Semgrep MCP: security scans before agent code ships
Semgrep's built-in MCP server lets agents scan code, test custom rules, check dependencies and inspect ASTs. Install the Semgrep CLI and run semgrep mcp.
Project and installation docs
View projecthttps://github.com/semgrep/semgrep
Coding agents write code fast, but they won’t necessarily notice string-built SQL, hardcoded secrets or unsafe deserialization on their own. Semgrep MCP lets the agent call Semgrep, a deterministic static analyzer: after writing or editing code it runs a scan and fixes against concrete rule matches and line numbers. The server now lives in the main Semgrep repository and starts with the semgrep mcp subcommand; the standalone semgrep/mcp repository is archived. The Semgrep repo had about 17k stars as of 2026-10-06.
What it does
- Code scanning:
semgrep_scanchecks files against Semgrep rules, drawing on a registry of more than 10,000 rules across many languages. - Custom rules:
semgrep_scan_with_custom_ruleruns a rule you supply. The built-inwrite_custom_semgrep_ruleprompt helps the model write accurate rules, andsemgrep_rule_schemadocuments the format. - Dependency risk:
semgrep_scan_supply_chainlooks for supply chain issues in dependencies. - Syntax trees:
get_abstract_syntax_treereturns the AST so the model can reason about structure or debug a rule. - Platform findings: with
SEMGREP_APP_TOKENset,semgrep_findingsreads existing findings from Semgrep AppSec Platform.
Who it’s for
- Developers who want Claude Code or Cursor to pass a security scan before handing back every change.
- Security teams already on Semgrep who want the same rules applied to AI-generated code.
Setup
Install the Semgrep CLI, then start the MCP server in stdio mode:
brew install semgrep
semgrep mcp
Claude Code and Cursor users can instead install the Semgrep plugin (Semgrep Guardian) from the plugin marketplace and run /setup-semgrep-plugin. With Docker: docker run -i --rm semgrep/semgrep semgrep mcp -t stdio.
Our take
Among code-scanning servers, Semgrep’s edge is determinism: the same code and rules give the same result, unlike asking a model to review code, which varies run to run. The Semgrep Guardian plugin bundles the MCP server with hooks and skills, scans files the agent generates and prompts it to rewrite until the scan is clean or you dismiss the finding. Know the limits: the README says the project is under active development, reading platform findings needs a Semgrep account and token, and community rules cover less than the paid Semgrep Code, Supply Chain and Secrets products. The MCP code ships inside the Semgrep CLI, licensed LGPL-2.1.