Use Semgrep with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Equip your AI agent with read/write access to Semgrep's SAST platform to audit code security findings, update triage statuses, and enforce custom semantic rules
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 10 capabilities
The complete Semgrep capability set.
These are the exact actions your AI can choose when you ask it to work with Semgrep.
01-04
4 capabilities in this set.
Part of 10 available through Semgrep.
- 01
Create rule
Allows developers to forbid project-specific bad patterns securely and continuously across the enterprise repositories. Create a customized Semgrep security rule within the platform
- 02
Delete rule
Delete a custom Semgrep security rule from the deployment
- 03
Get finding details
Explains the exact malicious code block, suggests semantic fixes, states whether it is blocking PRs in CI, and links to CVE data (if an SCA supply chain defect). Get atomic details for a specific Semgrep flaw
- 04
Get metrics
Typically consumed to render executive security dashboards. Get AppSec metrics and compliance stats for Semgrep
05-07
3 capabilities in this set.
Part of 10 available through Semgrep.
- 05
Get project
Search for a precise Semgrep project by exact repository name
- 06
List deployments
The primary key is the deployment slug identifier. Almost all subsequent API operations targeting rules, projects, or findings will require this deployment slug to define the scope. List Semgrep organizational deployments
- 07
List findings
Findings provide snippet details, file line numbers, severity, and rule types. Fetch globalThis static analysis security findings for a deployment
08-10
3 capabilities in this set.
Part of 10 available through Semgrep.
- 08
List projects
Projects maintain a link between developers and static security scan outputs over time. List Semgrep projects (repositories) monitored in a deployment
- 09
List rules
The rules are structured YAML definitions that search for semantic anti-patterns in codebases (e.g., unparameterized SQL queries, hardcoded AWS keys). List Semgrep semantic rules deployed globally
- 10
Update finding status
Valid states generally include active, fixed, false_positive, ignored, mitigated. Resolving findings through this API cleans up the developer experience when managing compliance queues. Mark a Semgrep finding state (e.g., fixed, false positive)
Observed, not estimated
898ms average. Fast in production.
Semgrep is checked daily against the live service.
- Fastest day
- 653ms
- Slowest day
- 1121ms
- 14-day trend
- Slowing+53%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 10 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of Semgrep, so you can see the experience inside your AI.
It does not authenticate your account with Semgrep. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
Semgrep Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_419UaVAC33VwJmeeVBLCqRf2d8eEEPrGrsnPeNVU/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — Semgrep capabilities are ready to use.
{
"mcpServers": {
"semgrep-mcp": {
"url": "https://edge.vinkius.com/vk_preview_419UaVAC33VwJmeeVBLCqRf2d8eEEPrGrsnPeNVU/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions Semgrep owners ask.
- 01
Can the AI resolve or close findings in Semgrep natively?
Yes. This server supports mutable actions. By invoking update_finding_status, your AI agent can shift a specific semantic flaw to 'mitigated', 'fixed', 'ignored', or 'false_positive' updating the registry in real-time.
- 02
How can I deploy a new custom SAST rule via chat?
Simply ask the LLM: 'Draft a semantic grep rule to ban hardcoded API keys in Python and deploy it'. The agent will natively format the JSON structure required and call create_rule, sending it directly to all repositories.
- 03
Do I need to supply a 'Deployment Slug' for every request?
Most API queries require the deployment context. To ensure smooth interactions, just tell the agent your organization slug once (or let it query list_deployments to fetch the default one). The agent will remember it for the rest of the conversation loop.
Explore
More in Fort Knox
Snyk AI Connector
Bring your Snyk code security ecosystem directly to your AI. Analyze vulnerabilities, project metadata, and sc
ViewGitLab AI Connector
Manage projects, track issues, and oversee CI/CD pipelines via AI agents with GitLab.
ViewCode Climate AI Connector
Manage code quality and engineering metrics via Code Climate — track repository grades, monitor snapshots, and
ViewGitGuardian AI Connector
Automate secret detection and incident response via GitGuardian — manage secret incidents, deploy honeytokens,
View
Suggestions
Exa AI AI Connector
Search the web with neural embeddings that understand meaning, not just keywords, and return the most relevant
ViewContentKing AI Connector
Enable your AI agent to fetch real-time SEO audit metrics and monitor website changes through ContentKing.
ViewHackEDU (Security Journey) AI Connector
Automate security training via HackEDU — manage users, track progress, and integrate vulnerability data direct
ViewBugSnag AI Connector
Monitor application errors via BugSnag — track stability, inspect error groups, and retrieve event details dir
View
