Developer Tools · Security

MCP Server Semgrep logo

MCP Server Semgrep

Szowesgad/mcp-server-semgrep

MCP Server Semgrep is a Model Context Protocol compliant server that integrates the powerful Semgrep static analysis tool with AI assistants like Anthropic Claude. It enables advanced code analysis, security vulnerability detection, and code quality improvements directly through a conversational interface.

Install

npm install -g mcp-server-semgrep

Client configuration

{
  "mcpServers": {
    "semgrep": {
      "command": "node",
      "args": [
        "/your_path/mcp-server-semgrep/build/index.js"
      ],
      "env": {
        "SEMGREP_APP_TOKEN": "<SEMGREP_APP_TOKEN>",
        "MCP_SERVER_SEMGREP_ALLOWED_ROOTS": "<MCP_SERVER_SEMGREP_ALLOWED_ROOTS>"
      }
    }
  }
}

Environment variables

SEMGREP_APP_TOKENMCP_SERVER_SEMGREP_ALLOWED_ROOTS
GitHub stars
12
Category
Developer Tools, Security
License
MIT
Updated
Oct 6, 2026

About MCP Server Semgrep

This project was initially inspired by robustness of Semgrep tool, The Replit Team and their Agent V2, as well as the implementation by stefanskiasan/semgrep-mcp-server, but has evolved with significant architectural changes for enhanced and easier installation and maintenance.

Features

  • Direct integration with the official MCP SDK

  • Simplified architecture with consolidated handlers

  • Clean ES Modules implementation

  • Efficient error handling and path validation for security

  • Interface and documentation in both English and Polish

  • Comprehensive unit tests

  • Extensive documentation

  • Cross-platform compatibility (Windows, macOS, Linux)

  • Flexible Semgrep installation detection and management

Tools (7)

  • scan_directory

    Scanning source code for potential issues

  • list_rules

    Displaying available rules and languages supported by Semgrep

  • analyze_results

    Detailed analysis of scan results

  • create_rule

    Creating custom Semgrep rules

  • filter_results

    Filtering results by various criteria

  • export_results

    Exporting results in various formats

  • compare_results

    Comparing two sets of results (e.g., before and after changes)

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools