# Semgrep

> Use this tool when you need to scan codebases for security vulnerabilities and quality issues, and integrate static analysis into AI-assisted development workflows. Semgrep solves problems related to code security, vulnerability detection, and quality improvement, supporting various programming languages and offering features like custom rule creation and result filtering. It accepts codebases as input and outputs scan results, making it ideal for use cases requiring AI-driven code analysis and optimization.

Canonical page: https://skillsregistry.net/skills/szowesgad-semgrep  
JSON: https://api.skillsregistry.net/v1/skills/szowesgad-semgrep

## Description

This MCP server implementation integrates Semgrep, a static analysis tool, into AI-assisted development workflows. Developed by Szowesgad, it provides tools for scanning codebases, managing Semgrep rules, and analyzing scan results. The server supports various programming languages and offers features like custom rule creation, result filtering, and comparison of scan outputs. It's designed for use cases requiring AI-driven code security analysis, vulnerability detection, and code quality improvement.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/szowesgad-semgrep)
- **Repository:** <https://github.com/vetcoders/mcp-server-semgrep>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "szowesgad-semgrep"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/szowesgad-semgrep` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/szowesgad-semgrep/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
