Semgrep

Package

Static application-code security scanning with a local CLI and MCP server

Price
Free Community Edition; paid platform
Access
None, runs locally

About

Semgrep Community Edition scans application source code with structural rules from a local CLI without an account. Its official CLI also offers a local MCP server. Advanced cross-file analysis and hosted AppSec workflows are paid features; Community Edition has narrower analysis.

What you can do with it

  • Scan application source code for unsafe patterns before merging changes
  • Write custom structural rules for security policies in your codebase
  • Let a coding agent invoke the local MCP server to inspect generated code

Get started

  1. Install the Semgrep CLI with Python 3.10 or newer
  2. Run semgrep scan with a rule configuration or start semgrep mcp
  3. Use local scans without login; authenticate for paid platform workflows

Example

semgrep scan --config auto .
# Optional local MCP transport
semgrep mcp --transport stdio

Details

Hosting
Runs locally
Available in
Worldwide
MCP server
Local

Tasks

Alternatives

Other tools for the same tasks.

Last checked on .