semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
The Semgrep Claude Code plugin brings lightweight static analysis capabilities directly into AI coding assistants through the Model Context Protocol. This plugin enables developers to scan code for bugs, security vulnerabilities, and standards violations across 30+ languages using patterns that resemble source code rather than complex regular expressions. By integrating Semgrep's fast analysis engine with Claude Code and other AI assistants, developers can run security scans, write custom rules, and enforce coding standards without leaving their development environment.
Key Features
Use Cases
- 01Scanning pull requests for security vulnerabilities before code review
- 02Detecting dangerous API usage patterns like exec() calls or hardcoded credentials
- 03Enforcing project-specific coding standards and best practices automatically
- 04Finding tainted data flows and potential injection vulnerabilities
- 05Migrating codebases away from deprecated APIs with automatic fix suggestions
- 06Auditing configuration files for security issues like exposed S3 ARNs
Related Plugins
View moreandrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Understand-Anything
Graphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
rtk
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
semgrep — FAQ
What is the Semgrep Claude Code plugin?+
It's a Claude Code marketplace plugin that integrates Semgrep's static analysis engine with AI coding assistants through the Model Context Protocol (MCP). The plugin allows AI assistants to run code scans, detect bugs, and enforce security policies across 30+ programming languages.
How do I install the Semgrep plugin in Claude Code?+
Add the plugin from the official marketplace using the command '/plugin marketplace add semgrep/mcp-marketplace'. Once added, you can interact with Semgrep's analysis capabilities directly through Claude Code's interface.
Which AI clients work with this plugin?+
The Semgrep MCP server integrates with Claude Code, Cursor, VS Code, Windsurf, and Claude Desktop. The plugin is available on official marketplaces for these platforms.
Do I need API keys or a Semgrep account?+
The core Semgrep Community Edition works without an account and analyzes code locally. However, logging in with 'semgrep login' unlocks additional features like Supply Chain vulnerability scanning, Pro rules, and the advanced Pro engine with cross-file analysis.
Is the Semgrep plugin free to use?+
Yes, the Semgrep Community Edition and MCP plugin are free and open-source under LGPL-2.1. Premium features like the Pro engine, Semgrep Assistant AI, and advanced AppSec Platform capabilities are available in paid tiers.
What programming languages does Semgrep support?+
Semgrep analyzes 30+ languages including Python, JavaScript, TypeScript, Java, Go, Rust, C/C++, C#, Ruby, PHP, Kotlin, Swift, Terraform, and many others. It also supports dependency scanning for 12 languages across 15 package managers.
How do I install semgrep?+
Open the source repository on GitHub and follow its README. semgrep is a plugin — MCP Agents Market links you directly to the official repo.
Is semgrep free?+
semgrep is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.