⚠️ The Semgrep MCP server has been moved from a standalone repo to the main semgrep repository! ⚠️
This repository has been deprecated, and further updates to the Semgrep MCP server will be made via the official semgrep binary.
Semgrep MCP Server
A Model Context Protocol (MCP) server for using Semgrep to scan code for security vulnerabilities. Secure your vibe coding! 😅
Model Context Protocol (MCP) is a standardized API for LLMs, Agents, and IDEs like Cursor, VS Code, Windsurf, or anything that supports MCP, to get specialized help, get context, and harness the power of tools. Semgrep is a fast, deterministic static analysis tool that semantically understands many languages and comes with over 5,000 rules. 🛠️
[!NOTE] This beta project is under active development. We would love your feedback, bug reports, feature requests, and code. Join the
#mcpcommunity Slack channel!
Contents
- Semgrep MCP Server
- Contents
- Getting started
- Cursor
- ChatGPT
- Hosted Server
- Cursor
- Demo
- API
- Tools
- Scan Code
- Understand Code
- Cloud Platform (login and Semgrep token required)
- Meta
- Prompts
- Resources
- Tools
- Usage
- Standard Input/Output (stdio)
- Python
- Docker
- Streamable HTTP
- Python
- Docker
- Server-sent events (SSE)
- Python
- Docker
- Standard Input/Output (stdio)
- Semgrep AppSec Platform
- Integrations
- Cursor IDE
- VS Code / Copilot
- Manual Configuration
- Using Docker
- Windsurf
- Claude Desktop
- Claude Code
- OpenAI
- Agents SDK
- Custom clients
- Example Python SSE client
- Contributing, community, and running from source
- Similar tools 🔍
- Community projects 🌟
- MCP server registries






