SemgrepBLOCK
A MCP server for using Semgrep to scan code for security vulnerabilities.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
⚠️ The Semgrep MCP server has been moved from a standalone repo to the [main `semgrep` repository!](https://github.com/semgrep/semgrep/tree/develop/cli/src/semgrep/mcp) ⚠️ This repository has been deprecated, and further updates to the Semgrep MCP server will be made via the official `semgrep` binary.
[](https://lmstudio.ai/install-mcp?name=semgrep&config=eyJ1cmwiOiJodHRwczovL21jcC5zZW1ncmVwLmFpL21jcCIsImhlYWRlcnMiOnsiQXV0aG9yaXphdGlvbiI6IkJlYXJlciA8WU9VUl9IRl9UT0tFTj4ifX0%3D) [](cursor://anysphere.cursor-deeplink/mcp/install?name=semgrep&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJzZW1ncmVwLW1jcCJdfQ==) [![I
7d30c3bd62afOBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add semgrep-mcp --env SEMGREP_APP_TOKEN=${SEMGREP_APP_TOKEN} -- uvx semgrep-mcp{
"mcpServers": {
"semgrep-mcp": {
"command": "uvx",
"args": [
"semgrep-mcp"
],
"env": {
"SEMGREP_APP_TOKEN": "${SEMGREP_APP_TOKEN}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
deprecation_notice | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (9)
yaml_contents = yaml.load(fd)
settings = yaml.load(f)
print(f" SEMGREP_APP_TOKEN: {'*' * min(8, len(token))}").gitmodules
.pre-commit-config.yaml
safe_join(base_dir, "subdir/../../file.txt")
safe_join(base_dir, "./subdir/../../../file.txt")
By default, the server listens on [127.0.0.1:8000/mcp](https://127.0.0.1/mcp) for client connections. To change any of this, set [FASTMCP\_\*](https://github.com/modelcontextprotocol/python-sdk/blob/m
By default, the server listens on [127.0.0.1:8000/sse](https://127.0.0.1/sse) for client connections. To change any of this, set [FASTMCP\_\*](https://github.com/modelcontextprotocol/python-sdk/blob/m
Gates applied: no_behavioural_pass.
7d30c3bd62affull audit observations/trust-audit/mcp-server/semgrep__semgrep-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 7d30c3bd62af | BLOCK | D | 69 | first audit |
Questions
What is the Semgrep MCP server?
A MCP server for using Semgrep to scan code for security vulnerabilities.
What tools does Semgrep expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Semgrep safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Semgrep need?
It reads SEMGREP_APP_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Semgrep run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as semgrep-mcp.
How current is this page?
The grade is for one exact copy of the source (7d30c3bd62af), read on 2026-09-28. The repository is watched and re-audited when it changes.