mcp

mcp

MCP.Pizza Chef: semgrep

Semgrep reads source code against a library of more than five thousand published rules and flags the risky patterns, the kind of thing that slips past a quick read. Wiring it into your assistant means the check happens while the code is being written rather than weeks later, and you can ask why a particular line was flagged. It runs in Cursor, VS Code, Claude Desktop, Claude Code, Windsurf, and ChatGPT. Note that this standalone project is deprecated: the same server now ships inside the main Semgrep tool.

Deprecated · standalone project folded into the main Semgrep tool
Coding

Use This MCP server To

Scan the code my assistant just wrote for security problems Ask why a flagged line is actually risky Check a single file before I commit it Point it at a folder and get a list of weak spots Get a plain explanation of a security warning I do not understand

README

⚠️ The Semgrep MCP server has been moved from a standalone repo to the main semgrep repository! ⚠️

This repository has been deprecated, and further updates to the Semgrep MCP server will be made via the official semgrep binary.

Semgrep logo

Documentation Join Semgrep community Slack Follow on LinkedIn Follow @semgrep on X

Semgrep MCP Server

mcp FAQ

Is this project still maintained?
Not as a standalone project. It has been folded into the main Semgrep tool, and further updates happen there, so start with the official Semgrep release.
Do I need to pay for it?
Scanning works without an account. Connecting to Semgrep's hosted platform for shared rules and saved findings requires a token.
Which apps does it work in?
Cursor, VS Code with Copilot, Claude Desktop, Claude Code, Windsurf, and ChatGPT, among others.
Can I use this to check code before I publish it?
Yes. Ask for a scan of a file or a folder and you get back the specific lines that look risky, with an explanation.
Which programming languages does it cover?
Semgrep understands a wide range of languages, and keeps a current list in its own documentation.
How hard is setup?
There is a hosted address you can point at, or you can run it locally with a single command. Either way it is a short paste into your settings.
Is it a replacement for a security review?
No. It catches known risky patterns quickly, but it is one check among several rather than a full audit.