Atlas / MCP servers / semgrep / Semgrep

SemgrepBLOCK

mcp/semgrep/semgrep-1

A MCP server for using Semgrep to scan code for security vulnerabilities.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
687
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

⚠️ The Semgrep MCP server has been moved from a standalone repo to the [main `semgrep` repository!](https://github.com/semgrep/semgrep/tree/develop/cli/src/semgrep/mcp) ⚠️ This repository has been deprecated, and further updates to the Semgrep MCP server will be made via the official `semgrep` binary.

[](https://lmstudio.ai/install-mcp?name=semgrep&config=eyJ1cmwiOiJodHRwczovL21jcC5zZW1ncmVwLmFpL21jcCIsImhlYWRlcnMiOnsiQXV0aG9yaXphdGlvbiI6IkJlYXJlciA8WU9VUl9IRl9UT0tFTj4ifX0%3D) [](cursor://anysphere.cursor-deeplink/mcp/install?name=semgrep&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJzZW1ncmVwLW1jcCJdfQ==) [![I

Read from source at commit 7d30c3bd62afOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add semgrep-mcp --env SEMGREP_APP_TOKEN=${SEMGREP_APP_TOKEN} -- uvx semgrep-mcp
claude-desktop
{
  "mcpServers": {
    "semgrep-mcp": {
      "command": "uvx",
      "args": [
        "semgrep-mcp"
      ],
      "env": {
        "SEMGREP_APP_TOKEN": "${SEMGREP_APP_TOKEN}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
deprecation_noticeread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (2 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (9)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/semgrep_mcp/utilities/tracing.py:65
yaml_contents = yaml.load(fd)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/semgrep_mcp/utilities/utils.py:52
settings = yaml.load(f)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/configure_semgrep_mcp.py:136
print(f"     SEMGREP_APP_TOKEN: {'*' * min(8, len(token))}")
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_safe_join.py:40
safe_join(base_dir, "subdir/../../file.txt")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_safe_join.py:48
safe_join(base_dir, "./subdir/../../../file.txt")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:254
By default, the server listens on [127.0.0.1:8000/mcp](https://127.0.0.1/mcp) for client connections. To change any of this, set [FASTMCP\_\*](https://github.com/modelcontextprotocol/python-sdk/blob/m
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:278
By default, the server listens on [127.0.0.1:8000/sse](https://127.0.0.1/sse) for client connections. To change any of this, set [FASTMCP\_\*](https://github.com/modelcontextprotocol/python-sdk/blob/m

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 7d30c3bd62affull audit observations/trust-audit/mcp-server/semgrep__semgrep-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-287d30c3bd62afBLOCKD69first audit
06

Questions

What is the Semgrep MCP server?

A MCP server for using Semgrep to scan code for security vulnerabilities.

What tools does Semgrep expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Semgrep safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Semgrep need?

It reads SEMGREP_APP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Semgrep run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as semgrep-mcp.

How current is this page?

The grade is for one exact copy of the source (7d30c3bd62af), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement