MCP server · Security · official
Semgrep MCP server
by semgrep · official
Lets your AI check code for security problems using Semgrep before you ship it.

This is a helper from Semgrep, a company that makes a tool for finding security problems in code. Once it is connected, your AI assistant can run Semgrep checks on the code it writes or on files you point it at. It is handy for developers, but also for anyone who asks an AI to write code and wants a second pair of eyes on safety.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to another tool. This one connects your AI to Semgrep, a code checking tool. So when you ask your AI to look at code for security issues, it can actually run Semgrep and bring the results back into the chat.
What this MCP server does
You ask your AI to check some code for security problems. The AI uses this helper, which runs Semgrep on the code. Semgrep looks through the code using thousands of built-in rules and reports anything suspicious. The AI then shows you what it found, in plain words, right in the chat. If you use it inside a coding tool like Claude Code or Cursor, it can also scan each file the AI writes and ask the AI to fix problems before you accept the code.
Click to zoomWhat you can do with it
- Scan a piece of code you paste in for security issues
- Check files in your project for known bad patterns
- Look for leaked secrets like passwords or keys in code
- Flag risky dependencies in your project
- Get a short explanation of each finding in the chat
- Ask the AI to rewrite code until the scan comes back clean
Try asking your AI
- “Scan this Python file for security problems and explain what you find”
- “Check my project folder for any hardcoded passwords or API keys”
- “Look at the code you just wrote and fix anything Semgrep flags”
- “Are there any risky patterns in this JavaScript snippet?”
What it gives back to you
You get a list of findings, each with the file and line where the problem is, a short description, and a severity level. The AI usually summarises them in plain words and can suggest fixes. If nothing is found, it tells you the scan came back clean. In coding tools, it can also show the scan result before you accept a change.
Before you start
What you need
- The Semgrep tool installed on your computer (the README shows how, for example with Homebrew or pip)
- A coding tool that supports MCP, like Claude Code, Cursor, VS Code, Windsurf, or Kiro
- Optional: a free Semgrep account and token if you want to connect to the Semgrep platform
Good to know
It reads the code you point it at, so avoid scanning files that contain private information you would not want sent to your AI tool.
Install it with your AI
Add Semgrep MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check Semgrep MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Developers and anyone who uses an AI to write code and wants a quick security check before using it.





