Semgrep
Scan code for vulnerabilities with Semgrep rules
Verified: Checked by the catalog team: official server with OAuth or docs and an owner contactOnlineNo sign-inGlobalFreeRead-only
What it can do
- Scan a code snippet
- Explain a finding
- Find a Semgrep rule
What data it sees
Code you submit is sent to Semgrep.
Do you need an account
No: the server works without sign-in
Official Semgrep server. TODO: confirm the /mcp path is current (older lists show /sse).
Tools not fetched yet: the server requires sign-in; the list appears after a manual check.