Semgrep
PackageStatic application-code security scanning with a local CLI and MCP server
- Access
- None, runs locally
About
Semgrep Community Edition scans application source code with structural rules from a local CLI without an account. Its official CLI also offers a local MCP server. Advanced cross-file analysis and hosted AppSec workflows are paid features; Community Edition has narrower analysis.
What you can do with it
- Scan application source code for unsafe patterns before merging changes
- Write custom structural rules for security policies in your codebase
- Let a coding agent invoke the local MCP server to inspect generated code
Get started
- Install the Semgrep CLI with Python 3.10 or newer
- Run semgrep scan with a rule configuration or start semgrep mcp
- Use local scans without login; authenticate for paid platform workflows
Example
semgrep scan --config auto .
# Optional local MCP transport
semgrep mcp --transport stdioDetails
- Hosting
- Runs locally
- Available in
- Worldwide
- MCP server
- Local