No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by semgrep · MCP Server · ★ 687
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp safe to install? View the security audit →
⚠️ The Semgrep MCP server has been moved from a standalone repo to the main repository! ⚠️ This repository has been deprecated, and further updates to the Semgrep MCP server will be made via the official binary. Semgrep MCP
| Stars | 687 |
| Forks | 58 |
| Language | Python |
| Category | MCP Server |
| License | MIT |
| Quality Score | 75.2977850694175/100 |
| Open Issues | 28 |
| Last Updated | 2025-10-28 |
| Created | 2025-03-17 |
| Platforms | mcp, python |
| Est. Tokens | ~62k |
These tools work well together with mcp for enhanced workflows:
Explore other popular mcp server tools:
mcp is A MCP server for using Semgrep to scan code for security vulnerabilities.. It is categorized as a MCP Server with 687 GitHub stars.
mcp is primarily written in Python. It covers topics such as mcp, semgrep.
You can find installation instructions and usage details in the mcp GitHub repository at github.com/semgrep/mcp. The project has 687 stars and 58 forks, indicating an active community.
mcp is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: