MCP MCP Server

MCP Server for Semgrep Integration - static code analysis with AI

Remote serverstreamable-httpPython

What is the MCP MCP server?

MCP Server for Semgrep Integration - static code analysis with AI. The mcp mcp server wraps that behind the Model Context Protocol, so an assistant can use it through 9 defined tools rather than through you.

What it actually does

MCP Server Semgrep is a Model Context Protocol compliant server that integrates the powerful Semgrep static analysis tool with AI assistants like Anthropic Claude. It enables advanced code analysis, security vulnerability detection, and code quality improvements directly through a conversational interface.

  • Direct integration with the official MCP SDK
  • Simplified architecture with consolidated handlers
  • Clean ES Modules implementation
  • Efficient error handling and path validation for security
  • Interface and documentation in both English and Polish
  • Comprehensive unit tests

Its toolset

Everything the assistant can do here goes through one of these:

  • scan_directory — Scanning source code for potential issues
  • list_rules — Displaying available rules and languages supported by Semgrep
  • analyze_results — Detailed analysis of scan results
  • create_rule — Creating custom Semgrep rules
  • filter_results — Filtering results by various criteria
  • export_results — Exporting results in various formats
  • compare_results — Comparing two sets of results (e.g., before and after changes)
  • Prerequisites — The Prerequisites tool exposed by this server
  • Testing — The Testing tool exposed by this server

Adding it to your client

Being a remote server, there is no local install. You register the endpoint with your client, authorise it once, and the tools appear.

Configuration

You will need 2 environment variables: SEMGREP_APP_TOKEN, MCP_SERVER_SEMGREP_ALLOWED_ROOTS. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

  • Node.js v18+ - TypeScript (for development)

When to reach for it

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. MCP's toolset — scan_directory, list_rules, analyze_results and 6 more — is a fair guide to whether it matches your workflow. It is maintained by div0.space; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Caveats

  • Your data travels to the provider's service, so the usual questions apply about what you send and what they retain.
  • With 9 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch MCP.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the mcp mcp server does with a few real requests.

Available tools

ToolWhat it does
scan_directoryScanning source code for potential issues
list_rulesDisplaying available rules and languages supported by Semgrep
analyze_resultsDetailed analysis of scan results
create_ruleCreating custom Semgrep rules
filter_resultsFiltering results by various criteria
export_resultsExporting results in various formats
compare_resultsComparing two sets of results (e.g., before and after changes)
PrerequisitesThe Prerequisites tool exposed by this server.
TestingThe Testing tool exposed by this server.

How to install the MCP MCP server

{
  "mcpServers": {
    "semgrep-1": {
      "command": "npx",
      "args": ["-y", "mcp-server-semgrep"],
      "env": {
        "SEMGREP_APP_TOKEN": "your-value",
        "MCP_SERVER_SEMGREP_ALLOWED_ROOTS": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

  • Node.js v18+ - TypeScript (for development)
VariableDescriptionRequired
SEMGREP_APP_TOKENCredential the server authenticates with.Yes
MCP_SERVER_SEMGREP_ALLOWED_ROOTSConfiguration value read at startup.Optional

Example prompts to try

  • Use MCP to scan directory.
  • Use MCP to list rules.
  • Use MCP to analyze results.

Frequently asked questions

It connects MCP to MCP-compatible AI assistants such as Claude and Cursor, exposing 9 tools (scan_directory, list_rules, analyze_results, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with MCP directly.