Major-vendorhttphosted available● online
Semgrep MCP
by Semgrep · Security
Run Semgrep SAST scans, query findings, and manage rulesets and policies.
Works with:Claude CodeCursorWindsurfOpenCode
sastfindingsrulesetsscanread
Install
Connector URL
https://mcp.semgrep.ai/mcpAdd directly in Claude → Settings → Connectors → Add custom connector, then paste this URL. No API key — sign in when prompted.
Run this command in your terminal:
claude mcp add --transport http mcp-semgrep https://mcp.semgrep.ai/mcp
Authentication
OAuth
Official Semgrep MCP.
Skills that use this MCP
Semgrep Plugin
This plugin is the Claude Code interface for running Semgrep SAST scans via MCP.
static-analysis
Semgrep MCP runs the actual SAST scans that the static-analysis skill orchestrates.
security-audit (PHP/OWASP)
Semgrep MCP runs OWASP pattern scans that supplement the manual audit workflow.
claude-code-security-audit
Security audit skill runs Semgrep MCP scans as part of the audit workflow.

