mcp-semgrep-scanner
Verified asset on Archimedes Market. View the full 4-dimension Trust Report (security · quality · license · complexity) and the curated catalog on the asset page.
MCP Semgrep Scanner
Run Semgrep static analysis from an AI agent. Lets an agent scan a repo with prebuilt rulesets (OWASP top 10, secrets, language-specific packs), surface findings with severity scoring, and run baseline diffs to focus only on newly-introduced issues.
Tools
scan— run a default scan (p/security-audit + p/secrets) and return findings sorted by severityscan_with_ruleset— scan with one or more named rulesets (p/owasp-top-ten,p/python, etc.)list_rulesets— built-in rulesets available without a Semgrep accountget_finding_details— full rule metadata + remediation hint for a finding IDbaseline_scan— scan only files modified since a git ref (HEAD~1, main, custom SHA)
Related MCP server: SAST MCP Server
What gets returned
Each finding includes:
rule_id— the Semgrep rule that matchedseverity—ERROR|WARNING|INFOcwe— CWE classification if availableowasp— OWASP category mappingfile+line_start+line_endmessage— human-readable explanationfix— suggested patch if available
Quick start
pip install mcp-semgrep-scanner
# Optional: Semgrep account token for Pro rules
export SEMGREP_APP_TOKEN="..."
mcp-semgrep-scanner serveTypical agent workflow
Agent: "Are there any security issues in this PR?"
↓
1. baseline_scan(repo="/path/to/repo", base_ref="origin/main")
→ returns only findings introduced by the PR's diff
2. get_finding_details(finding_id=...) for the ERROR-severity ones
3. Agent suggests fixes inline in PR reviewLicense
MIT.
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-config MCP security scanner for AI-generated apps. 25K+ vulnerability patterns.
Security scanner for AI agents: prompt injection, leaked secrets, PII, and SSRF-risk URL detection.
1Lets coding agents check their own code for leaked secrets, risky dependencies and AI-code mistakes
11Zero-install security baseline for AI coding agents — OWASP/CWE-cited rules over MCP.
Related MCP Servers
- AlicenseAqualityDmaintenanceAgent-native "safe to ship?" security gate for AI-generated code. Uses real parsers and inter-rocedural taint analysis (JS/TS, Python, Go) to flag the classes AI coding agents get wrong — secrets, SQL injection, SS, SSRF, path traversal, command injection, weak JWT/CORS — and ranks findings by confidence. Exposes a scan tool over MCP.110 npm2MIT
- AlicenseAqualityCmaintenanceEnables AI agents to scan code for security vulnerabilities using multiple static analysis tools, with support for filtering, deduplication, and CI/CD integration.2779 PyPI4MIT
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to scan code for security and quality issues and receive machine-readable reports with suggested fixes and verification criteria.58 npm2MIT
- AlicenseNot gradedqualityCmaintenanceProvides security checks for AI agents, including secret scanning, CVE lookup, and dependency vulnerability scanning, all running locally except for CVE lookups.MIT