MCP.so
Sign In

Semgrep Server

@MCP-Mirror

About Semgrep Server

Mirror of

Config

No standard config provided

This server doesn't expose a parseable MCP config block in its README. See the repository for install instructions.

Repository

Tools

No tools detected

We auto-extract tools from the README. The maintainer can list them under a ## Tools heading to populate this section.

Overview

What is Semgrep Server?

Semgrep Server is an MCP (Model Context Protocol) server that integrates Semgrep static code analysis into a development environment. It allows users to run scans, manage rules, and analyze results directly through the MCP protocol. It is built for developers who need to incorporate code-quality checks into their toolchain.

How to use Semgrep Server?

Clone the repository, run npm install to install dependencies, then npm build to compile the TypeScript source. Start the server in production mode with npm start or in development mode with npm run dev. No configuration keys are mentioned.

Key features of Semgrep Server

  • Scan a directory with scan_directory.
  • List available Semgrep rules with list_rules.
  • Analyze scan results with analyze_results.
  • Create new Semgrep rules with create_rule.
  • Filter and export results with filter_results and export_results.
  • Compare two sets of scan results with compare_results.

Use cases of Semgrep Server

  • Automatically scan a project folder for security vulnerabilities or coding patterns.
  • Manage and extend a set of static analysis rules without leaving the development environment.
  • Compare scan outputs from different code versions to catch regressions.
  • Export filtered results to share with team members or integrate into CI pipelines.

FAQ from Semgrep Server

What dependencies are required?

Node.js and npm are required. The project also uses TypeScript, the MCP SDK, and Axios for HTTP requests.

How do I start the server?

Run npm start for production mode or npm run dev for development mode from the project root.

What tools (MCP tools) are available?

The server provides seven tools: scan_directory, list_rules, analyze_results, create_rule, filter_results, export_results, and compare_results.

Is there a license?

Yes, the project is released under the ISC license. Details are in the LICENSE file.

What language is the server written in?

The server is written in TypeScript and compiled to JavaScript.

Frequently asked questions

What dependencies are required?

Node.js and npm are required. The project also uses TypeScript, the MCP SDK, and Axios for HTTP requests.

How do I start the server?

Run `npm start` for production mode or `npm run dev` for development mode from the project root.

What tools (MCP tools) are available?

The server provides seven tools: `scan_directory`, `list_rules`, `analyze_results`, `create_rule`, `filter_results`, `export_results`, and `compare_results`.

Is there a license?

Yes, the project is released under the ISC license. Details are in the LICENSE file.

What language is the server written in?

The server is written in TypeScript and compiled to JavaScript.

Comments

More Developer Tools MCP servers