Skip to main content

MCP server trust card

Semgrep MCP Server

Semgrep · recorded version or snapshot 0.1.0

Semgrep MCP — run static analysis rules, detect security bugs, and enforce code patterns using Semgrep's rule engine.

Metadata reviewed Elevated access

Source and identity

Publisher
Semgrep
Namespace
Not recorded
Recorded version / snapshot
0.1.0
License
Not recorded
Artifact SHA-256
Not recorded — a source snapshot alone does not pin an artifact

Declared access

Review every permission against your own environment and least-privilege policy.

  • read:code
  • write:findings

Required secrets

Generated examples use placeholders. Never paste real secrets into ToolDix.

  • SEMGREP_APP_TOKEN

Compatibility and connection

Clients

  • Codex
  • Claude
  • Cursor
  • OpenClaw

Runtimes

  • python

Transports

  • stdio

Authentication

  • api-key

Evidence