Tracecat
Book a demo

Semgrep MCP server

Scan code for vulnerabilities with Semgrep Guardian from your AI agents.

AppSec
http
Official docs

About

Connect Tracecat to Semgrep Guardian to scan code for vulnerabilities from AI agents working alongside AppSec engineers reviewing code changes. Guardian is Semgrep's hosted AppSec scanning service, and its MCP server checks code the agent sends it with the default Guardian ruleset across Semgrep Code, Supply Chain, and Secrets. From there, agents can inspect the AST for any snippet, test a custom rule before it ships, and triage pull requests with findings attached.

Setup

  1. 1

    Sign in with OAuth

    You'll authorize Tracecat to access Semgrep on your behalf. No API keys to manage.

  2. 2

    Select the Semgrep tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the Semgrep tile, and complete the OAuth flow.

  3. 3

    Enable Semgrep in your agent

    In your ai.agent action or Agents → tools tab, select Semgrep from the MCP integrations dropdown.

Tools

security_check

Scan code for security vulnerabilities and return findings.

semgrep_scan

Scan code files with a Semgrep config string such as `p/default`.

semgrep_scan_with_custom_rule

Scan code files using a custom Semgrep rule supplied at call time.

get_abstract_syntax_tree

Return the AST for a snippet, useful when authoring custom rules.

supported_languages

List languages Semgrep can parse and scan today.

semgrep_rule_schema

Return the JSON Schema for Semgrep rule files.

Deploy the Semgrep MCP server in minutes

Connect your security agents to 50+ hosted MCP servers.