Complete AI Training

MCP server · Security · official

Semgrep MCP server

by semgrep · official

Lets your AI check code for security problems using Semgrep before you ship it.

Flow diagram: you ask your AI “Check this code for security problems”, the Semgrep MCP server connects it to Semgrep, and you get back A list of problems found.

This is a helper from Semgrep, a company that makes a tool for finding security problems in code. Once it is connected, your AI assistant can run Semgrep checks on the code it writes or on files you point it at. It is handy for developers, but also for anyone who asks an AI to write code and wants a second pair of eyes on safety.

What is an MCP server? The 30-second version

On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI a new skill or a connection to another tool. This one connects your AI to Semgrep, a code checking tool. So when you ask your AI to look at code for security issues, it can actually run Semgrep and bring the results back into the chat.

What this MCP server does

You ask your AI to check some code for security problems. The AI uses this helper, which runs Semgrep on the code. Semgrep looks through the code using thousands of built-in rules and reports anything suspicious. The AI then shows you what it found, in plain words, right in the chat. If you use it inside a coding tool like Claude Code or Cursor, it can also scan each file the AI writes and ask the AI to fix problems before you accept the code.

Flow diagram: you ask your AI “Check this code for security problems”, the Semgrep MCP server connects it to Semgrep, and you get back A list of problems found. Click to zoom

What you can do with it

  • Scan a piece of code you paste in for security issues
  • Check files in your project for known bad patterns
  • Look for leaked secrets like passwords or keys in code
  • Flag risky dependencies in your project
  • Get a short explanation of each finding in the chat
  • Ask the AI to rewrite code until the scan comes back clean

Try asking your AI

  • “Scan this Python file for security problems and explain what you find”
  • “Check my project folder for any hardcoded passwords or API keys”
  • “Look at the code you just wrote and fix anything Semgrep flags”
  • “Are there any risky patterns in this JavaScript snippet?”

What it gives back to you

You get a list of findings, each with the file and line where the problem is, a short description, and a severity level. The AI usually summarises them in plain words and can suggest fixes. If nothing is found, it tells you the scan came back clean. In coding tools, it can also show the scan result before you accept a change.

Before you start

What you need

  • The Semgrep tool installed on your computer (the README shows how, for example with Homebrew or pip)
  • A coding tool that supports MCP, like Claude Code, Cursor, VS Code, Windsurf, or Kiro
  • Optional: a free Semgrep account and token if you want to connect to the Semgrep platform

Good to know

It reads the code you point it at, so avoid scanning files that contain private information you would not want sent to your AI tool.

Install it with your AI

Add Semgrep MCP server to your AI, no technical skills needed

You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.

Sign in to get the install prompt

Members get a ready-made prompt that lets the Claude desktop app check Semgrep MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.

Sign in Become a member

Who it's for

Developers and anyone who uses an AI to write code and wants a quick security check before using it.