenseBqualityFmaintenanceAn MCP server that provides a comprehensive interface to Semgrep, enabling users to scan code for security vulnerabilities, create custom rules, and analyze scan results through the Model Context Protocol.6601 PyPI688MIT- AlicenseNot gradedqualityBmaintenanceEnables AI clients to perform local code search, indexing, and analysis across Java, JavaScript/TypeScript, .NET/C#, and Python projects through the MCP protocol.1Apache 2.0
- AlicenseAqualityDmaintenanceA production-grade security auditing MCP server that wraps semgrep (SAST) and gitleaks (secret detection) to enable one-click code security scanning via MCP stdio protocol.14 npmMIT
- AlicenseAqualityAmaintenanceMCP server that exposes SQLFluff's linting, fixing, and parsing capabilities, enabling MCP-aware clients to lint and fix SQL directly.8MIT