Semgrep MCP Server

MCP Server for Semgrep Integration - static code analysis with AI

Remote serverstreamable-httpPython

What is the Semgrep MCP server?

Semgrep MCP server is a hosted integration for AI assistants that speak the Model Context Protocol. MCP Server for Semgrep Integration - static code analysis with AI.

What you get

MCP Server Semgrep is a Model Context Protocol compliant server that integrates the powerful Semgrep static analysis tool with AI assistants like Anthropic Claude. It enables advanced code analysis, security vulnerability detection, and code quality improvements directly through a conversational interface.

  • Direct integration with the official MCP SDK
  • Simplified architecture with consolidated handlers
  • Clean ES Modules implementation
  • Efficient error handling and path validation for security
  • Interface and documentation in both English and Polish
  • Comprehensive unit tests

What the assistant can call

Once Semgrep is connected, these are the calls the assistant has available:

  • scan_directory — Scanning source code for potential issues
  • list_rules — Displaying available rules and languages supported by Semgrep
  • analyze_results — Detailed analysis of scan results
  • create_rule — Creating custom Semgrep rules
  • filter_results — Filtering results by various criteria
  • export_results — Exporting results in various formats
  • compare_results — Comparing two sets of results (e.g., before and after changes)
  • Prerequisites — The Prerequisites tool exposed by this server
  • Testing — The Testing tool exposed by this server

Configuration and credentials

You will need 2 environment variables: SEMGREP_APP_TOKEN, MCP_SERVER_SEMGREP_ALLOWED_ROOTS. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

  • Node.js v18+ - TypeScript (for development)

Setting it up

Being a remote server, there is no local install. You register the endpoint with your client, authorise it once, and the tools appear.

Choosing this one

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Semgrep's toolset — scan_directory, list_rules, analyze_results and 6 more — is a fair guide to whether it matches your workflow. It is maintained by Szowesgad; worth a glance at recent repository activity before you build anything load-bearing on it.

This entry was verified against Semgrep's own documentation before publication; SyncDev keeps the directory reviewed rather than auto-generated.

Before you rely on it

  • Your data travels to the provider's service, so the usual questions apply about what you send and what they retain.
  • With 9 tools registered it takes up a noticeable share of the context window; turn it off in projects that never touch Semgrep.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the semgrep mcp server does with a few real requests.

Available tools

ToolWhat it does
scan_directoryScanning source code for potential issues
list_rulesDisplaying available rules and languages supported by Semgrep
analyze_resultsDetailed analysis of scan results
create_ruleCreating custom Semgrep rules
filter_resultsFiltering results by various criteria
export_resultsExporting results in various formats
compare_resultsComparing two sets of results (e.g., before and after changes)
PrerequisitesThe Prerequisites tool exposed by this server.
TestingThe Testing tool exposed by this server.

How to install the Semgrep MCP server

{
  "mcpServers": {
    "server-semgrep": {
      "command": "npx",
      "args": ["-y", "mcp-server-semgrep"],
      "env": {
        "SEMGREP_APP_TOKEN": "your-value",
        "MCP_SERVER_SEMGREP_ALLOWED_ROOTS": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

  • Node.js v18+ - TypeScript (for development)
VariableDescriptionRequired
SEMGREP_APP_TOKENCredential the server authenticates with.Yes
MCP_SERVER_SEMGREP_ALLOWED_ROOTSConfiguration value read at startup.Optional

Example prompts to try

  • Use Semgrep to scan directory.
  • Use Semgrep to list rules.
  • Use Semgrep to analyze results.

Frequently asked questions

It connects Semgrep to MCP-compatible AI assistants such as Claude and Cursor, exposing 9 tools (scan_directory, list_rules, analyze_results, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Semgrep directly.