Semgrep MCP server
Scan code for vulnerabilities with Semgrep Guardian from your AI agents.
About
Connect Tracecat to Semgrep Guardian to scan code for vulnerabilities from AI agents working alongside AppSec engineers reviewing code changes. Guardian is Semgrep's hosted AppSec scanning service, and its MCP server checks code the agent sends it with the default Guardian ruleset across Semgrep Code, Supply Chain, and Secrets. From there, agents can inspect the AST for any snippet, test a custom rule before it ships, and triage pull requests with findings attached.
Setup
- 1
Sign in with OAuth
You'll authorize Tracecat to access Semgrep on your behalf. No API keys to manage.
- 2
Select the
Semgreptile in the Tracecat MCP catalogOpen the
MCP catalogin your workspace, select theSemgreptile, and complete the OAuth flow. - 3
Enable
Semgrepin your agentIn your
ai.agentaction orAgents→toolstab, selectSemgrepfrom theMCP integrationsdropdown.
Tools
security_checkScan code for security vulnerabilities and return findings.
semgrep_scanScan code files with a Semgrep config string such as `p/default`.
semgrep_scan_with_custom_ruleScan code files using a custom Semgrep rule supplied at call time.
get_abstract_syntax_treeReturn the AST for a snippet, useful when authoring custom rules.
supported_languagesList languages Semgrep can parse and scan today.
semgrep_rule_schemaReturn the JSON Schema for Semgrep rule files.