Prerequisites
- Ensure you have Python 3.13+ installed.
Installation
CLI Installation
- Install
uv using their installation instructions.
- Clone the repository.
- Install Semgrep:
pip install semgrep
Docker Installation
- Build the Docker image:
docker build -t mcp-server .
Usage
Running the Server
CLI
- Start the MCP server:
uv run mcp run server.py -t sse
Docker
- Run the Docker container:
docker run -p 8000:8000 mcp-server
- Alternatively, use the published image:
docker run -p 8000:8000 ghcr.io/semgrep/mcp:latest
Creating Your Own Client
- Connect to the MCP server using the following Python code:
from mcp.client import Client
client = Client()
client.connect("localhost:8000")
# Scan code for security issues
results = client.call_tool("semgrep_scan", {
"code": "def get_user(user_id):n return User.objects.get(id=user_id)",
"language": "python"
})
Cursor Plugin Configuration
- Go to
Cursor > Settings > Cursor Settings.
- Choose the MCP tab.
- Click “Add new MCP server”.
- Set the following:
- Name: Semgrep
- Type: sse
- Server URL: http://127.0.0.1:8000/sse
- Ensure the MCP server is enabled.
Alternative Configuration
- Add the following to
~/.cursor/mcp.json:
{
"mcpServers": {
"Semgrep": {
"url": "http://localhost:8000/sse"
}
}
}
Advanced Usage
Scan an Entire Directory
results = client.call_tool("scan_directory", {
"path": "/path/to/code",
"config": "p/security-audit"
})
Filter Results by Severity
filtered = client.call_tool("filter_results", {
"results_file": "/path/to/results.json",
"severity": "ERROR"
})
Development
Running the Development Server
- Start the MCP server in development mode:
uv run mcp dev server.py
- The server runs on
http://localhost:3000 with the inspector server on http://localhost:5173.
Note
- When opening the inspector server, add query parameters to the URL to increase the default timeout of the server from 10s:
http://localhost:5173/?timeout=300000
uv using their installation instructions.pip install semgrep
docker build -t mcp-server .
uv run mcp run server.py -t sse
docker run -p 8000:8000 mcp-server
docker run -p 8000:8000 ghcr.io/semgrep/mcp:latest
from mcp.client import Client
client = Client()
client.connect("localhost:8000")
# Scan code for security issues
results = client.call_tool("semgrep_scan", {
"code": "def get_user(user_id):n return User.objects.get(id=user_id)",
"language": "python"
})
Cursor > Settings > Cursor Settings.- Name: Semgrep
- Type: sse
- Server URL: http://127.0.0.1:8000/sse
~/.cursor/mcp.json:
{
"mcpServers": {
"Semgrep": {
"url": "http://localhost:8000/sse"
}
}
}
results = client.call_tool("scan_directory", {
"path": "/path/to/code",
"config": "p/security-audit"
})
filtered = client.call_tool("filter_results", {
"results_file": "/path/to/results.json",
"severity": "ERROR"
})
uv run mcp dev server.py
http://localhost:3000 with the inspector server on http://localhost:5173.http://localhost:5173/?timeout=300000