Semgrep
Semgrep is a fast, open-source static analysis platform for finding security bugs and enforcing code standards. Its hosted MCP server lets agents scan code and query findings directly.
Semgrep is a static application security testing platform built on a fast, open-source engine that scans code against thousands of rules for vulnerabilities, secrets and anti-patterns. The hosted MCP server lets an agent run scans and query Semgrep findings, so it can catch security issues, explain them and help fix them inside a coding workflow.
- Category
- Security & Privacy
- EU hosting
- No
- HQ
- United States of America
- Pricing
- Freemium
- Open source
- Yes
Engineering and security teams who want agents to scan code and reason about findings.
Teams that need dynamic runtime testing rather than static analysis.
- Static analysis engine
- Security rule packs
- Secrets detection
- Custom rules
- Findings management
Scan code for vulnerabilities from an agent; triage and explain findings; enforce code standards.
Works with any MCP client (Claude, Cursor, VS Code) and through the Tulimoa gateway.
Tulimoa has tested and verified this tool's MCP server. Agents can plug in with confidence.
- Endpoint
- Authentication
- OAuth
