# Semgrep

> Use this tool when you need to automate code analysis and vulnerability detection in your development workflow. It integrates Semgrep's static analysis capabilities, providing a TypeScript-based interface for AI agents to scan code, detect vulnerabilities, and interpret results. Ideal for DevSecOps teams and security researchers, it streamlines continuous security monitoring, custom rule development, and AI-assisted vulnerability remediation.

Canonical page: https://skillsregistry.net/skills/stefanskiasan-semgrep  
JSON: https://api.skillsregistry.net/v1/skills/stefanskiasan-semgrep

## Description

This MCP server, developed by Asan Stefanski, provides a TypeScript-based interface for integrating Semgrep static analysis capabilities. Built using the Model Context Protocol SDK, it enables AI agents to leverage Semgrep's powerful code scanning and vulnerability detection features. The implementation focuses on streamlining the process of running Semgrep scans and interpreting results, making it easier to incorporate security checks into development workflows. It's particularly useful for DevSecOps teams and security researchers who want to automate code analysis, enabling use cases such as continuous security monitoring, custom rule development, and AI-assisted vulnerability remediation without deep Semgrep expertise.

## Trust

- **Trust score (0–1):** 0.97
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** media
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/stefanskiasan-semgrep)
- **Repository:** <https://github.com/stefanskiasan/semgrep-mcp-server>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "stefanskiasan-semgrep"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/stefanskiasan-semgrep` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/stefanskiasan-semgrep/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
